Particle.news
Download on the App Store

CISA Lists CVE-2026-21962 in KEV and Orders Rapid Federal Patching

The move signals active exploitation of an unauthenticated Oracle HTTP Server/WebLogic proxy flaw that can give attackers a path from internet-facing proxies into backend systems.

Overview

  • CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24 and set a remediation deadline for Federal Civilian Executive Branch agencies of August 27 under BOD 26-04.
  • The flaw is a maximum-severity (CVSS 10.0) improper access control bug in Oracle HTTP Server and the WebLogic Server Proxy Plug-in that allows an unauthenticated HTTP requester to read, create, modify, or delete data accessible through the proxy.
  • Oracle published fixes in its January 2026 Critical Patch Update, but multiple telemetry sources report ongoing attacks against unpatched, internet-exposed proxy instances since February.
  • Researchers observed scanning from a recurring IP (193.24.123[.]42) and CloudSEK captured exploitation attempts in honeypots, though public reporting does not include a proof-of-concept, named threat actor, or confirmed victim counts.
  • Security teams are urged to inventory all Oracle HTTP Server and WebLogic proxy deployments, apply the January patch or later, hunt logs for signs of compromise going back to February, and restrict internet exposure where immediate patching is not possible.