CISA Adds Critical Oracle WebLogic Flaw to Known Exploited Catalog
A CVSS 10.0 vulnerability allows unauthenticated attackers to modify or delete critical data via HTTP.
CISA has added a critical security vulnerability in Oracle software to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-21962, is currently being exploited in the wild to target enterprise infrastructure.
The vulnerability affects both the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. According to data from The Hacker News and security advisories, the flaw allows unauthenticated attackers with network access via HTTP to access, create, delete, or modify critical data. The vulnerability carries a CVSS 3.1 base score of 10.0, the highest possible severity rating, reflecting the ease of exploitation and the potential for total system compromise.
The Enterprise Edge
Oracle WebLogic and Oracle HTTP Server serve as foundational middleware and web server solutions for thousands of global enterprises. Because these components typically reside at the edge of corporate networks, they act as the primary gateway for external traffic reaching internal applications. This positioning makes them high-value targets for threat actors, as a single breach at the proxy or server level can provide a foothold into the rest of the corporate environment and expose sensitive application data.
Systemic Risk
A CVSS 10.0 rating indicates that the flaw requires no special privileges and can be triggered remotely, making it a prime candidate for automated exploitation scripts. The ability for an unauthenticated user to not only read but also modify or delete critical data represents a catastrophic failure of access control. By adding the flaw to the KEV catalog on August 24, 2026, CISA has mandated that federal agencies patch the vulnerability immediately, a move that signals an urgent risk to the broader global infrastructure beyond the U.S. government.