TechNewsReel
Live

CISA Adds Critical Oracle WebLogic Flaw to Known Exploited Catalog

A CVSS 10.0 vulnerability allows unauthenticated attackers to modify or delete critical data via HTTP.

TechNewsReel Newsroom · August 25, 2026

CISA has added a critical security vulnerability in Oracle software to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-21962, is currently being exploited in the wild to target enterprise infrastructure.

The vulnerability affects both the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. According to data from The Hacker News and security advisories, the flaw allows unauthenticated attackers with network access via HTTP to access, create, delete, or modify critical data. The vulnerability carries a CVSS 3.1 base score of 10.0, the highest possible severity rating, reflecting the ease of exploitation and the potential for total system compromise.

The Enterprise Edge

Oracle WebLogic and Oracle HTTP Server serve as foundational middleware and web server solutions for thousands of global enterprises. Because these components typically reside at the edge of corporate networks, they act as the primary gateway for external traffic reaching internal applications. This positioning makes them high-value targets for threat actors, as a single breach at the proxy or server level can provide a foothold into the rest of the corporate environment and expose sensitive application data.

Systemic Risk

A CVSS 10.0 rating indicates that the flaw requires no special privileges and can be triggered remotely, making it a prime candidate for automated exploitation scripts. The ability for an unauthenticated user to not only read but also modify or delete critical data represents a catastrophic failure of access control. By adding the flaw to the KEV catalog on August 24, 2026, CISA has mandated that federal agencies patch the vulnerability immediately, a move that signals an urgent risk to the broader global infrastructure beyond the U.S. government.

Immediate Remediation\Organizations utilizing Oracle HTTP Server or the WebLogic Server Proxy Plug-in are urged to apply the latest security updates provided by Oracle. Security teams should prioritize these patches given the confirmed active exploitation. Until updates are deployed, administrators are advised to monitor HTTP traffic for unusual patterns targeting these services, though the severity of the flaw suggests that patching is the only reliable defense against this specific attack vector.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.