Back to Feed
VulnerabilitiesAug 25, 2026

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA warns of exploited Oracle WebLogic vulnerability CVE-2026-21962.

Summary

CISA has issued a warning about a critical vulnerability, CVE-2026-21962, affecting Oracle WebLogic servers and Oracle HTTP Server. This remote code execution flaw, with a CVSS score of 10, has been actively exploited by threat actors since January, even before Oracle released a patch in its January 2026 updates. CISA has added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it by August 27.

Full text

The cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against Oracle WebLogic servers. The remote code execution flaw, identified as CVE-2026-21962 with a CVSS score of 10, affects Oracle HTTP Server and the WebLogic Server Proxy plugin, which bridges HTTP Server to WebLogic. The security hole can be exploited without authentication to hack affected servers. Oracle patched the vulnerability with its January 2026 updates. CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog on August 24 and instructed federal agencies to address it by August 27. [ Read: CISA Tells Federal Agencies to Prioritize Patches Based on Risk ] While the KEV list is primarily designed for government agencies, all organizations can use it to prioritize patching, alongside other tools and resources. Advertisement. Scroll to continue reading. It’s unclear which attacks triggered CISA’s alert for CVE-2026-21962. The vulnerability has been exploited since January, with the first attacks flagged by CloudSEK. The security firm warned in March that its honeypots had seen exploitation attempts aimed at Oracle WebLogic servers since January 22, immediately after a PoC exploit was made public. FalconFeeds mentioned the vulnerability’s exploitation in June, in a post describing the cybercrime supply chain. This was one of the several weaknesses exploited against enterprises, but not specific details were shared. SOCRadar reported in July that CVE-2026-21962 had been one of the several vulnerabilities exploited by a China-linked threat actor in attacks targeting government infrastructure. WebLogic servers are often targeted by hackers. CISA’s KEV catalog currently includes more than a dozen such vulnerabilities. Related: 91 Vulnerabilities Patched in Spring Application Framework Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Related: Hackers Target Zimbra Servers in Active Exploitation Campaign Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindHackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCareCloud Data Breach Impact Grows to 3.7 Million Individuals Latest News ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was LimitedHired for One Job, Judged on Another: The CISO’s Real ProblemUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachRethinking Application Security for the AI EraIran-Linked Hackers Shut Down UK Power Plant for Four Days Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveDevi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.More People On The MoveExpert Insights Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-21962

Entities

Oracle WebLogic (product)Oracle HTTP Server (product)Oracle (vendor)Oracle WebLogic Server Proxy plugin (product)China-linked threat actor (threat_actor)WebLogic Server (product)