CISA orders federal agencies to patch exploited Oracle WebLogic flaw by Aug. 27
This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency added a maximum-severity Oracle WebLogic vulnerability to its Known Exploited Vulnerabilities catalog on Aug. 24, giving federal agencies until Aug. 27 to patch. The flaw, CVE-2026-21962, allows unauthenticated attackers to access critical data via crafted HTTP requests. A China-linked threat actor has already exploited the bug in campaigns targeting government infrastructure across more than 100 countries.
Key Facts
- CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on Aug. 24, 2026, with a federal patch deadline of Aug. 27.
- The vulnerability affects Oracle Fusion Middleware's HTTP Server and WebLogic Server Proxy Plug-in components in Apache HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and IIS version 12.2.1.4.0.
- SOCRadar reported in July 2026 that a China-linked threat actor tracked as Snowlight used the flaw as one of 11 exploit chains targeting government and commercial infrastructure across more than 100 countries.
- Oracle disclosed and patched the vulnerability in January 2026, but exploitation by a state-linked actor was observed within weeks.
The Vulnerability
CVE-2026-21962 is an authentication bypass flaw in the Oracle WebLogic Server Proxy Plug-in that allows unauthenticated attackers with network access via HTTP to compromise Oracle HTTP Server and the WebLogic Server Proxy Plug-in. The flaw exists in the request handling logic of the proxy plug-in component that connects front-end web servers such as Apache HTTP Server or IIS to backend WebLogic Server instances. SentinelOne noted that the WebLogic Server Proxy Plug-in does not properly validate or enforce access controls on incoming HTTP requests before processing them. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as complete access to all data accessible through the proxy plug-in.
Exploitation Campaign
SOCRadar reported in July 2026 that a threat actor tracked as Snowlight by Google and linked to Chinese access brokers UNC5174 and UNC6586 incorporated the Oracle WebLogic vulnerability into one of 11 distinct exploit chains assembled from public GitHub proof-of-concepts. The campaign targeted government and commercial infrastructure across more than 100 countries, with activity concentrated heavily on Taiwan. Adrian Culley, offensive security engineer at SafeBreach, said the window between Oracle's January patch and state-linked actor operational use was measured in weeks, not months. Culley added that reported campaigns like this rarely win on novel tooling but succeed because internet-facing proxy components sit outside the inventory and monitoring that the application server itself receives.
Federal Response
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Aug. 24, 2026, and gave federal agencies until Aug. 27 to apply Oracle's January patch. The three-day deadline reflects the maximum-severity rating and active exploitation status of the flaw. Security firm SentinelOne said attackers could bypass intended access restrictions through network-based HTTP requests after identifying servers running the vulnerable WebLogic Server Proxy Plug-in configuration.
2 sources
CISA orders federal agencies to patch exploited Oracle WebLogic flaw by Aug. 27



