CISA Adds CVSS 10.0 Oracle WebLogic Flaw to KEV, Exploited Since February 2026
CISA added CVE-2026-21962, a maximum-severity improper access control vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24, 2026. The flaw allows an unauthenticated attacker with HTTP network access to read, create, delete, or modify critical data across any system reachable through the proxy tier, requiring no credentials or user interaction. Oracle had already issued a patch in its January 2026 Critical Patch Update, meaning affected organizations had seven months to remediate before active exploitation was officially confirmed. Security firms GreyNoise and CloudSEK documented exploitation attempts as early as February and March 2026, with attackers simultaneously probing several older WebLogic vulnerabilities alongside the new flaw. Federal civilian agencies were given until August 27, 2026 — a three-day window — to apply fixes under Binding Operational Directive 26-04.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in