Overview
- CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on Monday and required Federal Civilian Executive Branch agencies to remediate the flaw by August 27 under BOD 26-04.
- The bug is a CVSS 10.0 improper access-control vulnerability in Oracle HTTP Server and the WebLogic Server Proxy plug-in that allows unauthenticated HTTP requests to access, create, modify, or delete critical data.
- Oracle published fixes in its January 2026 Critical Patch Update, but telemetry from honeypots and scanners has shown active exploitation since February, which security firms link to unpatched, internet-facing deployments rather than lack of a vendor patch.
- Security researchers observed scanning and exploit attempts, including a recurring probe from IP 193.24.123[.]42 and honeypot captures that show attackers dropping web shells and running discovery commands.
- CISA's action, coupled with KEV additions for other in-the-wild flaws such as a Citrix NetScaler bug, signals a wider pattern of attackers targeting exposed management and proxy services and underlines the need for immediate inventory, patching, and retrospective log hunting.