Critical Oracle WebLogic Zero-Day Flaw «CVE-2026-21962» Under Active Attack

Oracle WebLogic and Oracle HTTP Server have been hit by a critical access control vulnerability (CVE-2026-21962) that’s now under active exploitation. Federal watchdog CISA has added it to its Known Exploited Vulnerabilities (KEV) list, warning that unauthenticated attackers with HTTP access can leverage the flaw to read or modify sensitive data, or take over entire servers. The Common Vulnerability Scoring System (CVSS) rates it at the maximum severity, 10.0. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

What the Vulnerability Does

The vulnerability is in the Oracle WebLogic Proxy Plug-in and Oracle HTTP Server components. Thanks to improper access controls, anyone on the network who can send HTTP requests could potentially create, delete, or alter critical data—or simply access anything they shouldn’t. All this can happen before any authentication. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

Oracle released patches for the flaw back in January 2026. Despite this, researchers with threat intelligence firms GreyNoise and CloudSEK are seeing real exploitation attempts in the wild—indicating that many systems remain vulnerable. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

Broader Attack Activity & Enforcement Mandates

Monitoring firms spotted attacks in early 2026 involving this flaw alongside others affecting WebLogic and related infrastructure. For example, an IP address flagged in February was trying to exploit several Oracle- and WebLogic-related flaws. CloudSEK also recorded this specific vulnerability in honeypot traps, along with other high-impact remote code execution bugs originally patched years ago. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

U.S. civilian federal agencies are under a tight deadline. Per Binding Operational Directive 26-04, Federal Civilian Executive Branch (FCEB) entities must apply Oracle’s patch or equivalent mitigation by August 27, 2026, or risk exposure and potential regulatory consequences. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

Even so, many non-federal organizations must stay alert: vulnerabilities like CVE-2026-21962 often spread beyond government systems to private sector and academic networks. Any system exposed to HTTP and running Oracle WebLogic, WebLogic Proxy Plug-in, or Oracle HTTP Server should be presumed at risk. Patch now. ([thehackernews.com](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html))

With the severity pegged at the highest possible level and confirmed active exploitation, CVE-2026-21962 ranks among the most serious vulnerabilities in recent memory. Though Oracle has provided a fix six months ago, the continued attacks highlight ongoing patch gaps. For organizations still vulnerable, now is the time to act. Prioritize auditing your WebLogic install footprint, verifying whether Proxy Plug-in is used, and confirming that all updates are applied with minimal delay.