Back to Feed
VulnerabilitiesAug 26, 2026

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

CISA orders federal agencies to patch actively exploited Oracle WebLogic proxy flaw by Aug 27.

Summary

CISA has issued a directive requiring federal civilian agencies to patch a critical vulnerability in Oracle WebLogic Server. The flaw, identified as CVE-2023-21931, allows unauthenticated attackers to expose or alter sensitive data. Agencies have a deadline of August 27, 2024, to implement the necessary patches, highlighting the urgency due to active exploitation.

Indicators of Compromise

  • cve — CVE-2023-21931

Entities

Oracle WebLogic Server (product)Oracle (vendor)