CISA has ordered government organizations to urgently patch CVE-2026-21962, a critical unauthenticated remote code execution flaw affecting Oracle HTTP Server and the WebLogic Server Proxy plugin. The vulnerability has been actively exploited since January in attacks against Oracle WebLogic servers, with reporting tied to CloudSEK, FalconFeeds, SOCRadar, and a China-linked threat actor. #CVE-2026-21962 #OracleWebLogic #OracleHTTPServer #CloudSEK #FalconFeeds #SOCRadar
Keypoints
- CISA urged immediate patching of CVE-2026-21962.
- The flaw allows unauthenticated remote code execution.
- It affects Oracle HTTP Server and the WebLogic Server Proxy plugin.
- Oracle fixed the issue in its January 2026 updates.
- Exploitation has been observed since January, including activity linked to a China-linked threat actor.
Read More: https://www.securityweek.com/cisa-warns-of-exploited-oracle-weblogic-vulnerability/