Today’s Field Note

Three unauthenticated exploitation stories landed at once, and none of them wait for your change window. CISA added Oracle WebLogic/HTTP Server CVE-2026-21962 (CVSS 10.0) to KEV with confirmed active exploitation, letting network attackers reach critical data with no credentials. In parallel, attackers are forging SAML responses against the Xecurify miniOrange SAML 2.0 SSO plugin (CVE-2026-61979 and its sibling) to log into WordPress as any admin. And CISA gave agencies just three days to patch Zimbra CVE-2026-73570, a full-takeover mailbox flaw. This is the pattern now: internet-facing middleware, plugins, and mail servers get hit before most teams finish reading the advisory.

Today’s Action

  • Inventory all internet-facing Oracle WebLogic and Oracle HTTP Server instances and apply the CVE-2026-21962 fix now; pull them off the public internet until patched.
  • Update or disable the miniOrange SAML 2.0 SSO plugin on every WordPress install, then audit admin accounts and recent logins for forged SAML sessions.
  • Patch Zimbra against CVE-2026-73570 inside CISA’s three-day window and review mailbox rules, delegations, and sent items for signs of takeover.
  • Hunt for WebLogic exploitation: unexpected child processes, outbound connections, and web shells under the servlet paths.
  • Check KEV against your asset list daily this week; treat any match as work-in-progress, not a ticket for next sprint.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

It’s not “if the advisory applies to you.” It’s whether you moved before they did.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.