TODAY
Perfect-10 Oracle/Apache flaw hits KEV; 115 ransomware victims this week.
THE THREE
- KEV#1 · CVE-2026-21962
Apache
What: This CVSS 10.0 flaw in Oracle HTTP Server and WebLogic Server's Apache/IIS proxy plug-in was added to CISA's exploited list just two days ago — attackers are actively hitting it right now. If your org runs WebLogic 12.2.1.4.0 or 14.1.1 behind Apache or IIS, you are an immediate target for full server compromise.
Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · New this week
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Oracle WebLogic proxy plug-in to a fixed version immediately.
- KEV#2 · CVE-2026-33824
Windows
What: A double-free memory bug in Windows IKE Extension lets an unauthenticated attacker run code on your Windows systems over the network — no login required, 73% exploit probability. Any Windows machine reachable on the network is at risk of full takeover.
Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the Microsoft patch for CVE-2026-33824 to all Windows systems now.
- KEV#3 · CVE-2026-8037
Progress
What: Progress LoadMaster load balancers have a command injection flaw with near-certain (99.6%) exploit odds — unauthenticated attackers can run any command on the appliance. Compromised load balancers sit in front of your entire application stack, making this a catastrophic pivot point.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Progress LoadMaster firmware to the vendor-patched version immediately.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 289
- Indicators
- 578k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.