By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Actively Exploited Oracle WebLogic Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog. This designation signifies that the flaw is actively being exploited by malicious actors in the wild. The vulnerability, identified as CVE-2026-21962, carries a maximum severity score of 10.0 on the Common Vulnerability Scoring System (CVSS), indicating a critical risk to affected systems. According to CISA's advisory, an unauthenticated attacker who possesses network access via the HTTP protocol can exploit this vulnerability. The primary impact of a successful exploitation is the ability for attackers to access critical data housed within the compromised Oracle environments. This means sensitive information, potentially including customer details, financial records, or proprietary business data, could be exfiltrated by threat actors without requiring any prior authentication or credentials. The inclusion of CVE-2026-21962 in the KEV catalog mandates that federal agencies patch this vulnerability on their systems by a specified deadline, which is typically 14 days from the date of inclusion. While this mandate applies to federal agencies, it serves as a strong warning to all organizations utilizing Oracle WebLogic Server and Oracle HTTP Server to prioritize remediation efforts. The KEV catalog is a crucial resource maintained by CISA to inform the cybersecurity community about vulnerabilities that pose an immediate and significant threat. By tracking actively exploited vulnerabilities, CISA aims to help organizations allocate their security resources effectively and mitigate risks proactively. The presence of CVE-2026-21962 on this list underscores the urgency for organizations to implement security patches and updates provided by Oracle to protect their infrastructure and sensitive data from unauthorized access and potential breaches. Oracle WebLogic Server is a Java EE application server that provides a robust platform for developing and deploying enterprise applications. Oracle HTTP Server, often used in conjunction with WebLogic, serves as a web server component. The widespread use of these Oracle products across various industries means that a vulnerability like CVE-2026-21962 could have a broad impact, affecting numerous organizations and potentially leading to significant data breaches if left unaddressed. The CVSS score of 10.0 indicates that the vulnerability is not only easy to exploit but also has severe consequences, making it a top priority for cybersecurity professionals.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.