rootpwn

Advisories

CISA Adds Oracle WebLogic CVE‑2026‑21962 to Known Exploited Vulnerabilities Catalog

CISA has expanded its Known Exploited Vulnerabilities (KEV) list by adding CVE‑2026‑21962, an improper access‑control flaw in Oracle HTTP Server and WebLogic Server Proxy Plug‑in. The vulnerability allows attackers to gain full control over exposed assets. Federal agencies are urged to patch immediately under BOD 26‑04, which prioritizes remediation of KEV items on publicly reachable systems. All organizations are encouraged to adopt risk‑based vulnerability management and report any newly exploited CVEs through CISA’s nomination form.

CISA has just added a new entry to its Known Exploited Vulnerabilities (KEV) catalog: CVE‑2026‑21962. The flaw resides in the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug‑in, where improper access control can let attackers assume complete control of an exposed system.

Why It Matters

Exploited vulnerabilities are the most dangerous type of risk for any organization, especially for federal agencies that manage sensitive data and critical services. The new CVE is a classic example of a high‑impact attack vector that can be leveraged by malicious actors to compromise entire networks.

BOD 26‑04: A Federal Mandate

The recent directive, Prioritizing Security Updates Based on Risk, mandates that Federal Civilian Executive Branch (FCEB) agencies treat KEV catalog items as top‑priority. Agencies must:

  • Patch publicly exposed assets that could grant full control after exploitation.
  • Verify whether a system has already been compromised before applying a fix.
  • Defer action on lower‑risk CVEs that are not in the KEV catalog.
"The KEV Catalog is a critical tool for prioritizing vulnerability remediation and protecting federal assets," says CISA.

What You Should Do

Organizations outside the federal sphere are also encouraged to follow a risk‑based approach:

  • Check if your systems run Oracle HTTP Server or WebLogic Server.
  • Apply the latest patch or configuration change that mitigates CVE‑2026‑21962.
  • Monitor for any signs of exploitation, especially on publicly reachable services.
  • If you discover a new exploited CVE, submit it via CISA’s KEV Nomination Form.

How to Report a New Exploit

To add a vulnerability to the KEV catalog, submit a nomination that includes:

  • A valid CVE identifier.
  • Clear evidence of active exploitation.
  • Mitigation guidance that can be applied by organizations.

By staying on top of the KEV list and acting swiftly, you can reduce the attack surface and safeguard your critical assets.

CISA Oracle WebLogic CVE-2026-21962 KEV Vulnerability Management Federal Agencies

← All news