THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle vulnerability, tracked as CVE-2026-21962 with a CVSS score of 10.0, to its Known Exploited Vulnerabilities catalog. This unauthenticated flaw affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, allowing attackers to remotely exploit the flaw via HTTP without needing valid credentials. Exploitation could lead to unauthorized access and modification of critical data.
The vulnerability, which impacts specific versions of Oracle's software, poses significant risks as it can potentially allow attackers access to backend systems without authentication. CISA has mandated that federal agencies address this vulnerability by August 27, 2026.