CISA orders immediate patch for exploited Oracle WebLogic flaw

CISA told federal agencies to patch CVE-2026-21962, a critical unauthenticated RCE in Oracle HTTP Server and the WebLogic Proxy; KEV entry added Aug. 24 with Aug. 27 deadline.

The Cybersecurity and Infrastructure Security Agency ordered federal agencies to immediately patch a critical remote code execution vulnerability in Oracle WebLogic, tracked as CVE-2026-21962. CISA added the flaw to its Known Exploited Vulnerabilities catalog on Aug. 24 and set an Aug. 27 remediation deadline. Oracle released a patch in its January 2026 security updates.

The vulnerability carries a CVSS score of 10 and affects Oracle HTTP Server and the WebLogic Server Proxy plugin, the component that connects HTTP Server to WebLogic. The flaw can be exploited without authentication by actors who can reach the affected service.

Security researchers observed exploitation attempts beginning in late January after a public proof-of-concept exploit became available. Honeypot systems and network monitoring recorded scanning and exploitation activity through spring and summer. CISA’s KEV entry does not list specific incidents that triggered the listing.

Some observed exploitation has been attributed to actors targeting government infrastructure. WebLogic instances often expose administrative and proxy interfaces on the network, which can allow remote attackers to reach these services. Successful exploitation can result in arbitrary code execution, full server compromise, data theft or use of the host for further intrusion.

CISA’s KEV catalog is used to prioritize urgent remediation for federal agencies; private organizations can use the list to guide patch programs. Administrators running Oracle HTTP Server, the WebLogic Server Proxy plugin or exposed WebLogic instances should verify they applied Oracle’s January 2026 fixes, restrict or block access to affected services where possible, and monitor logs and network traffic for indicators of compromise.

CVE-2026-21962 is one of more than a dozen WebLogic-related vulnerabilities added to CISA’s KEV list in recent months. Exploitation observed since January and the maximum severity score mean systems that remain unpatched are vulnerable.

Articles by this author