CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic

Author: Published 5 min de lectura 13 reading

The images in this article were generated with artificial intelligence. How we publish

The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-21962, qualified with the maximum score 10.0 on the CVSS scale. According to the entry in the catalogue, there are signs of active exploitation affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in: an unauthenticated attacker with network access via HTTP could achieve unauthorized access or modify critical data in vulnerable instances. Oracle published patches for this problem in January; however, CISA and Internet monitoring groups point to attempts at abuse after that date, which motivates the Federal Administration to require corrections for its agencies before 27 August 2026 under the Binding Operational Directive 26-04.

Technically, vulnerability is reported as an access control failure in the Proxy Plug-in that accompanies Oracle HTTP Server and WebLogic. In general terms, a proxy plug-in receives and directs HTTP requests to the application server; if that component does not properly value permissions or parameters, an attacker can send specially built requests that the plug-in process with privileges that should not be granted. The result described by CISA includes the possibility of creating, eliminating or modifying critical data and, in more serious scenarios, fully access all the information to which the plug-in has access. Although the operating details are kept technical and, in some cases, reserved for security reasons, the key feature is that the vector is HTTP without prior authentication, which facilitates the attack on services exposed to the Internet.

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
Image generated with IA.

Those at risk are organizations that maintain public or accessible implementation in network of Oracle HTTP Server and / or WebLogic with the vulnerable plug- in without patching. This includes business servers, web portals and front-end layers that act as a gateway to critical applications. CISA has added the entry to the KEV catalogue precisely because the combination of remote vulnerability, easy exploitation and frequent presence in corporate infrastructure increases the likelihood of serious commitments. The risk is particularly high for environments with exposed management interfaces or for networks where segmentation and filtering do not limit HTTP traffic to confidence devices.

There is public evidence of attempts to operate after the publication of patches: reports of Internet intelligence services mention activity from specific directions (for example, the IP reported as "193.24.123 [.] 42" in February 2026 observations) trying to exploit multiple historical vulnerabilities of WebLogic and other products, and observations on honeypots that show simultaneous exploitation of persistent failures in WebLogic (including old ETS 2017 and 2020). These observations confirm an operational pattern: attackers re-use a small set of well-known and proven WebLogic deployments that remain unpatched. However, data such as the exact number of systems involved, responsible actors and geographical scope of the campaign remain incomplete or to be confirmed publicly.

The specific technical and operational consequences can range from the exposure of sensitive data and the handling of web content to the installation of back doors, ransomware or pivoting to internal networks. In federal environments, gravity motivated inclusion in KEV and the mandatory correction directive. For the private sector, the potential speed of operation and the ease of the vector mean that the exposure window - from the patch publication to its application in production - is the most dangerous period.

Recommended actions - priority and concrete - for managers and security officials:

1) Apply the patch with priority. Install the updates published by Oracle for CVE-2026-21962 on all affected servers, including testing and production environments. If the update should be delayed for compatibility, plan immediate compensatory mitigation and an accelerated test and deployment route.

2) Reduce network exposure. Block direct public access to Oracle HTTP Server and WebLogic through firewall rules and access control lists (ACL). Limit HTTP connections to known administrative addresses or networks and use private networks or VPNs for management.

3) Implement protection in the HTTP layer. Unfold or adjust rules in WAFs (Web Application Firewalls) and IPS / IDS to detect and block abnormal request patterns to endpoints related to the Proxy Plug-in and WebLogic's administrative interfaces. Make sure that the heuristic signatures and signatures are updated.

4) Monitoring and seeking evidence of exploitation. Review web and applications for unusual applications, especially POST or GET with atypical loads, attempts to access administrative routes and unauthorized modifications of files or configurations. Correlate with access from suspicious PIs (such as the one already reported) and mark "create / delete / modify" events on critical data. If signs of commitment are detected, isolate the system and proceed to a complete forensic response.

5) Prepare response and recovery. For systems that show signs of intrusion, consider reconstruction from clean images and the rotation of credentials. Keep an updated inventory of WebLogic / Oracle HTTP Server instances to prioritize interventions and ensure that backup and restoration procedures are validated.

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
Image generated with IA.

Public sources recommended to contrast and obtain patches: the corresponding entry in the CISA KEV catalogue and the Oracle safety notices page. It is also useful to consult the official CVE record for technical details when available. Reference links: CISA KEV catalog, Oracle Security Alerts and the CVE tab in MITRE (when published): MITRE CVE.

Confirmed facts: CISA included CVE-2026-21962 in KEV and rated vulnerability as of maximum impact; Oracle published patches in January; external observers recorded subsequent attempts at exploitation. Estimates: the ease of operation and frequency of WebLogic deployments pose a high risk to many organizations; the reuse of old vulnerabilities suggests persistent tactics of opportunistic actors. Information still uncertain: the real scope of commitments in the nature, identity or motivation of the attackers and the existence of widespread public exploits beyond the attempts detected on honeypots and Internet sensors.

If you manage WebLogic or Oracle HTTP Server servers, treat this alert as a priority: park, reduce exposure and increase detection. The window to avoid real commitments remains narrow, and evidence of active attempts already documented shows that attackers systematically explore infrastructure that remains unupdated.

Coverage

Related

More news on the same subject.