CISA Adds Critical Oracle Vulnerability to KEV Catalog Amidst Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, adding a maximum-severity flaw affecting **Oracle HTTP Server** and **Oracle WebLogic Server** to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as **CVE-2026-21962**, this vulnerability is actively being exploited, posing a significant risk of unauthorized access and data manipulation.
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has escalated warnings regarding a critical security vulnerability, **CVE-2026-21962**, by including it in its **Known Exploited Vulnerabilities (KEV)** catalog. This move underscores the urgency for organizations to patch their systems, as evidence of active exploitation has been observed.

### The Vulnerability at a Glance
**CVE-2026-21962**, with a **CVSS score of 10.0**, represents a severe improper access control flaw within **Oracle HTTP Server** and **Oracle WebLogic Server Proxy Plug-in**. This allows an unauthenticated attacker, with network access via HTTP, to compromise affected instances. Successful exploitation can lead to unauthorized access, creation, deletion, or modification of critical data.
**CISA** explicitly stated that the vulnerability "can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all **Oracle HTTP Server** and **Oracle WebLogic Server Proxy Plug-in** accessible data."
### Active Exploitation Confirmed
While **Oracle** released patches for **CVE-2026-21962** in January, various private sector reports from cybersecurity firms like **GreyNoise**, **CloudSEK**, and **SOCRadar** confirm ongoing active exploitation efforts.
In February 2026, a specific IP address (**193.24.123[.]42**) was identified attempting to exploit this and other known vulnerabilities across **Oracle WebLogic**, **Ivanti Endpoint Manager Mobile**, **GNU InetUtils**, and **GLPI**. A month later, **CloudSEK** reported observing exploitation attempts against its honeypot network.
### Link to State-Sponsored Activity
**CVE-2026-21962** is also among several vulnerabilities utilized by a China-linked threat actor. This sophisticated group has been targeting government and commercial infrastructure in over 100 countries to deploy the **SNOWLIGHT** downloader, indicating a broader, more strategic campaign.
**CloudSEK** further noted that its honeypot captured attacks targeting other persistent and critical **WebLogic RCE** flaws, including **CVE-2020-14882/14883** (Console RCE), **CVE-2020-2551** (IIOP RCE), and **CVE-2017-10271** (WLS-WSAT RCE). This highlights a consistent pattern where threat actors leverage a small set of highly effective, easy-to-exploit vulnerabilities to compromise **WebLogic** environments.
### Mandate for Federal Agencies
In response to this critical threat, **CISA** has issued **Binding Operational Directive (BOD) 26-04**. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies apply the necessary fixes for **CVE-2026-21962** by August 27, 2026, to protect their networks from potential compromise. All organizations, regardless of their federal affiliation, are strongly advised to follow suit and prioritize patching.