securityaffairs.com 8/25/2026, 9:40:59 AM · external

CISA flags Oracle flaw CVE-2026-21962, orders patch by Aug 27

CISA flags Oracle flaw CVE-2026-21962, orders patch by Aug 27
Developing story vulnerability 6 articles tracked
CISA adds exploited Oracle HTTP Server flaw CVE-2026-21962 to KEV catalog
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle vulnerability, tracked as CVE-2026-21962 with a CVSS score of 10.0, to its Known Exploited Vulnerabilities catalog. This unauthenticated flaw affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, allowing attackers to remotely exploit the flaw via HTTP without needing valid credentials. Exploitation could lead to unauthorized access and modification of critical data.

The vulnerability, which impacts specific versions of Oracle's software, poses significant risks as it can potentially allow attackers access to backend systems without authentication. CISA has mandated that federal agencies address this vulnerability by August 27, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline