FRIDAY, AUGUST 28, 2026
STRIDING TECH · THREAT INTELLIGENCE

Security Advisory & Threat Intelligence Report

Vulnerability root-cause analysis, exploit attack surface telemetry, and vendor mitigation engineering.

THREAT REPORT CYBERSECURITY · August 25, 2026

Maximum-Severity Oracle Flaw CVE-2026-21962 Actively Exploited, Added to CISA KEV Catalog

Maximum-Severity Oracle Flaw CVE-2026-21962 Actively Exploited, Added to CISA KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities (KEV) catalog. This action follows documented evidence of active exploitation targeting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in deployments.

The vulnerability, which Oracle patched in January 2026, allows unauthenticated attackers with network access via HTTP to compromise affected servers.

? WHY IT MATTERS
  • Critical Data Compromise: A successful exploit permits unauthenticated creation, deletion, or modification of critical data, alongside unauthorized access to sensitive information. This directly impacts data integrity and confidentiality for enterprises utilizing these Oracle components.
  • Mandatory Federal Remediation: Inclusion in CISA’s KEV catalog mandates federal civilian executive branch (FCEB) agencies to apply necessary fixes by August 27, 2026, under Binding Operational Directive (BOD) 26-04. This underscores the immediate and significant risk.
  • Persistent Threat Vector: Threat actors continue to leverage this and other critical, yet patched, WebLogic flaws, indicating a reliance on unaddressed vulnerabilities for initial access and broader system compromise.

The vulnerability, tracked as CVE-2026-21962, carries a CVSS score of 10.0, denoting maximum severity. This improper access control flaw (CWE-284) primarily impacts Oracle HTTP Server and the WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS. It arises from the plug-in’s inadequate validation and enforcement of access controls on incoming HTTP requests.

Exploitation requires only unauthenticated network access via HTTP, enabling attackers to bypass authentication mechanisms. This can lead to unauthorized access to critical data or even complete access to all data accessible through the affected Oracle HTTP Server and WebLogic Server Proxy Plug-in instances. The vulnerability also presents a “scope-change” impact, meaning exploitation can affect systems or applications beyond the initially compromised component.

Oracle released patches for CVE-2026-21962 in its January 2026 Critical Patch Update (CPU). Despite patch availability, active exploitation has been observed by multiple threat intelligence firms, including GreyNoise and CloudSEK. A specific IP address, “193.24.123[.]42,” was identified in February 2026 attempting to exploit this and other known WebLogic vulnerabilities. CloudSEK further reported observing exploitation efforts against its honeypot network in March 2026.

Affected versions include Oracle HTTP Server and WebLogic Server Proxy Plug-in versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. For WebLogic Server Proxy Plug-in for IIS, only version 12.2.1.4.0 is impacted.

STRIDING TECH WIRE WEEKLY RADAR

Weekly Technology Briefings

Multi-source tech synthesis, primary research breakdowns, and high-impact insights delivered every Sunday morning.

Strategic Outlook & Next Milestones

The inclusion of CVE-2026-21962 in CISA’s KEV catalog signifies that this vulnerability is not merely theoretical but is actively being leveraged by malicious actors. Organizations operating Oracle HTTP Server and WebLogic Server Proxy Plug-in deployments must prioritize the immediate application of Oracle’s January 2026 CPU to mitigate this critical risk.

Beyond patching, enterprises should implement robust network segmentation and ingress filtering to restrict access to WebLogic Proxy Plug-in endpoints to trusted sources only, where immediate patching is not feasible. Ongoing monitoring of HTTP traffic and access logs for indicators of compromise remains crucial to detect potential prior exploitation and unauthorized data access. This event underscores the continuous operational imperative for timely patch management and adherence to CISA’s directives for critical infrastructure protection.

Type a keyword to instantly search articles, research papers, and breaking news.
STRIDING TECH INTELLIGENCE WIRE

Weekly Technology Briefings

Multi-source tech synthesis, primary research breakdowns, and high-impact tech news delivered every Sunday morning.

No spam. One-click unsubscribe at any time.