Skip to content
feed: live
>_0dayNews
oracle
● Breaking

Oracle WebLogic CVE-2026-21962 Added to CISA KEV

CISA added CVE-2026-21962 to KEV on August 25. CVSS 10.0. Unauthenticated HTTP access to Oracle WebLogic and HTTP Server. Active exploitation confirmed.

Oracle WebLogic CVE-2026-21962 Added to CISA KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Confirmed. CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 25, 2026. Active exploitation against Oracle WebLogic servers is confirmed.

CVSS score: 10.0 — maximum severity. An unauthenticated attacker with network access via HTTP can access critical data on Oracle HTTP Server and Oracle WebLogic Server. No credentials. No user interaction. Network-accessible, no auth.

What’s affected

Both Oracle HTTP Server and Oracle WebLogic Server are in scope. Per The Hacker News and SecurityWeek, exploitation has been wide. WebLogic is the primary target surface based on reporting. HTTP Server is listed as affected — treat it accordingly.

NVD record: CVE-2026-21962. CVSS 10.0 confirmed.

What to do

Patch. Oracle’s Security Alerts portal is the authoritative source for the Critical Patch Update containing the fix. Federal civilian agencies are on the BOD clock as of today’s KEV addition. Everyone else: treat KEV additions as exploitation-confirmed, not theoretical — because they are.

If patching cannot happen immediately: restrict HTTP access to WebLogic admin ports and HTTP Server management interfaces from untrusted networks. Not a fix — an exposure reduction while the patch is staged.

Review WebLogic access logs for anomalous unauthenticated HTTP requests across the period before today. This flaw is being exploited at scale; if you’re internet-exposed and unpatched, forensic log review is warranted alongside patching.

Context

Oracle’s middleware stack has been under sustained pressure. CVE-2026-46817 — unauthenticated RCE in Oracle EBS Payments, CVSS 9.8 — landed on the KEV catalog in July. CVE-2025-61882 in Oracle BI Publisher was the entry point for the Estée Lauder breach attributed to Cl0p, which went undetected for eleven months.

Two Oracle KEV additions in under six weeks, both unauthenticated, both enterprise middleware. Pattern observed. Oracle enterprise stacks are being actively targeted. Patch Oracle components ahead of cycle if at all possible — queue-jumping is warranted here.

A CVE at CVSS 10.0 that is actively exploited and now in the KEV catalog is not a “patch in the next window” situation. It is a “patch before the window” situation.


CVE entry with full technical details: CVE-2026-21962.
Track Oracle security advisories and KEV additions: /topics/oracle/.

Related CVEs
  • [ CRITICAL ]CVE-2026-21962Oracle WebLogic/HTTP Server unauthenticated data access via HTTP

Found this useful? Share it.