View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA adds critical Oracle proxy plug-in flaw to KEV catalog

🚨 ACTIVE EXPLOITATION

  • CISA adds critical Oracle proxy plug-in flaw to KEV catalog CVE-2026-21962 CISA lists a critical Oracle proxy plug-in vulnerability in its KEV catalog.
    • Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in customers are affected.
    • CVE-2026-21962 is an improper access control flaw with a CVSS score of 10.0.
    • Affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; IIS is affected only at 12.2.1.4.0.
    • An unauthenticated attacker can exploit the flaw remotely over HTTP to access or modify critical data. πŸ“„ Source: oracle.com Β· πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Fake GTA 6 Demo Sites Distribute Vidar Infostealer Fake GTA 6 demo sites are distributing the Vidar infostealer.
    • GTA 6 fans searching for leaks, demos, or PC builds are targeted.
    • Fake Rockstar-branded sites deliver a 1.1 MB gta6_installer.exe instead of a game.
    • The Vidar sample steals browser passwords, cookies, authenticated sessions, history, autofill data, and FTP credentials.
    • β€œPlay Now” links and copied Rockstar Extended Look promotions lead to the malware download.
    • Observed IOCs include SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 and gta6demo[.]asia, gta6demo[.]eu, and gta6demo[.]us. πŸ“„ Source: cnet.com Β· πŸ“Ž Coverage: malwarebytes.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-71933 β€” CVSS 8.8 β€” DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions...

  • CVE-2026-9254 β€” CVSS 8.7 β€” Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer ...

  • CVE-2026-71943 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetMultipl...

  • CVE-2026-71942 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalertMultipl...

  • CVE-2026-71941 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmailMultiple ...

  • CVE-2026-71940 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edi...

  • CVE-2026-71939 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add...

  • CVE-2026-71938 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrpMultip...

  • CVE-2026-71937 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profileM...

  • CVE-2026-71936 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via sysrebootMultiple Dra...

  • CVE-2026-71935 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupActionMultip...

  • CVE-2026-71934 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtraceMultiple Dra...

  • CVE-2026-71931 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeMult...

  • CVE-2026-71930 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeMultiple ...

  • CVE-2026-71929 β€” CVSS 8.6 β€” DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoMulti...

  • CVE-2026-16348 β€” CVSS 8.5 β€” Command Injection Vulnerability in VPN connection of Archer BE800An authentic...

  • CVE-2026-71932 β€” CVSS 6.9 β€” DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileMultiple ...

  • CVE-2026-34491 β€” CVSS 6.1 β€” Improper neutralization of input during web page generation ('cross-site scri...

  • CVE-2026-78475 β€” CVSS 6.1 β€” Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderA fl...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check