VYPR
kevPublished Aug 24, 2026· Updated Aug 25, 2026· 6 sources

CISA Adds Oracle HTTP Server and WebLogic Server Vulnerability to KEV Catalog

CISA has added CVE-2026-21962, an Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in Improper Access Control Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-21962 to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that the vulnerability, which affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, is currently being actively exploited by malicious actors in the wild.

The vulnerability, identified as an Improper Access Control issue, allows unauthorized actors to potentially gain elevated privileges or bypass security restrictions within the affected Oracle products. Such vulnerabilities are frequently targeted by cybercriminals due to their potential to compromise sensitive data or disrupt critical services.

CISA's inclusion of CVE-2026-21962 in the KEV Catalog carries significant implications, particularly for Federal Civilian Executive Branch (FCEB) agencies. These agencies are mandated by Binding Operational Directive (BOD) 26-04 to prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially those that grant total control of an asset upon exploitation and are present on publicly exposed systems.

BOD 26-04 emphasizes a risk-based approach to vulnerability management, requiring FCEB agencies to address high-risk vulnerabilities, such as CVE-2026-21962, with urgency. The directive also outlines expectations for agencies to investigate potential compromises before applying patches, ensuring a comprehensive security posture.

While BOD 26-04 specifically applies to federal agencies, CISA strongly encourages all organizations, regardless of sector, to adopt similar risk-based vulnerability management practices. Prioritizing the patching of vulnerabilities listed in the KEV Catalog is a crucial step in defending against widespread cyber threats.

CISA continues to monitor the threat landscape and will regularly update the KEV Catalog with newly identified vulnerabilities that meet the criteria of active exploitation and clear mitigation guidance. Organizations are urged to stay informed about these updates and to proactively manage their vulnerability remediation efforts.

For those who discover vulnerabilities that appear to be actively exploited but are not yet listed in the KEV Catalog, CISA provides a nomination form. This process ensures that the catalog remains a comprehensive and up-to-date resource for the cybersecurity community, helping to drive timely patching and reduce the attack surface.

This new report provides further details on the active exploitation of CVE-2026-21962, noting that threat actors have been observed attempting to exploit this and other critical Oracle WebLogic vulnerabilities concurrently. Researchers also observed exploitation attempts against other Oracle products, including Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI, indicating a broad targeting of enterprise systems.

The new article from SecurityWeek provides additional context on the exploitation of CVE-2026-21962, noting that exploitation attempts were observed as early as January 22nd, immediately after a proof-of-concept exploit was released. It also highlights that a China-linked threat actor was reportedly exploiting this vulnerability against government infrastructure in July, further underscoring the active and diverse threat landscape targeting Oracle WebLogic servers.

This new report from Cyber Security News provides additional context on the active exploitation of CVE-2026-21962, emphasizing the risk to internet-exposed Oracle infrastructure. It details how threat actors scan for vulnerable enterprise products and highlights the importance of not only patching but also implementing broader security measures like restricting administrative access and using properly configured firewalls.

This new report details that exploitation of CVE-2026-21962 was observed in the wild as early as January 2026, shortly after Oracle released patches. A security researcher's honeypot captured high-volume, automated scanning attempts targeting the vulnerability, alongside other WebLogic bugs, indicating a broad 'spray and pray' approach by threat actors.

The new article details the specific threat actor, Snowlight, linked to China's Ministry of State Security, that has been observed exploiting CVE-2026-21962. This group, associated with access brokers UNC5174 and UNC6586, incorporated the Oracle WebLogic vulnerability into a broader exploit chain targeting government and commercial infrastructure across over 100 countries, with a notable concentration on Taiwan.

Synthesized by Vypr AI