CISA has added CVE‑2026‑21962 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Oracle HTTP Server and Oracle Weblogic Server Proxy Plug‑in and is named the Oracle HTTP Server and Oracle Weblogic Server Proxy Plug‑in Improper Access Control Vulnerability. In brief, the vulnerability allows an attacker to gain unauthorised creation, deletion or modification of critical data, or to read all data accessible to the affected components.
The issue is an improper access control weakness that can be exploited remotely over network traffic. Successful exploitation can lead to full compromise of the impacted Oracle HTTP Server and Weblogic Server Proxy Plug‑in environments, enabling attackers to alter or exfiltrate sensitive information. The vulnerability carries a CVSS base score of 10.0, rating it as critical. Oracle has released a patch that addresses the flaw.
Because the vulnerability is listed in the KEV catalogue, active exploitation has been confirmed in the wild. No ransomware campaign has been publicly linked to this CVE at present. CISA has set a remediation deadline of 26 August 2026 for federal civilian executive branch (FCEB) agencies to mitigate the risk.
CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22‑01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. While this directive binds FCEB agencies, all organisations should review their exposure to Oracle HTTP Server and Weblogic Server Proxy Plug‑in and apply the available patch or mitigations as soon as practicable.
For full details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-21962 and the CISA KEV catalogue.