The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. The flaw, tracked as CVE-2026-21962 with a CVSS score of 10.0, allows unauthenticated attackers to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in via HTTP.
Successful exploitation can lead to unauthorized access, modification, or deletion of critical data. CISA describes the issue as an improper access control vulnerability that could grant complete access to all accessible data on the affected components. Oracle released patches in January 2026, but active exploitation has been observed by GreyNoise and CloudSEK.
In February 2026, a single IP address (193.24.123[.]42) was seen attempting to exploit multiple known vulnerabilities, including those in Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. CloudSEK later reported attacks on its honeypot network targeting CVE-2026-21962 along with other critical WebLogic RCE flaws such as CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271. This indicates threat actors continue to rely on a small set of highly effective, simple-to-exploit vulnerabilities.
Per Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to apply fixes by August 27, 2026, to protect their networks.
CVEs: CVE-2026-21962, CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, CVE-2017-10271, CVE-2026-58231
Companies: Oracle, CISA, GreyNoise, CloudSEK
Products: Oracle HTTP Server, Oracle WebLogic Server, Oracle WebLogic Server Proxy Plug-in
Original source: thehackernews.com