CybersecurityAugust 25, 2026· via Security Affairs

Critical Oracle flaw exploited in the wild, CISA adds to KEV catalog

Critical Oracle flaw exploited in the wild, CISA adds to KEV catalog

Image : Security Affairs

A critical, unauthenticated flaw in Oracle’s WebLogic Server and HTTP Server Proxy Plug-in has been added to the U.S. government’s Known Exploited Vulnerabilities catalog after researchers confirmed active attacks. Tracked as CVE-2026-21962 with a perfect CVSS score of 10.0, the vulnerability allows remote attackers to execute code without credentials, potentially gaining full control over affected servers and any connected systems. CISA now requires federal agencies to remediate the issue by August 27, while private organizations are urged to prioritize the patch.

A flaw with perfect conditions for attackers

CVE-2026-21962 stems from improper access control in the Oracle HTTP Server and WebLogic Proxy Plug-in components. Because exploitation requires only network access via HTTP, attackers can target exposed WebLogic instances directly from the internet. Once inside, they can read, alter, or delete sensitive data and pivot to other systems relying on the vulnerable Oracle components, thanks to the flaw’s scope-change impact. Affected versions include 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, covering widely deployed enterprise setups.

Real-world attacks already underway

Threat actors have wasted no time weaponizing the flaw. CloudSEK’s 12-day honeypot experiment in early 2026 recorded immediate exploitation of CVE-2026-21962 alongside older, high-impact WebLogic remote code execution bugs such as CVE-2020-14882/14883 and CVE-2017-10271. The data confirms attackers favor a small set of easy-to-exploit, long-standing vulnerabilities to compromise WebLogic environments, making CVE-2026-21962 the latest addition to their playbook.

Why it matters

This vulnerability represents a high-value entry point for ransomware groups and espionage actors alike, given the prevalence of Oracle WebLogic in enterprise backends. Federal deadlines force agencies to act quickly, while private firms must treat this as an urgent priority to prevent lateral movement and data breaches. Ignoring the patch risks falling victim to automated exploitation campaigns already scanning the internet for exposed instances. The episode underscores how quickly newly disclosed critical flaws become weaponized, reinforcing the need for rapid patching and continuous vulnerability monitoring.

CISA alert CVE details KEV catalog


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home