Particle.news

CISA Orders 72‑Hour Patch for Critical Oracle WebLogic Flaw

Evidence of automated attacks with a vendor patch issued in January shows many internet‑exposed proxy instances remain unpatched and at immediate risk.

Overview

  • CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on Monday, Aug. 24, and gave Federal Civilian Executive Branch agencies until Aug. 27 to remediate the flaw.
  • The bug is a maximum‑severity (CVSS 10.0) unauthenticated improper access‑control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug‑in that can let attackers read, modify, create, or delete critical data reachable through the proxy.
  • Oracle released a patch in its January 2026 Critical Patch Update, so current exploitation reflects a deployment gap where internet‑facing proxy instances were left unpatched.
  • Researchers from CloudSEK and GreyNoise reported active scanning and honeypot hits beginning in February and March, and observed attackers reusing old WebLogic remote‑code‑execution flaws to compromise targets quickly.
  • Security teams are urged to inventory internet‑exposed Oracle HTTP Server and WebLogic Proxy deployments, apply the January or later cumulative patches, and hunt logs and configs for signs of prior compromise because patching does not prove a system was not already intruded upon.