Skip to content
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Ground.News August 25, 2026

CISA has added a critical failure that affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to the known exploited vulnerabilities (KEV) catalog. Identified as CVE-2026-21962, vulnerability has received CVSS 10.0 score, maximum severity rating, and already has evidence of active exploitation. The alert puts infrastructure administrators, security teams and DevOps professionals in a situation that requires immediate attention. Fail…

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition confirms that attackers are actively exploiting the vulnerability in real-world attacks. Organizations with affected Oracle infrastructure should identify exposed systems and apply available …

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Attackers abuse a vulnerability in Oracle HTTP server and Weblogic server that allows complete compromise.

CISA Adds One Known Exploited Vulnerability to Catalog mvining Aug 24, 2026 Release DateAugust 24, 2026 DescriptionCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control VulnerabilityThis type of vulnerability is a frequent attack vector for malicious cyber actors and …

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities