Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Reported exploitedOracle HTTP ServerWebLogic Server Proxy Plug-inOur summary
CISA has listed CVE-2026-21962 in its Known Exploited Vulnerabilities catalog after confirming active attacks against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This maximum-severity flaw (CVSS 10.0) stems from improper access control, allowing unauthenticated attackers over HTTP to gain full control or modify critical data. Although Oracle released patches earlier this year, threat actors have intensified exploitation efforts, with federal agencies required to remediate by August 27, 2026.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.