Home Active Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
ActiveCybersecurity

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Share
actively-exploited-oracle-weblogic-flaw-lets-unauthenticated-attackers-access-critical-data
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Share

Ravie LakshmananAug 25, 2026Vulnerability / Enterprise Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data.

“Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data,” CISA said.

While patches for the flaw were released by Oracle earlier this January, it has since witnessed active exploitation efforts, per multiple reports from GreyNoise and CloudSEK.

In February 2026, it emerged that a lone IP address (“193.24.123[.]42”) was attempting to exploit multiple known vulnerabilities impacting Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. A month later, CloudSEK reported seeing exploitation efforts aimed at its honeypot network.

“In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE),” CloudSEK noted at the time. “This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.”

Pursuant to Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies have been recommended to apply necessary fixes by August 27, 2026, to safeguard their networks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Share
Related Articles

New Zealand Pledges Under-16 Social Media Ban, Big Tech Required to Infer User Age

New Zealand is the latest country to try ban under-16-year-olds from accessing...

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Ravie LakshmananAug 25, 2026Vulnerability / Web Security Bad actors are attempting to...

Left-handed people tend to be left-leaning voters

Political preferences are generally explained by income, age and level of education....

The Medicines Patent Pool is improving access to essential medication where it’s most needed, but does it make economic sense?

The Medicines Patent Pool (MPP) is a not-for-profit organisation founded in 2010...