Oracle customers running WebLogic Server or Oracle HTTP Server got an urgent reason to check their patch logs this week. The US Cybersecurity and Infrastructure Security Agency added CVE-2026-21962, a flaw carrying the maximum possible severity score of 10.0, to its Known Exploited Vulnerabilities catalog on August 24, 2026, confirming that attackers are already using it against real targets.
The bug sits in the Oracle HTTP Server and the WebLogic Server Proxy Plug-in, the component that routes web traffic between a front-end server and the WebLogic application layer behind it. According to Oracle’s advisory, the flaw is an improper access control issue that lets an attacker reach the system over plain HTTP without needing to log in first. From there, an attacker can create, delete, or modify data that should be off limits, or read information they were never meant to see. Because no authentication is required and the attack travels over ordinary web traffic, the flaw is unusually easy to weaponize at scale.
Oracle shipped a fix for the vulnerability back in January 2026 as part of its regular quarterly Critical Patch Update. Seven months later, enough servers apparently still run the vulnerable version to draw active attacker interest. Threat intelligence firms GreyNoise, CloudSEK, and SOCRadar have all reported scanning and exploitation activity tied to the flaw. GreyNoise data cited in reporting on the issue traced one wave of probing in February 2026 to a single IP address testing several known WebLogic vulnerabilities at once, this one included.
More concerning is a separate campaign tied to a China-linked hacking group, which researchers say has folded CVE-2026-21962 into a broader toolkit of WebLogic bugs to deliver malware known as SNOWLIGHT. That campaign has reportedly hit government and commercial networks in more than 100 countries, using the vulnerability chain as an initial foothold before dropping the downloader on compromised systems.
CISA’s own description of the flaw is blunt: the agency says it “can result in unauthorized creation, deletion, or modification access to critical data.” Under the Binding Operational Directive rules that govern federal civilian agencies, a KEV listing comes with a hard deadline. Agencies running the affected Oracle software have until August 27, 2026, roughly 72 hours after the catalog addition, to apply the patch or otherwise take the systems out of reach of attackers.
Private organizations are not bound by that federal deadline, but security teams generally treat a KEV listing as a strong signal to patch without delay regardless of sector. Given that a fix has been available for more than half a year and exploitation is already documented by multiple independent researchers, anyone still running an unpatched Oracle HTTP Server or WebLogic Server Proxy Plug-in should move this to the top of the queue.
Source: The Hacker News, reporting on CISA’s Known Exploited Vulnerabilities catalog addition for CVE-2026-21962.
