Oracle WebLogic Flaw Under Active Attack
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
A critical flaw in Oracle HTTP Server and Oracle WebLogic Server has drawn the attention of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which added it to its Known Exploited Vulnerabilities (KEV) catalog on Monday. The vulnerability, already under active exploitation, carries the maximum CVSS severity score of 10.0, signaling that unauthenticated attackers can compromise affected systems with relative ease.
Critical Flaw in Oracle Components
Tracked as CVE-2026-21962, the vulnerability affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. It stems from an improper access control issue, allowing an unauthenticated attacker with network access via HTTP to compromise these components. Successful exploitation can lead to unauthorized access to instances or modification of critical data.
CISA's advisory describes the flaw as enabling "unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data." This broad access potential makes the vulnerability particularly dangerous for enterprise environments relying on these Oracle products.
Patches Released Earlier This Year
Oracle addressed the vulnerability in its January 2026 Critical Patch Update. Despite the availability of patches, the flaw has since witnessed active exploitation efforts, according to multiple reports from GreyNoise and CloudSEK. This pattern—patch released, then exploited—underscores the urgency for organizations to apply updates promptly.
Federal agencies, bound by Binding Operational Directive (BOD) 26-04, have been directed to apply necessary fixes by August 27, 2026, to safeguard their networks. While this directive applies specifically to Federal Civilian Executive Branch (FCEB) agencies, the recommendation serves as a broader reminder for all organizations running affected Oracle software.
Exploitation Linked to Known Vulnerabilities
In February 2026, researchers observed a lone IP address ("193.24.123[.]42") attempting to exploit multiple known vulnerabilities, including those in Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. A month later, CloudSEK reported seeing exploitation efforts aimed at its honeypot network, capturing attacks targeting not only CVE-2026-21962 but also other persistent, critical WebLogic RCE flaws.
CloudSEK noted that the honeypot captured attacks targeting CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE). This activity confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.
Recommendations for Organizations
While the directive applies to federal agencies, organizations using Oracle HTTP Server or Oracle WebLogic Server should treat this as a priority. Applying the vendor-provided patches is the most direct mitigation. Additionally, monitoring for indicators of compromise and restricting network access to these components can reduce exposure.
CISA's KEV catalog addition often serves as a trigger for organizations to accelerate patching, as it reflects confirmed real-world exploitation. The agency's guidance emphasizes the importance of timely patch management, especially for vulnerabilities with known attack paths.
Why It Matters
The active exploitation of CVE-2026-21962 highlights the persistent threat posed by known vulnerabilities in enterprise software. Even with patches available months in advance, threat actors continue to target these flaws, often because organizations fail to apply updates in a timely manner. For businesses relying on Oracle WebLogic, this incident underscores the critical need for rapid patch deployment and continuous vulnerability monitoring. The inclusion in CISA's KEV catalog raises the stakes, as it signals that exploitation is not theoretical but ongoing, and any delay in remediation could leave systems exposed to data compromise.
Sources
- The Hacker News Original source
Continue Reading
Weedhack Malware Poses as Minecraft Clients
Fake Minecraft sites spread Weedhack malware via SEO poisoning, with thousands of blocked attempts reported.
AliExpress caught using inaudible audio to fingerprint browsers
Researcher discovers AliExpress using obsolete WebAudio fingerprinting; Firefox fix likely neutralizes it.
Limited Breach: ReliaQuest Confirms Hack
ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.