VYPR
kevPublished Aug 24, 2026· 1 source

CISA Adds Oracle HTTP Server and WebLogic Server Vulnerability to KEV Catalog

CISA has added CVE-2026-21962, an Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in Improper Access Control Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-21962 to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that the vulnerability, which affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, is currently being actively exploited by malicious actors in the wild.

The vulnerability, identified as an Improper Access Control issue, allows unauthorized actors to potentially gain elevated privileges or bypass security restrictions within the affected Oracle products. Such vulnerabilities are frequently targeted by cybercriminals due to their potential to compromise sensitive data or disrupt critical services.

CISA's inclusion of CVE-2026-21962 in the KEV Catalog carries significant implications, particularly for Federal Civilian Executive Branch (FCEB) agencies. These agencies are mandated by Binding Operational Directive (BOD) 26-04 to prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially those that grant total control of an asset upon exploitation and are present on publicly exposed systems.

BOD 26-04 emphasizes a risk-based approach to vulnerability management, requiring FCEB agencies to address high-risk vulnerabilities, such as CVE-2026-21962, with urgency. The directive also outlines expectations for agencies to investigate potential compromises before applying patches, ensuring a comprehensive security posture.

While BOD 26-04 specifically applies to federal agencies, CISA strongly encourages all organizations, regardless of sector, to adopt similar risk-based vulnerability management practices. Prioritizing the patching of vulnerabilities listed in the KEV Catalog is a crucial step in defending against widespread cyber threats.

CISA continues to monitor the threat landscape and will regularly update the KEV Catalog with newly identified vulnerabilities that meet the criteria of active exploitation and clear mitigation guidance. Organizations are urged to stay informed about these updates and to proactively manage their vulnerability remediation efforts.

For those who discover vulnerabilities that appear to be actively exploited but are not yet listed in the KEV Catalog, CISA provides a nomination form. This process ensures that the catalog remains a comprehensive and up-to-date resource for the cybersecurity community, helping to drive timely patching and reduce the attack surface.

Synthesized by Vypr AI
CISA Adds Oracle HTTP Server and WebLogic Server Vulnerability to KEV Catalog · VYPR