CVE-2026-21962: Oracle WebLogic Flaw Exploited in the Wild
CISA has added the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in vulnerability CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Rated CVSS 10.0, the flaw is an improper access control issue: a remote unauthenticated attacker with HTTP network access can access affected instances, read protected data, or create, delete, or modify critical information. Oracle released patches in January 2026, and CISA Binding Operational Directive 26-04 gives U.S. Federal Civilian Executive Branch agencies until August 27, 2026, to apply the necessary fixes.
Exploitation is not limited to a single reported probe. GreyNoise and CloudSEK both observed activity, and CloudSEK said its honeypot captured attacks against this CVE alongside older WebLogic remote-code-execution bugs CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271. In February, the IP address 193.24.123[.]42 was observed attempting to exploit vulnerabilities in WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. The continued use of simple, high-impact flaws indicates that exposed WebLogic environments remain active targets.
Organizations should identify all HTTP Server and Proxy Plug-in deployments, verify that the January Oracle update is installed, prioritize internet-facing systems, and review web, reverse-proxy, and endpoint logs for anomalous requests or access from the reported address. Exposure can be checked with a port scanner, while transport settings and certificate health can be reviewed with an SSL/TLS checker. Investigators handling the IOC can also use a WHOIS lookup, but patching and access control remain the primary remediation because TLS alone does not prevent the HTTP exploit.