On August 24, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency cited evidence of active exploitation.

The vulnerability affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. It is an improper access control flaw. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data. It also allows unauthorized access to critical data or complete access to all accessible data.

What's New

  • CVE ID: CVE-2026-21962
  • Product: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in
  • Vulnerability Type: Improper Access Control
  • Impact: Unauthorized creation, deletion, or modification access to critical data; unauthorized access to critical data or complete access to all accessible data
  • Known Ransomware Use: Unknown
  • Date Added to KEV: August 24, 2026
  • Due Date for FCEB Agencies: August 27, 2026
  • Action Required: Apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance for cloud services, or discontinue use if mitigations are unavailable

Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch (FCEB) agencies to prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets. The directive applies to assets that grant total control of the asset post-exploitation. BOD 26-04 also establishes expectations for when agencies must check whether threat actors compromised the system before the patch was applied.

CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. The agency notes this vulnerability type is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

Why It Matters

Oracle WebLogic and HTTP Server deployments are widespread across enterprise and government environments, often exposed to the internet for application delivery. The three-day remediation window under BOD 26-04 reflects the severity of active exploitation and the risk of total asset compromise post-exploitation. Organizations outside the federal enterprise should treat this timeline as a benchmark for risk-based prioritization. The flaw's ability to grant complete data access without authentication elevates the risk of silent, persistent compromise in internet-facing middleware layers.

Our Take

The short due date signals CISA's assessment that exploitation is both active and consequential. While the KEV entry notes ransomware use as unknown, the improper access control flaw directly enables data manipulation and exfiltration — precursors to ransomware and espionage. Defenders should verify whether Oracle's July 2026 Critical Patch Update addresses this CVE and prioritize internet-facing instances immediately.

Sources