CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation
CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability that can be exploited remotely via HTTP without credentials. An attacker with network access can read, modify, or delete critical data and, in some scenarios, gain very broad access to the affected Oracle components. The case is significant because it involves widely deployed enterprise software and is therefore potentially exposed across many infrastructures. Its inclusion in KEV indicates that the risk window is already open and that organizations must treat remediation as urgent. In practice, the priority is no longer theoretical assessment but the immediate reduction of exposure.
Source: Security Affairs


Leave a Reply