CVE-2026-21962 (CVSS score: 10.0) allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CVE-2026-21962: an improper access control vulnerability
CISA said the flaw is an "improper access control vulnerability" in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in that can produce broad, high-impact outcomes. In CISA’s wording, successful exploitation "can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data." The agency assigned the issue a maximum severity and placed it in its Known Exploited Vulnerabilities (KEV) catalog after finding evidence of active exploitation.
CISA’s KEV listing and the timing of fixes
CISA added the vulnerability to the KEV catalog on Monday, citing evidence of active exploitation. The advisory notes that patches for the flaw were released by Oracle "earlier this January," but despite those patches multiple reports show attackers continued to target WebLogic environments.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadObserved threat activity: 193.24.123[.]42 and CloudSEK honeypots
Multiple outside monitors observed exploitation activity. GreyNoise and CloudSEK reported active efforts to exploit the vulnerability after patches were available. In February 2026 a single IP address — "193.24.123[.]42" — was observed attempting to exploit multiple known vulnerabilities, including those affecting Oracle WebLogic as well as other products.
CloudSEK later reported that its honeypot network captured attempts that included CVE-2026-21962 alongside other persistent WebLogic remote-code-execution flaws. "In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE)," CloudSEK noted. That pattern led CloudSEK to conclude that "threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments."
Binding Operational Directive 26-04: an August 27, 2026 implementation date for FCEB agencies
Pursuant to Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies were recommended to apply necessary fixes by August 27, 2026, to protect their networks. The BOD deadline is the operational lever cited in the advisory to accelerate remediation across federal agencies that rely on Oracle HTTP Server and WebLogic components.
What this means for security teams, FCEB agencies, and threat actors
- Security teams and technologists: The immediate technical task is clear in the record — apply the Oracle patches that were released earlier this January and confirm mitigations on instances that expose Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in over HTTP. CloudSEK’s honeypot capture underscores that attackers are chaining known, simple-to-exploit WebLogic flaws together.
- Federal Civilian Executive Branch agencies: The advisory ties remediation to BOD 26-04’s August 27, 2026 timeline. Agencies named by that directive are on a prescribed schedule to implement fixes; the KEV listing formalizes urgency and provides a common reference for compliance checks.
- Threat actors: The telemetry cited — including the single IP observed in February and the honeypot captures — indicates threat actors continue to favor a compact set of effective WebLogic RCE vulnerabilities. That pattern suggests attack campaigns will likely keep probing exposed HTTP interfaces until patches and compensating controls are widely deployed.
The facts are stark and contained: a maximum-severity, unauthenticated HTTP-accessible flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in has been actively exploited despite patches being available earlier this January. CISA’s KEV designation and the BOD 26-04 timeline compress the window for attention and action, while telemetry from GreyNoise and CloudSEK shows attackers continuing to exploit easy-to-find, well-documented WebLogic weaknesses. Whether the August 27 remediation deadline closes the gap between exposure and exploitation will be the immediate operational test.




