CISA says attackers are exploiting Oracle WebLogic proxy flaw CVE-2026-21962 and urges immediate patching

CISA says attackers are actively exploiting a critical Oracle WebLogic-related server flaw, putting organizations with exposed systems at immediate risk. The bug, CVE-2026-21962, is a CVSS 10.0 unauthenticated remote code execution issue affecting Oracle HTTP Server and the WebLogic Server Proxy plugin that bridges HTTP Server to WebLogic. Oracle patched it in January 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on August 24 with a federal patch deadline of August 27.
Why it matters: Organizations running Oracle HTTP Server or the WebLogic Server Proxy plugin should treat this as urgent because attackers have been exploiting it since shortly after public proof-of-concept code appeared. Internet-facing systems should be patched immediately and reviewed for signs of compromise.

Sources

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
2026.08.25 97% relevant
This article is a direct update on the same event, adding that CISA gave federal agencies the maximum-urgency three-day remediation deadline and noting earlier honeypot evidence and public exploit activity soon after Oracle's January patch.
CISA Warns of Exploited Oracle WebLogic Vulnerability
Eduard Kovacs 2026.08.25 100% relevant
This article establishes a distinct tracked event: CISA's KEV addition and active-exploitation warning for CVE-2026-21962 in Oracle HTTP Server and the WebLogic Server Proxy plugin, which is different from the previously tracked Oracle WebLogic story about CVE-2024-21182.
← Back to all stories