Maximum-severity Oracle HTTP Server/WebLogic flaw (CVE-2026-21962) added to CISA's exploited-vulnerabilities catalog
CISA added a maximum-severity (CVSS 10.0), unauthenticated Oracle HTTP Server and WebLogic Server Proxy Plug-in vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities catalog on August 24, ordering federal agencies to patch it by August 27. Per SecurityWeek and The Hacker News.
CISA added CVE-2026-21962, a maximum-severity (CVSS 10.0) improper access control flaw in Oracle $ORCL HTTP Server and the WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24, 2026. The flaw lets an unauthenticated attacker with network access via HTTP gain unauthorized access to, or modify, critical data on affected servers. Oracle patched the issue in its January 2026 Critical Patch Update, but the security firm CloudSEK reported its honeypots detected exploitation attempts starting January 22, 2026, within days of a proof-of-concept exploit going public. Federal civilian agencies have been instructed to apply the fix by August 27, 2026. It remains unclear which specific attacks prompted CISA's alert. Sources: The Hacker News, SecurityWeek.