← All briefings

Oracle HTTP Server / WebLogic Server Proxy Plug-in · Keycloak · Microsoft SharePoint

Date: 2026-08-25 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

The most critical new development today is CVE-2026-21962 — an Oracle HTTP Server / WebLogic Server Proxy Plug-in improper access control flaw added to the CISA KEV catalog with a three-day remediation deadline of 2026-08-27. Rapid7 has published analysis of CVE-2026-63520, a Microsoft SharePoint RCE warranting urgent review. A critical unauthenticated account takeover flaw in Keycloak (CVE-2026-18963, CVSS 9.1) and active exploitation of miniOrange WordPress SAML plugin authentication bypass flaws are also newly reported. The Berlin Senatsverwaltungen have come back online after more than a week of isolation.


Critical Vulnerabilities

CVE-2026-21962 — Oracle HTTP Server / WebLogic Server Proxy Plug-in (Improper Access Control)

  • Severity: Not yet published by Oracle; CISA KEV confirmed
  • EPSS: Not yet scored
  • Technical detail: An improper access control vulnerability (CWE-284) in Oracle HTTP Server and the WebLogic Server Proxy Plug-in allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible through the affected components. The plug-in is widely deployed as a reverse proxy front-end for Oracle WebLogic in enterprise middleware environments. The attack vector and authentication requirements have not been fully disclosed, but CISA’s KEV addition confirms active exploitation in the wild.
  • Exploitation status: Actively exploited — CISA KEV added 2026-08-24.
  • Remediation: Apply Oracle patches immediately. CISA deadline for federal agencies: 2026-08-27. Enterprise operators should treat this as equivalent urgency. Restrict external access to Oracle HTTP Server and WebLogic proxy interfaces pending patching.

CVE-2026-18963 — Keycloak (Unauthenticated Account Takeover via Password Reset)

  • Severity: CVSS 9.1 (Red Hat)
  • EPSS: Not yet scored — newly published
  • Technical detail: A critical flaw in the Keycloak open-source identity and access management server allows an unauthenticated remote attacker to force a password reset on any user account and take it over. The vulnerability resides in the password reset flow; no prior authentication is required. Keycloak is widely deployed as an SSO and OAuth2/OIDC provider in enterprise, cloud-native, and government environments — a successful exploit grants full account control, including administrative accounts, with no user interaction required.
  • Exploitation status: No confirmed exploitation; CVSS 9.1 with unauthenticated attack vector warrants urgent treatment.
  • Remediation: Apply patches released by Red Hat and the Keycloak project immediately. Audit Keycloak logs for anomalous password reset activity. Enforce MFA on all Keycloak-managed accounts as a compensating control.

CVE-2026-63520 — Microsoft SharePoint (Remote Code Execution)

  • Severity: Not yet confirmed in available data
  • EPSS: Not yet scored
  • Technical detail: Rapid7 has published an analysis of a remote code execution vulnerability in Microsoft SharePoint. Full technical details are limited in current disclosure, but SharePoint RCE vulnerabilities have historically been high-value targets for ransomware operators and nation-state actors due to SharePoint’s role as a central document management and collaboration platform in enterprise environments. Organizations running on-premises SharePoint deployments are at highest risk.
  • Exploitation status: No confirmed exploitation reported at time of writing; Rapid7 analysis suggests active research interest.
  • Remediation: Apply the relevant Microsoft patch (August 2026 Patch Tuesday or out-of-band if applicable). Prioritize on-premises SharePoint instances. Review Rapid7’s analysis for indicators and detection guidance.

CVE-2026-56705 / CVE-2026-56703 — Adminer (Unauthenticated RCE / DSN Injection)

  • Severity: CVSS 9.3 (CVE-2026-56705), 8.6 (CVE-2026-56703)
  • EPSS: 0.0 — newly published
  • Technical detail: Two critical flaws affect Adminer (the widely used single-file PHP database management tool) prior to version 5.4.3. CVE-2026-56705 allows unauthenticated attackers to inject ODBC parameters via semicolons in the server field, enabling arbitrary file writes (TraceFile injection) and potential RCE without authentication. CVE-2026-56703 allows authenticated attackers to achieve RCE via SQLite’s VACUUM INTO command, which is not blocked despite ATTACH restrictions. Adminer is frequently exposed on internal developer and admin portals; unauthenticated access to CVE-2026-56705 makes this particularly dangerous if the login page is internet-facing.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Upgrade Adminer to ≥ 5.4.3. Restrict Adminer access to trusted IP ranges or VPN only. Remove publicly accessible Adminer instances immediately.

CVE-2026-39975 — Combodo iTop (Unauthenticated RCE via .readonly File Deletion)

  • Severity: CVSS 9.4
  • EPSS: 0.0 — newly published
  • Technical detail: In Combodo iTop (web-based ITSM tool) prior to version 3.2.3, unauthenticated users can delete the .readonly file that iTop creates during maintenance mode to prevent code execution. Removing this file re-enables code execution pathways, allowing an unauthenticated attacker to achieve RCE. iTop is deployed in enterprise IT service management environments, often with access to CMDB data, ticketing, and internal infrastructure records. A companion XSS (CVE-2026-30864, CVSS 8.9) and PHP object injection leading to RCE (CVE-2026-40877, CVSS 8.7) are also patched in 3.2.3.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Upgrade iTop to ≥ 3.2.3 immediately. Restrict iTop to internal networks or VPN.

ONGOING:

  • CVE-2026-68820 (Windows AFD/Lazarus): KEV deadline today (2026-08-25) — apply August Patch Tuesday without further delay.
  • CVE-2026-19478 (GitLab): Actively exploited — upgrade to 19.0.6 / 19.1.4 / 19.2.2.
  • CVE-2026-73570 (Zimbra ZCS): KEV deadline passed 2026-08-24 — patch immediately if not yet done; audit for web shells.
  • CVE-2026-72529 / CVE-2026-72530 (TrueConf): KEV deadline passed — patch or block port 4307/TCP.
  • CVE-2026-64849 (MLflow SSRF): KEV deadline 2026-09-02 — patch and audit IAM.
  • CVE-2026-69414 (Microsoft Defender ShieldBreak): No patch available — monitor MSRC.
  • CVE-2026-78155 (StackGres), CVE-2026-78207 cluster (exceljs), CVE-2026-7808 cluster (justhtml), CVE-2026-10053 (GitLab): Patch per prior guidance.

European Advisories

BSI — New advisories (2026-08-24):

WID-SEC-2026-2974 (Rapid7 Velociraptor — NEW): An authenticated remote attacker can exploit multiple vulnerabilities in Rapid7 Velociraptor to manipulate files, bypass security controls, execute code, or escalate privileges. Organizations using Velociraptor for endpoint detection and DFIR should apply available updates promptly, as compromise of a DFIR platform has significant secondary risk.

WID-SEC-2026-2968 (Notepad++ — NEW): Version 8.9.8 patches 14 vulnerabilities including code execution, Windows credential disclosure, file manipulation, and DoS. Heise Security confirms the release. Update to Notepad++ 8.9.8 via official channels.

WID-SEC-2026-2965 (Langflow OSS — NEW): Multiple vulnerabilities in the Langflow AI workflow platform allow security bypass, information disclosure, and data manipulation. Organizations running Langflow in enterprise AI pipelines should apply patches.

BSI — Updated advisories: GeoServer (SQL injection/RCE — kritisch), Google Chrome (multiple — hoch), util-linux, Red Hat Enterprise Linux (nodejs:24, 389-ds-base, mrtg/kbd/urwid), Linux Kernel (multiple advisories), Mozilla Firefox/ESR/Thunderbird, Microsoft Developer Tools, GIMP, QEMU — apply current vendor patches per prior guidance.

Berlin Senatsverwaltungen: Heise Security reports that both affected Berlin Senate agencies have returned to normal network operations after more than a week of isolation following the cyberattack. Incident investigation is ongoing.

ONGOING: WID-SEC-2026-2962 (Apache CloudStack), WID-SEC-2026-2964 (TP-Link Omada), WID-SEC-2026-2963 (PTC Windchill), WID-SEC-2026-2951 (Microsoft Azure/Entra/Exchange) — apply vendor patches; no change.


Active Threats and Campaigns

miniOrange SAML WordPress Plugin — Active Exploitation (NEW): Bleeping Computer reports active exploitation of two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. Attackers can forge SAML responses to authenticate as administrators without valid credentials. WordPress site operators using this plugin should update immediately and audit admin account activity and recent logins.

Weedhack Malware — Gaming Lure Campaign (NEW): McAfee Labs reports that multiple websites are actively distributing the Weedhack malware family by impersonating Minecraft clients, with over 6,300 blocked access attempts detected. The campaign uses SEO poisoning and lookalike gaming sites. While primarily consumer-targeted, BYOD environments and developer workstations are at risk.

UAT-10147 / SPECTRE — AI-Assisted Server Attacks (NEW): A Chinese-speaking cybercrime group (UAT-10147) is using AI to scale attacks against Windows and Linux web servers in education, media, technology, and gaming sectors globally, deploying the SPECTRE implant with EDR bypass capabilities and a Linux rootkit. No confirmed European targeting reported, but the EDR bypass capability warrants detection rule review.

ONGOING:

  • ToxicPanda 2.0: Expanded to 349 apps, 167 remote commands, VPN abuse — update mobile threat detection, review MDM policies.
  • RedC2 4.0 npm supply chain: Audit npm dependencies, rotate secrets.
  • SynkLoader / Microsoft Teams phishing: Enforce Teams external access policies; monitor EDR.
  • FTP Banner RAT delivery (E4del / PINHOLE): Hunt for anomalous FTP banner content.

Security News and Context

  • Keycloak account takeover: Red Hat and Keycloak have patched CVE-2026-18963 (CVSS 9.1), a critical unauthenticated password reset flaw; see Critical Vulnerabilities for full detail. (The Hacker News)
  • Notepad++ 8.9.8: Patches 14 security flaws including credential disclosure and code execution; update via official channels. (Heise Security)
  • GI demands legal protection for security researchers: Germany’s Gesellschaft für Informatik has formally called on the federal government to protect ethical hackers from criminal prosecution. (Heise Security)
  • WordlistLoader / Amatera Stealer: New malware chain using ClickFix/ClearFake lures delivers Amatera Stealer; SynkLoader phishes Windows credentials via fake lock screens. (The Hacker News)

  1. Oracle HTTP Server / WebLogic (CVE-2026-21962): Apply Oracle patches immediately — CISA KEV deadline 2026-08-27; restrict proxy interface exposure pending patch.
  2. Keycloak (CVE-2026-18963): Apply Red Hat/Keycloak patches now; enforce MFA on all Keycloak accounts; audit password reset logs.
  3. Windows AFD (CVE-2026-68820): KEV deadline today — apply August Patch Tuesday without further delay.
  4. Microsoft SharePoint (CVE-2026-63520): Apply relevant Microsoft patch; review Rapid7 analysis for detection guidance; prioritize on-premises instances.
  5. Adminer (CVE-2026-56705 / CVE-2026-56703): Upgrade to ≥ 5.4.3; restrict or remove internet-facing Adminer instances immediately.
  6. Combodo iTop (CVE-2026-39975 cluster): Upgrade to ≥ 3.2.3; restrict to internal networks.
  7. miniOrange SAML WordPress plugin: Update immediately; audit admin accounts and recent authentication logs.
  8. Notepad++ / Rapid7 Velociraptor / Langflow OSS: Apply vendor updates per BSI advisories WID-SEC-2026-2968, WID-SEC-2026-2974, WID-SEC-2026-2965.
  9. UAT-10147 / SPECTRE: Review EDR detection rules for bypass techniques; audit Linux web server integrity.
  10. Continue remediation of previously reported items: CVE-2026-73570 (Zimbra — deadline passed), CVE-2026-72529/72530 (TrueConf — deadline passed), CVE-2026-64849 (MLflow — deadline 2026-09-02), CVE-2026-69414 (Defender ShieldBreak — no patch), CVE-2026-78155 (StackGres), exceljs/justhtml/GitLab clusters.