The images in this article were generated with artificial intelligence. How we publish
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-21962, qualified with the maximum score 10.0 on the CVSS scale. According to the entry in the catalogue, there are signs of active exploitation affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in: an unauthenticated attacker with network access via HTTP could achieve unauthorized access or modify critical data in vulnerable instances. Oracle published patches for this problem in January; however, CISA and Internet monitoring groups point to attempts at abuse after that date, which motivates the Federal Administration to require corrections for its agencies before 27 August 2026 under the Binding Operational Directive 26-04.
Technically, vulnerability is reported as an access control failure in the Proxy Plug-in that accompanies Oracle HTTP Server and WebLogic. In general terms, a proxy plug-in receives and directs HTTP requests to the application server; if that component does not properly value permissions or parameters, an attacker can send specially built requests that the plug-in process with privileges that should not be granted. The result described by CISA includes the possibility of creating, eliminating or modifying critical data and, in more serious scenarios, fully access all the information to which the plug-in has access. Although the operating details are kept technical and, in some cases, reserved for security reasons, the key feature is that the vector is HTTP without prior authentication, which facilitates the attack on services exposed to the Internet.

Those at risk are organizations that maintain public or accessible implementation in network of Oracle HTTP Server and / or WebLogic with the vulnerable plug- in without patching. This includes business servers, web portals and front-end layers that act as a gateway to critical applications. CISA has added the entry to the KEV catalogue precisely because the combination of remote vulnerability, easy exploitation and frequent presence in corporate infrastructure increases the likelihood of serious commitments. The risk is particularly high for environments with exposed management interfaces or for networks where segmentation and filtering do not limit HTTP traffic to confidence devices.
There is public evidence of attempts to operate after the publication of patches: reports of Internet intelligence services mention activity from specific directions (for example, the IP reported as "193.24.123 [.] 42" in February 2026 observations) trying to exploit multiple historical vulnerabilities of WebLogic and other products, and observations on honeypots that show simultaneous exploitation of persistent failures in WebLogic (including old ETS 2017 and 2020). These observations confirm an operational pattern: attackers re-use a small set of well-known and proven WebLogic deployments that remain unpatched. However, data such as the exact number of systems involved, responsible actors and geographical scope of the campaign remain incomplete or to be confirmed publicly.
The specific technical and operational consequences can range from the exposure of sensitive data and the handling of web content to the installation of back doors, ransomware or pivoting to internal networks. In federal environments, gravity motivated inclusion in KEV and the mandatory correction directive. For the private sector, the potential speed of operation and the ease of the vector mean that the exposure window - from the patch publication to its application in production - is the most dangerous period.
Recommended actions - priority and concrete - for managers and security officials:
1) Apply the patch with priority. Install the updates published by Oracle for CVE-2026-21962 on all affected servers, including testing and production environments. If the update should be delayed for compatibility, plan immediate compensatory mitigation and an accelerated test and deployment route.
2) Reduce network exposure. Block direct public access to Oracle HTTP Server and WebLogic through firewall rules and access control lists (ACL). Limit HTTP connections to known administrative addresses or networks and use private networks or VPNs for management.
3) Implement protection in the HTTP layer. Unfold or adjust rules in WAFs (Web Application Firewalls) and IPS / IDS to detect and block abnormal request patterns to endpoints related to the Proxy Plug-in and WebLogic's administrative interfaces. Make sure that the heuristic signatures and signatures are updated.
4) Monitoring and seeking evidence of exploitation. Review web and applications for unusual applications, especially POST or GET with atypical loads, attempts to access administrative routes and unauthorized modifications of files or configurations. Correlate with access from suspicious PIs (such as the one already reported) and mark "create / delete / modify" events on critical data. If signs of commitment are detected, isolate the system and proceed to a complete forensic response.
5) Prepare response and recovery. For systems that show signs of intrusion, consider reconstruction from clean images and the rotation of credentials. Keep an updated inventory of WebLogic / Oracle HTTP Server instances to prioritize interventions and ensure that backup and restoration procedures are validated.

Public sources recommended to contrast and obtain patches: the corresponding entry in the CISA KEV catalogue and the Oracle safety notices page. It is also useful to consult the official CVE record for technical details when available. Reference links: CISA KEV catalog, Oracle Security Alerts and the CVE tab in MITRE (when published): MITRE CVE.
Confirmed facts: CISA included CVE-2026-21962 in KEV and rated vulnerability as of maximum impact; Oracle published patches in January; external observers recorded subsequent attempts at exploitation. Estimates: the ease of operation and frequency of WebLogic deployments pose a high risk to many organizations; the reuse of old vulnerabilities suggests persistent tactics of opportunistic actors. Information still uncertain: the real scope of commitments in the nature, identity or motivation of the attackers and the existence of widespread public exploits beyond the attempts detected on honeypots and Internet sensors.
If you manage WebLogic or Oracle HTTP Server servers, treat this alert as a priority: park, reduce exposure and increase detection. The window to avoid real commitments remains narrow, and evidence of active attempts already documented shows that attackers systematically explore infrastructure that remains unupdated.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...

Npm campaign installs RedC2 4.0 when importing malicious packages
Cybersecurity researchers have found a malicious package campaign in the npm ecosystem that, at first sight, provide calendar and calculation utilities but actually serve as a v...