Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
What happened
CISA has added a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog. CVE-2026-21962 allows unauthenticated attackers with network access via HTTP to access critical data.
Why it ranks #1
Confirmed active exploitation of a maximum-severity (CVSS 10.0) vulnerability in widely used enterprise infrastructure, placing it in the highest urgency tier.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply security updates for Oracle HTTP Server and WebLogic Server immediately to remediate CVE-2026-21962.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed