Summary
- CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.
- The flaw affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in, and carries the maximum CVSS score of 10.
- Successful exploitation can allow unauthorised creation, deletion, or modification of critical data, or complete read access to all data accessible by the affected components.
- The remediation deadline for US federal civilian agencies is 27 August 2026 — one of CISA’s tightest three-day patching windows.
- Organisations unable to apply mitigations should consider discontinuing use of the affected product until a fix is in place.
What Has Been Disclosed
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue on 24 August 2026, confirming that the vulnerability is being actively exploited. The flaw resides in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in and is classified as an improper access control vulnerability. It carries a CVSS score of 10 — the maximum possible — reflecting the breadth of potential impact.
Scope of the Risk
According to the CISA advisory, successful exploitation can result in unauthorised creation, deletion, or modification of critical data, as well as complete unauthorised read access to all data reachable by the affected components. In practical terms, an attacker who exploits this flaw could gain sweeping control over data handled by Oracle’s web tier and application server proxy infrastructure — environments that frequently sit at the boundary between public-facing services and internal enterprise systems.
An Unusually Short Federal Deadline
CISA has set a remediation due date of 27 August 2026 for agencies bound by Binding Operational Directive 22-01. As The Register has reported, this represents one of CISA’s tightest three-day patching deadlines, a signal that the agency considers the threat to be both credible and time-sensitive. While BOD 22-01 applies directly to US federal civilian executive branch agencies, CISA routinely encourages all organisations to treat KEV catalogue entries as high-priority remediation targets.
Context: Oracle WebLogic as a Recurring Target
Oracle WebLogic Server has a well-documented history as a target of choice for threat actors, given its prevalence in enterprise and government environments. The inclusion of the Proxy Plug-in in this advisory broadens the affected surface beyond a standalone application server component. Organisations running Oracle HTTP Server in front of WebLogic workloads should treat this as affecting their entire Oracle web tier, not a single isolated product.
Required Actions
CISA’s required action is clear: apply mitigations per Oracle’s vendor instructions, follow BOD 22-01 guidance for any cloud-hosted instances of the affected software, or discontinue use of the product if mitigations are not available. The advisory does not provide additional technical detail about the exploitation method or the threat actors involved beyond confirming that active exploitation is occurring.
Why it matters
Oracle HTTP Server and WebLogic Server are deeply embedded in enterprise application stacks across financial services, government, and critical infrastructure sectors. A maximum-severity access control flaw in these components — confirmed as actively exploited — represents a direct threat to data integrity and confidentiality at the web tier. CISOs should not treat this as a routine patch cycle item: the three-day federal deadline, the CVSS 10 score, and the confirmed exploitation status together indicate a vulnerability that warrants immediate escalation to patching teams. Organisations running Oracle web infrastructure in cloud environments have an additional obligation under BOD 22-01 guidance to verify their exposure and document remediation.
What to do now
- Identify all instances of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in across your environment, including cloud-hosted deployments.
- Apply mitigations per Oracle’s vendor instructions as a priority action.
- For cloud service instances, follow the applicable BOD 22-01 guidance as directed by CISA.
- If mitigations are not available or cannot be applied within the required timeframe, consider discontinuing use of the affected product until a fix is in place.
- Treat this as an active incident risk: review access logs for the affected components for signs of unauthorised access or anomalous activity.
Sources
- CISA KEV: CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- The Register: CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
- CISA Advisories: CISA Adds One Known Exploited Vulnerability to Catalog
- The Hacker News: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
