← All briefings

Oracle WebLogic Server · Delinea Secret Server · Google Chrome

Date: 2026-09-16 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

Oracle published a large set of critical Fusion Middleware and enterprise-application vulnerabilities, including multiple CVSS 10.0 issues affecting WebLogic Server, Access Manager, Forms, Internet Directory and related products. New high-impact items also affect Delinea Secret Server and Google Chrome. European reporting highlights a new high-severity MISP advisory and updates to Linux, Samba, Firefox, Redis and Microsoft developer-tool advisories. CHOSEN BRICK malware activity targeting dissidents and journalists was detailed by UK authorities.

Critical Vulnerabilities

CVE-2026-83021 — Oracle WebLogic Server

  • Severity: CVSS 10.0
  • EPSS: 0 — no elevated exploitation probability supplied
  • Technical detail: The vulnerability affects the Web Container component in Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. EUVD describes it as easily exploitable, but the supplied data does not specify the precise attack vector or resulting impact.
  • Exploitation status: NEW — no confirmed exploitation supplied.
  • Remediation: Apply Oracle’s September 2026 security update and verify all WebLogic instances, including externally accessible administration and application endpoints. Restrict management interfaces to trusted networks while patching.

CVE-2026-70756 — Oracle WebLogic Server

  • Severity: CVSS 9.8
  • EPSS: 0 — no elevated exploitation probability supplied
  • Technical detail: The flaw affects the WebLogic Core component across versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Oracle classifies the vulnerability as easily exploitable; available data does not provide sufficient detail to confirm whether authentication is required or whether code execution is possible.
  • Exploitation status: NEW — no confirmed exploitation supplied.
  • Remediation: Apply the applicable Oracle CPU immediately, inventory WebLogic versions and review access logs for anomalous requests or administrative activity.

CVE-2026-15640 — Delinea Secret Server

  • Severity: CVSS 9.5
  • EPSS: Not supplied
  • Technical detail: Under certain conditions, a valid SAML identity-provider response can be used to impersonate another Secret Server user. A successful attack could affect identity integrity and privileged-access workflows in on-premises Secret Server deployments from 10.5.0 through 12.1.3.
  • Exploitation status: NEW — no confirmed exploitation supplied.
  • Remediation: Apply Delinea’s fixed release, review SAML configuration and identity-provider logs, and validate recent privileged-account access. Treat unexplained administrator sessions or vault access as potential incidents.

CVE-2026-91728 — Google Chrome

  • Severity: CVSS 9.6
  • EPSS: Not supplied
  • Technical detail: An integer-overflow flaw in the V8 JavaScript engine allows a remote attacker to execute arbitrary code inside the browser sandbox through a crafted HTML page. Chrome versions before 153.0.8010.47 are affected.
  • Exploitation status: NEW — no confirmed exploitation supplied.
  • Remediation: Deploy Chrome 153.0.8010.47 or later through enterprise management. Prioritize internet-facing and high-risk users, and monitor endpoint telemetry for abnormal browser child processes or exploit-like crashes.

CVE-2026-15638 — Delinea Secret Server

  • Severity: CVSS 9.1
  • EPSS: Not supplied
  • Technical detail: An unauthenticated user with access to Secret Server may exploit a padding-oracle condition to decrypt or encrypt data using one of the server’s cryptographic keys. The key itself is reportedly not exposed, but affected on-premises versions include 10.5.1 through 12.1.3.
  • Exploitation status: NEW — no confirmed exploitation supplied.
  • Remediation: Apply Delinea’s security update, restrict access to Secret Server and review requests for unusual cryptographic or authentication activity. Rotate protected secrets where compromise of encrypted data cannot be excluded.

ONGOING

  • CVE-2026-76461 (Cisco Secure Email Gateway): actively exploited; patch before the 2026-09-17 CISA deadline and investigate for root-level compromise.
  • CVE-2026-85706 (GitLab CE/EE): actively exploited; patch and investigate arbitrary-file access.
  • CVE-2026-84869 (ConnectWise ScreenConnect): active exploitation reported; remediation is overdue.
  • CVE-2026-42016 / CVE-2026-42018 (JFrog Artifactory): actively exploited and reportedly chained; patch and rotate tokens.
  • CVE-2026-67277 / CVE-2026-86060 (MikroTik RouterOS): actively exploited; restrict management exposure.
  • CVE-2026-75650 (Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file changes.
  • CVE-2026-86218 (N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.
  • CVE-2026-81963 / CVE-2026-85880 (Windows): actively exploited; complete September updates.
  • CVE-2026-63520 (Microsoft SharePoint): exploitation and public PoC reported; verify patching and hunt for web shells.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut): exploitation reported; deploy current maintenance releases.

European Advisories

Oracle’s September 2026 security release generated numerous new EUVD records covering Fusion Middleware, WebLogic Server, Access Manager, Forms, Internet Directory, Identity Manager, WebCenter, Oracle E-Business Suite, Analytics and other enterprise products. Prioritize internet-exposed WebLogic, identity, portal and E-Business Suite deployments; the highest-risk records are covered above.

WID-SEC-2026-3370 (MISP) is NEW and describes multiple high-severity vulnerabilities that may permit privilege escalation, security-control bypass, data access or manipulation, arbitrary code execution and redirection to malicious URLs. Apply the vendor-recommended MISP update and restrict administrative access.

BSI updated advisories for Linux Kernel, Samba, Firefox/Thunderbird, Redis and Microsoft developer tools. Apply vendor updates and correlate affected package versions with internet-facing services. The BSI advisory feed should be used for individual remediation details.

The BSI advisory on Cisco Secure Email Gateway is covered in Critical Vulnerabilities. See the BSI warning.

Active Threats and Campaigns

  • CHOSEN BRICK spyware — NEW: UK authorities and allies report Windows malware used by Iranian state actors to target dissidents, activists and journalists. Capabilities include theft of emails and chat messages, screenshots and microphone recording. Review the UK NCSC advisory and protect high-risk users.
  • BambooToken — NEW: A cross-platform Windows and Linux malware framework uses MQTT for command and control. Organizations should investigate unusual outbound MQTT connections and unauthorized broker communication.
  • KREMLIN banking malware — NEW: A Brazilian banking-malware operation uses malicious Chrome extensions to steal credentials and browser session tokens. Enforce browser-extension allowlists and review newly installed extensions.
  • Vite development-server credential theft — NEW: Mass scanning targets exposed Vite development servers to extract AWS/Azure credentials and infrastructure state files. Remove development servers from the public internet and rotate exposed cloud credentials.
  • GitLab, Artifactory, GrayRabbit and Microsoft 365 phishing activity — ONGOING: Continue monitoring for exploitation, web shells, unauthorized OAuth grants, suspicious authentication methods and endpoint persistence.

Security News and Context

  • BleepingComputer reports active exploitation of a high-severity local privilege-escalation flaw in the Acronis backup plugin for cPanel, WHM and Plesk. Identify affected hosting systems and apply the vendor fix.
  • BleepingComputer reports that ransomware groups are exploiting a critical VMware vCenter flaw patched in July. Revalidate vCenter exposure and remediation status.
  1. Patch or isolate Cisco Secure Email Gateway before the 2026-09-17 CISA deadline; investigate appliance integrity.
  2. Inventory Oracle WebLogic and Fusion Middleware deployments and apply the September 2026 CPU.
  3. Patch Delinea Secret Server and review SAML, vault and privileged-access logs.
  4. Deploy Chrome 153.0.8010.47 or later and enforce browser-extension controls.
  5. Update MISP and restrict its administrative interfaces.
  6. Hunt for CHOSEN BRICK activity on high-risk Windows endpoints, including screenshots, microphone access and Telegram-related communications.
  7. Remove exposed Vite development servers and rotate potentially exposed AWS/Azure credentials.
  8. Continue remediation of previously reported items: GitLab, ScreenConnect, Artifactory, RouterOS, Magento, N-central, Windows, SharePoint and PaperCut.