The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog.
The addition confirms that attackers are actively exploiting the vulnerability in real-world attacks. Organizations with affected Oracle infrastructure should identify exposed systems and apply available Oracle security updates or mitigations as a priority.
CVE-2026-21962 affects components commonly deployed in enterprise environments to route and manage web traffic for Oracle WebLogic Server applications.
Oracle HTTP Server can serve as a front-end web server, while the WebLogic proxy plug-in routes requests from the web tier to WebLogic application servers.
CISA classified the issue as an improper access control vulnerability. This weakness can occur when an application or server component fails to enforce authorization rules, potentially allowing an attacker to access functionality, resources, or backend services that should be restricted.
Public-facing Oracle HTTP Server and WebLogic Server deployments may present a particularly significant risk. Internet-exposed infrastructure is often scanned by threat actors looking for vulnerable enterprise products, including application servers, remote-access platforms, and web-facing management interfaces.
CISA said malicious cyber actors frequently exploit vulnerabilities listed in the KEV Catalog, posing significant risk to federal organizations. The agency encourages both government and private-sector defenders to treat KEV entries as high-priority remediation targets because they are backed by evidence of active exploitation.
The warning is also relevant under Binding Operational Directive 26-04, which establishes risk-based vulnerability management requirements for Federal Civilian Executive Branch agencies.
The directive requires agencies to rapidly address KEV-listed vulnerabilities on publicly exposed assets when successful exploitation could provide attackers with total control of a system.
BOD 26-04 also requires agencies to consider whether a threat actor may have compromised an affected system before a patch was deployed.
This means remediation should not end with patching. Security teams should review authentication logs, web-server access logs, proxy logs, WebLogic logs, endpoint telemetry, and network connections for signs of suspicious activity.
Organizations should first determine whether Oracle HTTP Server or the Oracle WebLogic Server Proxy Plug-in is installed in their environment.
They should then identify systems exposed to the internet, validate installed versions, consult Oracle’s security guidance, and apply fixes in accordance with change-management procedures.
Defenders should also restrict administrative access, place application servers behind properly configured reverse proxies or web application firewalls, and ensure that backend WebLogic services are not directly accessible from the internet unless operationally required.
Security teams should hunt for unusual requests targeting Oracle server paths, unexpected access to protected applications, anomalous administrative activity, newly created accounts, suspicious processes, and outbound connections from affected servers.
CISA’s KEV designation does not necessarily disclose the specific threat actor or attack campaign responsible for exploitation. However, the listing is a clear signal that organizations should not treat CVE-2026-21962 as a routine patching issue.
Active exploitation means that unpatched Oracle WebLogic and Application Server infrastructure could be targeted before standard maintenance windows.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…