VMTech
Discuss a project

CISA Adds Actively Exploited Oracle WebLogic Flaw to KEV Catalog

CISA Adds Actively Exploited Oracle WebLogic Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. The maximum-severity vulnerability, rated CVSS 10.0, affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in.

The flaw can be exploited by an unauthenticated attacker with network access over HTTP. CISA said successful compromise can provide unauthorized access to affected instances and allow the creation, deletion, or modification of critical data.

Critical access-control weakness

CISA describes CVE-2026-21962 as an improper access-control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Its advisory says the issue may enable unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or all data accessible through the affected products.

The combination of unauthenticated HTTP reachability and the potential impact on critical data makes the issue particularly significant for exposed enterprise infrastructure. Oracle released patches for the vulnerability in January, but subsequent reporting has indicated that attackers have begun attempting to exploit it.

Exploitation activity extends to established WebLogic targets

GreyNoise and CloudSEK have both reported exploitation efforts involving CVE-2026-21962. In February 2026, a single IP address, 193.24.123[.]42, was observed attempting to exploit known vulnerabilities affecting Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI.

CloudSEK reported a month later that its honeypot network had captured exploitation attempts. Alongside CVE-2026-21962, the activity targeted long-standing critical WebLogic remote-code-execution flaws: CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271.

CloudSEK said the observed attempts show that threat actors continue to use a small set of effective and simple-to-exploit vulnerabilities to compromise WebLogic environments. The activity places the newly cataloged flaw within a wider pattern of scanning and exploitation against enterprise application infrastructure.

Required remediation timeline

Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies have been recommended to apply the necessary fixes by August 27, 2026. The KEV listing reflects CISA's assessment that the vulnerability is being exploited in the wild.

Organizations operating Oracle HTTP Server or the Oracle WebLogic Server Proxy Plug-in should establish where those services are reachable over HTTP, apply Oracle's available patches, and confirm that exposed systems are addressed. The practical business implication is that patching this CVSS 10.0 issue and reviewing externally reachable deployments should be treated as an immediate operational priority.

#cybersecurity#oracleweblogic#vulnerability#patchmanagement
Open analytics
On the site 0 views
min read 3 25.08.2026
Instagram

CISA Adds Actively Exploited Oracle WebLogic Flaw to KEV Catalog

Open the post on Instagram ↗