Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-21962

Oracle WebLogic/HTTP Server unauthenticated data access via HTTP

Unauthenticated HTTP access exposes critical data on Oracle HTTP Server and WebLogic Server. CVSS 10.0. CISA added to KEV August 25, 2026; active exploitation confirmed.

cat cve-2026-21962.json
Vendor
Oracle
Product
WebLogic Server / HTTP Server
CVSS
10.0
EPSS (exploit probability)
N/A
Status
kev
Published

Unauthenticated attacker with network access via HTTP can access critical data on Oracle HTTP Server and Oracle WebLogic Server. No credentials required. No user interaction required.

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 25, 2026, citing active exploitation. CVSS score: 10.0 — maximum possible severity.

Patch via Oracle’s Critical Patch Update advisory. Check Oracle Security Alerts for the current CPU containing the fix. If immediate patching is not possible, restrict HTTP access to WebLogic and HTTP Server admin interfaces from untrusted networks.

See coverage: Oracle WebLogic CVE-2026-21962 Added to CISA KEV.