Heise.De
Critical Oracle WebLogic Flaw Under Active Exploitation
Article Content
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog. This flaw, with a CVSS score of 10.0, allows unauthenticated attackers to gain unauthorized access to critical data. Affected versions include 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. CISA has urged organizations to patch the vulnerability within three days due to evidence of active exploitation. The vulnerability was first disclosed in January 2026, with proof-of-concept code available shortly after. Attackers can exploit this flaw via manipulated URIs, leading to complete compromise of vulnerable systems. Organizations are advised to treat any exposed Oracle systems as compromised until patched. The situation is urgent as attacks have already been observed targeting this vulnerability.
Key Points: • CVE-2026-21962 has a CVSS score of 10.0 and allows unauthenticated access. • CISA requires federal agencies to patch this vulnerability within three days. • Active exploitation of this flaw has been confirmed, with attacks already underway.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.