Oracle WebLogic/HTTP Server unauthenticated data access via HTTP
Unauthenticated HTTP access exposes critical data on Oracle HTTP Server and WebLogic Server. CVSS 10.0. CISA added to KEV August 25, 2026; active exploitation confirmed.
- Vendor
- Oracle
- Product
- WebLogic Server / HTTP Server
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
Unauthenticated attacker with network access via HTTP can access critical data on Oracle HTTP Server and Oracle WebLogic Server. No credentials required. No user interaction required.
CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 25, 2026, citing active exploitation. CVSS score: 10.0 — maximum possible severity.
Patch via Oracle’s Critical Patch Update advisory. Check Oracle Security Alerts for the current CPU containing the fix. If immediate patching is not possible, restrict HTTP access to WebLogic and HTTP Server admin interfaces from untrusted networks.
See coverage: Oracle WebLogic CVE-2026-21962 Added to CISA KEV.
