CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers

The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A corporate server room with Oracle WebLogic servers and associated hardware, with critical alert notifications flashing on monitoring dashboards, showing activ
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • CISA added CVE-2026-21962, a flaw in Oracle HTTP Server and Oracle WebLogic Server, to its Known Exploited Vulnerabilities catalog on Monday.
  • The bug carries a CVSS score of 10.0, the highest possible rating, and can be triggered over the internet with no login required.
  • CISA says it has evidence the flaw is already being exploited in real attacks.
  • Federal civilian agencies must patch affected Oracle systems by CISA's set deadline, and private organisations are strongly urged to do the same.

A critical flaw in widely used Oracle server software is being exploited in the wild, and the U.S. Government wants it fixed fast.

The U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog on Monday. That catalog is a public list of security holes attackers are actively abusing; federal agencies must patch anything on it within a set window.

The flaw is tracked as CVE-2026-21962. It scores a perfect 10.0 on the CVSS severity scale, which runs from 0 to 10 and rates how dangerous a bug is. We first covered this CVE on 25 August 2026.

What does the flaw actually let attackers do?

It lets a stranger on the internet break into vulnerable Oracle servers without needing credentials. From there, they can reach data the server is supposed to protect.

The bug sits in two Oracle products: Oracle HTTP Server and Oracle WebLogic Server, both pieces of back-office software that large organisations use to run business applications and internal systems. Because the attack works over normal web traffic (HTTP), any vulnerable server exposed to the internet is reachable. No phishing, where criminals send fake emails to trick staff into handing over passwords, is required. The attacker just sends the right request.

Who is being targeted?

CISA hasn't named specific victims or the group behind the attacks. Its listing only confirms exploitation is happening. The Hacker News first flagged the KEV addition on Monday.

Oracle WebLogic bugs have a long history of drawing in a wide mix of attackers. Financially motivated crews tend to jump on them within days, as do state-linked operators. It's too early to attribute this specific campaign, and single-source attribution should be treated with caution.

Capability and intent are separate questions here. The capability, remote unauthenticated access to sensitive data, is available to anyone who can write or buy a working exploit. Intent will vary by group. That's what makes a CVSS 10.0 with no authentication barrier genuinely dangerous: it doesn't require a sophisticated actor.

What should organisations do now?

Patch, and check whether anyone got in already.

Item Detail
CVE ID CVE-2026-21962
CVSS score 10.0 (critical)
Affected products Oracle HTTP Server, Oracle WebLogic Server
Access needed None (unauthenticated, over HTTP)
Added to CISA KEV Monday

Admins should apply Oracle's fix from the latest Critical Patch Update. WebLogic servers shouldn't be exposed directly to the public internet where it can be avoided; putting them behind a VPN or web application firewall cuts the attack surface. Log reviews going back several weeks are sensible, because attackers who broke in before the patch may have left backdoors.

Should ordinary customers worry?

Not directly, but watch for notices from organisations you deal with over the coming weeks. If a company was breached through this flaw, they may write to you about it. Treat any unexpected email asking you to verify an account with suspicion, and go to the company's website directly rather than clicking links.

© 2026 Threat Vectr