CISA added CVE-2026-21962 — an improper access-control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in — to the KEV catalog today with confirmed active exploitation and a due date of 2026-08-27.
Everything else on the board traces the same shape: authorization logic that trusts something it already checked once. Sakai shipped a stored-XSS in Conversations and a profile-image IDOR in the same batch; 3X-UI's database-import flow lets a trusted admin action smuggle an arbitrary file write into the Xray process; Cloudreve's cached context-hint skips share revalidation for up to five minutes after a share is revoked; and django CMS took two hits in one release — a cyclic-reparenting DoS and a cache key that ignores plugin-declared Vary headers. Two more server-triggered panics in the Rust postgres client family and a predictable-PRNG fix in gorilla/websocket round out the day, with no active package-registry campaign surfacing in the RSS sweep.
→ Operational priority for the night patch the Oracle proxy plug-in wherever it fronts a WebLogic deployment ahead of the 08-27 KEV deadline, then take the django CMS 5.0.8 upgrade since it closes two separate bugs in one release.