mimile
Back to feed

CISA Orders Federal Agencies to Patch Exploited Oracle WebLogic Flaw by August 27

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

CISA Orders Federal Agencies to Patch Exploited Oracle WebLogic Flaw by August 27

CISA has added CVE-2026-21962, a critical Oracle WebLogic Server vulnerability with a CVSS score of 10, to its Known Exploited Vulnerabilities catalog. Federal agencies must patch the flaw by August 27, 2026. The vulnerability has been actively exploited since January 2026, with attacks reported by CloudSEK and SOCRadar.

Key Facts

  • CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24, 2026.
  • The vulnerability has a CVSS score of 10.0 and affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
  • Oracle released patches for the flaw in January 2026.
  • CloudSEK reported exploitation attempts against its honeypots starting January 22, 2026.
  • SOCRadar reported in July 2026 that a China-linked threat actor exploited CVE-2026-21962 in attacks on government infrastructure.

CISA Directive

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24, 2026. Federal agencies must remediate the vulnerability by August 27, 2026. The KEV catalog is primarily intended for government agencies, but CISA recommends all organizations use it to prioritize patching.

Vulnerability Details

CVE-2026-21962 is a remote code execution flaw with a CVSS score of 10.0. It affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise affected systems. Successful exploitation can lead to unauthorized access to instances or modification of critical data. Oracle patched the vulnerability in its January 2026 updates.

Exploitation Activity

CloudSEK warned in March 2026 that its honeypots had seen exploitation attempts aimed at Oracle WebLogic servers since January 22, 2026. The first attacks were flagged by CloudSEK immediately after a proof-of-concept exploit was made public. In February 2026, a lone IP address attempted to exploit multiple known vulnerabilities, including CVE-2026-21962, according to GreyNoise. SOCRadar reported in July 2026 that CVE-2026-21962 was among several vulnerabilities exploited by a China-linked threat actor in attacks targeting government infrastructure. CISA's KEV catalog currently includes more than a dozen WebLogic-related vulnerabilities.

2 sources

CISA Orders Federal Agencies to Patch Exploited Oracle WebLogic Flaw by August 27