CISA adds Oracle HTTP Server flaw to KEV
CISA added an actively exploited improper access control flaw in Oracle HTTP Server and WebLogic Proxy Plug-in to its Known Exploited Vulnerabilities catalog.
CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of vulnerabilities in the KEV Catalog, particularly those on publicly exposed assets that could grant an attacker total control post-exploitation, and to verify whether systems were compromised prior to patching.
While BOD 26-04 formally applies only to FCEB agencies, CISA recommends that all organizations running affected Oracle HTTP Server or WebLogic Server Proxy Plug-in deployments treat this as a priority patching item and review exposure of internet-facing instances. No technical details of the exploitation method, threat actor, or malware involved were disclosed in this advisory; organizations should consult Oracle's security advisories for patch information and apply updates promptly.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free