โ Back to FeedActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
CVE-2026-21962
August 25, 2026 ยท The Hacker News ยท Severity: CRITICAL
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity (CVSS 10.0) security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its KEV catalog, citing evidence of active exploitation. The vulnerability, CVE-2026-21962, allows an unauthenticated attacker with network access via HTTP to compromise instances or modify critical data. Patches were released by Oracle earlier this January, but active exploitation has been observed by GreyNoise and CloudSEK across multiple campaigns targeting WebLogic environments. FCEB agencies must apply fixes by August 27, 2026.
๐ **Analyst Note:** This CVE is confirmed actively exploited in the wild and has been added to CISA KEV. Apply patches immediately and monitor for indicators of compromise targeting Oracle HTTP Server and WebLogic environments.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. "Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data," CISA said . While patches for the flaw were released by Oracle earlier this January, it has since witnessed active exploitation efforts, per multiple reports from GreyNoise and CloudSEK. In February 2026, it emerged that a lone IP address ("193.24.123[.]42") was attempting to exploit multiple known vulnerabilities impacting Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. A month later, CloudSEK reported seeing exploitation efforts aimed at its honeypot network. "In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE)," CloudSEK noted at the time. "This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments." Pursuant to Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies have been recommended to apply necessary fixes by August 27, 2026, to safeguard their networks. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- CVE-2026-21962 enables unauthenticated attackers to access critical data via HTTP network access.
- The vulnerability impacts Oracle HTTP Server and WebLogic Server Proxy Plug-in.
- Active exploitation of this CVSS 10.0 flaw was observed by GreyNoise and CloudSEK.
- Patches were released by Oracle in January 2026 and should be applied immediately.