CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after confirming active attacks against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. The maximum-severity flaw, rated CVSS 10.0, affects versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and can be exploited by unauthenticated attackers over HTTP to compromise exposed systems, including unauthorized access to and modification of critical data. Public reporting describes the issue as a URI normalization path traversal bug that may also enable privilege escalation and execution of injected code through crafted requests.
Oracle issued patches in its January 2026 Critical Patch Update, but reporting from GreyNoise and CloudSEK indicated exploitation in the wild, prompting CISA to order Federal Civilian Executive Branch agencies to remediate by August 27, 2026 under Binding Operational Directive 26-04. Because CISA did not publish indicators of compromise, defenders are being urged to patch immediately and to treat internet-facing Oracle WebLogic and HTTP Server deployments as potentially compromised until proven otherwise.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
On Monday, CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog after confirming active exploitation. CISA described the issue as an improper access control flaw that can enable unauthorized access to or modification of critical data in affected Oracle products.
In July 2026, SOCRadar reported that a China-linked threat actor used CVE-2026-21962 alongside other vulnerabilities in attacks targeting government organizations.
In March 2026, CloudSEK reported exploitation attempts against its honeypot network targeting CVE-2026-21962. It also saw attackers probe older Oracle WebLogic vulnerabilities including CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271.
In February 2026, GreyNoise observed the IP address 193.24.123[.]42 attempting to exploit multiple vulnerabilities, including CVE-2026-21962 affecting Oracle WebLogic. The activity also targeted Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI flaws.
CloudSEK said its honeypots observed exploitation attempts against Oracle WebLogic servers starting on January 22, 2026. According to the report, the activity began immediately after a proof-of-concept exploit for CVE-2026-21962 was made public.
A proof-of-concept exploit for CVE-2026-21962 became publicly available on January 21, 2026. Subsequent reporting tied exploitation activity against Oracle WebLogic servers to the PoC's release.
Oracle made fixes for CVE-2026-21962 available in its January 2026 Critical Patch Update. The flaw affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcescworld.com
Open sourcetheregister.com
Open sourcecybersecuritynews.com
Open sourcecirt.gy
Open sourcecyberveille.ch
Open sourcecve.org
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.