CVE -2026-21962 is one of the most dangerous vulnerabilities identified this year in corporate environments: CISA (US Cybersecurity and Infrastructure Security Agency) added it to the Known Exploited Vulnerabilities (KEV) list on August 24, 2026, confirming its active exploitation on the Internet. The vulnerability affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in , has received the maximum CVSS score of 10.0 and allows unauthorized attackers to gain full access to critical data without requiring credentials.

According to CISA, the vulnerability is classified as improper access control (CWE-284) and could allow a remote, unauthenticated attacker with network access over HTTPto compromise Oracle HTTP Server and WebLogic Server Proxy Plug-in. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as full access to all data accessible by these services. This is a nightmare scenario for any organization that exposes these services to the internet.
See also: CVE-2026-60236: Critical RCE in Oracle Coherence (CVSS 9.8) – what to do now
It is worth noting that Oracle had already released a patch for CVE-2026-21962 as part of its regular Critical Patch Update (CPU)This means that systems that have not been updated have remained exposed for more than seven months — enough time for attackers to identify and exploit vulnerable installations. Delayed patching in corporate environments is a chronic problem, and this case once again highlights its consequences.
According to reports from GreyNoise and CloudSEK, active exploitation of CVE-2026-21962 began early. In February 2026, a single IP address (193.24.123[.]42) was detected attempting to exploit multiple known vulnerabilities in Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils , and GLPI. A month later, CloudSEK reported attacks targeting the company's honeypot network.

CVE-2026-21962 and the broader threat landscape for Oracle WebLogic
CloudSEK noted that in addition to CVE-2026-21962 , its honeypot recorded attacks targeting other critical WebLogic Remote Code Execution (RCE) vulnerabilities : CVE-2020-14882 and CVE-2020-14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE). This demonstrates that attackers continue to rely on a small set of highly effective and easily exploitable vulnerabilities to compromise WebLogic environments .
See also: Oracle WebLogic CPU July 2026: 5 critical RCEs — deserialization in T3/IIOP/HTTP/SOAP
During the same period (July–August 2026), other serious vulnerabilities in the Oracle ecosystem emerged, such as CVE-2026-60365 and CVE-2026-60206, which are described as serious attack paths in similar components. Oracle's August 2026 patch cycle was characterized as unusually large, which highlights the broader security pressure on the platform and its middleware ecosystem. Oracle WebLogic remains one of the most popular targets for cyberattacks, as it is widely deployed in corporate environments exposed to the Internet.
CISA , citing Binding Operational Directive (BOD) 26-04 , recommended that federal agencies ( Federal Civilian Executive Branch — FCEB ) implement the necessary fixes by August 27, 2026. Although the directive officially concerns US government agencies, experts recommend that every organization address the vulnerability immediately, according to The Hacker News.

How to protect yourself from CVE-2026-21962: Immediate action steps
Organizations using Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in should take immediate action. The first step is to inventory all installations exposed to the internet, including bundled proxy components in middleware stacks. Next, verify that the January 2026 patch ( CPU January 2026 ) has actually been applied — the mere existence of the announcement does not mean that the fix has been completed.
Because active exploitation has been confirmed, security teams should maintain and analyze web server, reverse proxy, and application logs for evidence of abuse. If suspicious activity is detected, it is recommended to immediately rotate credentials and review access rights to sensitive data. Systems exposed to the internet that handle authentication, application routing, or backend data access should be prioritized.
See also: CISA warns of Oracle WebLogic vulnerability exploitation
For Greek businesses and organizations using Oracle middleware — particularly in the banking, telecommunications and public administration sectors — the threat is immediate and real. Oracle WebLogic is a core component of many enterprise applications in Europe, and the exploitation of CVE-2026-21962 could lead to a data breach with serious consequences for both operations and GDPR compliance . Immediate patching and enhanced monitoring are the most effective defenses against this critical threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
