Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Hacked: US cyber agency warns of active exploitation of Perfect 10 Oracle WebLogic bug

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities Catalog more than six months after its initial disclosure.

Wed, 26 Aug 2026
Hacked: US cyber agency warns of active exploitation of Perfect 10 Oracle WebLogic bug

The United States Cybersecurity & Infrastructure Security Agency has added a Critical Oracle WebLogic flaw to its list of known exploited vulnerabilities.

First disclosed – and patched – by Oracle back in January 2026, CVE-2026-21962 is an unauthenticated Remote Code Execution vulnerability in Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in product of Oracle Fusion Middleware.

The bug has a perfect CVSS score of 10, making it a Critical severity vulnerability, and CISA is urging US government entities to remediate the issue rapidly, saying “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise”.

 
 

Described in its CVE record as “easily exploitable”, CVE-2026-21962 could lead to the compromise of the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

“While the vulnerability is in Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change),” the CVE record says.

“Successful attacks of this vulnerability can result in unauthorised creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in accessible data, as well as unauthorised access to critical data or complete access to all Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in accessible data.”

The vulnerability was disclosed on January 20, 2026 and impacts the following versions: 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.

Cyber security firm CloudSEK investigated the vulnerability for several months following its initial disclosure, standing up a vulnerable honeypot system before sharing its findings in a March 25 blog post. At the time, hackers were observed rapidly setting up rented Virtual Private Servers as part of their malicious infrastructure.

“This swift adoption by attackers highlights its attractiveness and the immediate need for patching,” CloudSEK said.

“Organisations running unpatched Oracle WebLogic Server versions are critically exposed to this zero-day-like threat, which enables everything from data theft to the deployment of persistent backdoors and malware, all executed through a simple, unauthenticated web request.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: