started · updated
Oracle HTTP Server vulnerability added to CISA's KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw, identified as CVE-2026-21962, carries a maximum CVSS score of 10.0.
The vulnerability involves improper access control, which allows unauthenticated attackers with network access via HTTP to bypass authorization. Successful exploitation can lead to unauthorized access to critical data, the ability to create, delete, or modify sensitive information, or complete access to all data accessible through the affected components.
While Oracle released patches for this flaw in January 2026, reports from GreyNoise and CloudSEK indicate that the vulnerability is being actively exploited in the wild. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are mandated to address this flaw.