www.securityweek.com 8/25/2026, 8:01:12 AM · external

CISA urges patch of critical Oracle WebLogic flaw CVE-2026-21962

CISA urges patch of critical Oracle WebLogic flaw CVE-2026-21962
Developing story vulnerability 4 articles tracked
CISA adds Oracle HTTP Server flaw (CVE-2026-21962) to KEV catalog
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE cybersecurity agency CISA has urged government organizations to immediately patch a critical vulnerability in Oracle WebLogic servers, identified as CVE-2026-21962, which can be exploited for remote code execution without authentication. This vulnerability, with a CVSS score of 10, affects both Oracle HTTP Server and the WebLogic Server Proxy plugin. CISA included it in its Known Exploited Vulnerabilities (KEV) catalog and directed federal agencies to address it promptly.

The issue has been actively exploited since January, with attackers targeting it shortly after a proof-of-concept exploit was made publicly available. Security firms reported that various threat actors, including a China-linked group, have exploited this vulnerability for attacks on government infrastructure. CISA’s KEV list is a tool for organizations to prioritize patching efforts.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline