All incidents

CISA adds Oracle HTTP Server flaw (CVE-2026-21962) to KEV catalog

vulnerabilityopenAug 24, 2026 — Aug 25, 2026

CISA has placed CVE‑2026‑21962 on its Known Exploited Vulnerabilities catalogue after confirming that the flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug‑in is being actively exploited, as shown in the KEV entry. The vulnerability, described as an improper access control weakness, permits a remote attacker to read, alter or delete data handled by the affected components and can lead to full compromise of the middleware layer. Federal agencies are now required to remediate the issue within the timeframe set by the KEV programme, while private organisations are urged to treat the flaw as a priority.

CVE‑2026‑21962 carries a CVSS base score of 10.0, reflecting its critical severity. The root cause is an insufficient validation of user‑supplied input in the proxy plug‑in, which allows an unauthenticated sender to craft a request that bypasses intended access restrictions. Successful exploitation grants the attacker the same privileges as the Oracle HTTP Server process, enabling the creation, deletion or modification of any file or database entry that the service can access. Oracle has released a security update that addresses the flaw in all supported releases of HTTP Server and WebLogic Server Proxy Plug‑in.

CISA’s addition to the KEV catalogue is based on telemetry that shows the flaw being used in the wild, although no specific threat actor has been publicly attributed to the activity. The exploit does not require authentication and can be launched from any network that can reach the vulnerable proxy, making it attractive for opportunistic campaigns as well as targeted intrusions. By listing the vulnerability, CISA obliges all federal civilian agencies to apply the vendor patch within the prescribed deadline and encourages private sector owners to follow the same timeline to reduce exposure.

The incident highlights a continuing focus by attackers on middleware components that sit between web front ends and application back ends, as these services often run with elevated privileges and are sometimes overlooked in patching cycles. Security researchers note that flaws involving improper access control in Oracle’s HTTP stack have appeared repeatedly over the past year, suggesting a possible gap in defensive coverage for proxy technologies.

Organisations that maintain Oracle WebLogic environments should therefore review their asset inventories and verify that any instance of the proxy plug‑in is accounted for in vulnerability management programmes.

Administrators should first confirm whether Oracle HTTP Server or the WebLogic Server Proxy Plug‑in is present in their environment, using configuration management tools or network scans to locate listening ports associated with the service. Once identified, the latest Oracle security update must be applied according to the vendor’s instructions, and a restart of the affected components may be required to complete the patching process.

After patching, organisations should examine access logs for unexpected GET or POST requests to the proxy endpoints, consider restricting inbound traffic to trusted IP ranges, and enforce the principle of least privilege for the accounts under which the Oracle processes run.

Keeping the KEV catalogue in view helps security teams prioritise remediation based on real‑world exploitation rather than theoretical severity scores. By subscribing to CISA’s updates and integrating the feed into vulnerability scanners or ticketing systems, organisations can ensure that newly added flaws such as CVE‑2026‑21962 are acted upon without delay. Continuous monitoring of vendor advisories and regular penetration testing of exposed middleware further reduce the likelihood that a similar access‑control issue will go unnoticed.

Intelligence briefing updated Aug 25, 2026

CVE-2026-21962 10.0 KEV
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline