CISA just added a critical Oracle flaw to its Known Exploited Vulnerabilities catalog. The bug is being actively exploited right now. If you run Oracle HTTP Server or WebLogic Server, you need to act fast.
The vulnerability is CVE-2026-21962. It has a CVSS score of 10.0, the highest possible. This impacts Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
The exploitation of this vulnerability does not require any user credentials. The only requirement is having access to the server via the network through HTTP protocol.
If you use Oracle WebLogic, then this information is relevant for you. Let me give some explanation here.
Quick Summary
|
What |
Details |
|
Vulnerability |
CVE-2026-21962 |
|
CVSS Score |
10.0 (Maximum) |
|
Affected Products |
Oracle HTTP Server, Oracle WebLogic Proxy Plug-in |
|
Impact |
Unauthorized access, data modification |
|
Status |
Actively exploited |
|
Patch Available |
Yes (January 2026) |
|
CISA Deadline |
August 27, 2026 |
What's the Problem?
The CVE-2026-21962 Vulnerability of Oracle HTTP Server is that of improper access. It lets attackers:
- Create, delete, or modify critical data
- Access critical data without permission
- Get complete access to all data
What CISA Said:
"Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data."
Active Exploitation Confirmed
The Oracle HTTP Server CVE-2026-21962 vulnerability has been actively exploited since at least February 2026.
GreyNoise and CloudSEK Reports:
Security firms GreyNoise and CloudSEK confirmed the attacks. One IP address was seen trying to exploit multiple vulnerabilities. CloudSEK also caught exploitation attempts on their honeypot network.
Other WebLogic Flaws Being Targeted:
Attackers aren't just using this one flaw. They're also going after older WebLogic vulnerabilities:
|
CVE |
Description |
|
CVE-2020-14882/14883 |
Console RCE |
|
CVE-2020-2551 |
IIOP RCE |
|
CVE-2017-10271 |
WLS-WSAT RCE |
What CloudSEK Said:
"This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments."
What You Should Do
1. Apply the Patch Now
Oracle released patches in January 2026. If you haven't applied them, do it today.
2. Check Your Logs
Look for suspicious activity. Check for any access without authorization.
3. Meet the CISA Deadline
Federal agencies have until August 27, 2026. Don't wait.
4. Patch Older WebLogic Flaws Too
Attackers are also exploiting older vulnerabilities. Patch them while you're at it.
The Bottom Line
Oracle HTTP Server CVE-2026-21962 is a critical flaw under active attack. No credentials needed. Full access to critical data.
What You Need to Know:
|
Key Point |
Detail |
|
Vulnerability |
CVE-2026-21962 |
|
CVSS Score |
10.0 |
|
Impact |
Unauthorized access, data modification |
|
Status |
Actively exploited |
|
Patch |
Available since January 2026 |
|
CISA Deadline |
August 27, 2026 |
Here Is What You Should Do:
- Apply Oracle’s patch right away
- Look for any indicators of compromise
- Patch other WebLogic vulnerabilities
- Follow CISA’s guidelines
FAQ Section
What is CVE-2026-21962?
This is a critical vulnerability present in Oracle HTTP Server and WebLogic Proxy Plug-in. The attackers have the ability to view or change critical information without any credentials at all.
What is the CVSS score?
10.0, the highest possible.
Is it being exploited?
Yes. GreyNoise and CloudSEK have confirmed active exploitation.
What should I do?
Patch Oracle as soon as you can. See whether there have been any signs of intrusion. Patch all other WebLogic vulnerabilities.
When is the CISA deadline?
August 27, 2026.