Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Maximum Severity: Oracle Flaw (CVSS 10) Under Active Attack – CISA Warns

A maximum-severity vulnerability (CVSS 10.0) in the Oracle HTTP Server and the WebLogic Server Proxy Plug-in is under active attack. The US agency CISA has added CVE-2026-21962 to its catalog of actively exploited flaws.

Unauthenticated takeover

The flaw lets an unauthenticated attacker with network access over HTTP compromise affected servers – up to unauthorized access to or modification of critical data. It affects the Oracle HTTP Server and the WebLogic Server Proxy Plug-in that bridges the HTTP Server to WebLogic.

Exploited since January

Oracle had already patched the flaw with its January 2026 updates. According to security researchers – first reported by CloudSEK – attacks have been running since January. The mix of maximum severity and active exploitation makes it especially dangerous.

The clock is ticking

CISA added the vulnerability to its KEV catalog on 24 August and gave US federal agencies until 27 August. Anyone running Oracle HTTP Server or WebLogic should apply the patches immediately.


Sources: SecurityWeek, The Hacker News.

Mastodon
Scroll to Top