{
  "id": 3275830,
  "title": "Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February",
  "url": "https://urgent.news/2026/08/25/oracle-weblogic-proxy-plug-in-flaw-hits-cisa-kev-cvss-10-0",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T14:06:05.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/etairos/oracle-weblogic-proxy-plug-in-flaw-hits-cisa-kev-cvss-100-unauthenticated-exploited-since-4ii8"
  },
  "original_language": "en",
  "account": "On August 24, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962, a critical security flaw, to its Known Exploited Vulnerabilities catalog. The vulnerability affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, both of which are components that sit in front of the application tier. The flaw allows an unauthenticated attacker with network access over HTTP to gain unauthorized access to critical data and create, delete, or modify it across everything the proxy tier can reach. This includes both confidentiality and integrity, with the blast radius defined by what the proxy tier can reach, not by what it stores.\n\nThe severity of the flaw is highlighted by its CVSS score of 10.0, making it a high-risk vulnerability. Any organization running internet-reachable Oracle HTTP Server or WebLogic Proxy Plug-in instances is at risk, including federal civilian agencies which have until August 27, 2026 to remediate the issue under Binding Operational Directive 26-04. Despite being available for seven months, many organizations have yet to apply the necessary patches. The flaw was first reported in February 2026, and CISA has cited evidence of active exploitation since that time.\n\nOracle released the fix in its January 2026 Critical Patch Update, but the delay in remediation highlights a broader issue with patch deployment. The flaw was exploited alongside other known vulnerabilities such as CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271, all of which were previously disclosed and had patches available. The exploitation attempts were captured by honeypot networks, indicating that the threat actors are relying on a small set of highly effective, simple to exploit vulnerabilities to compromise WebLogic environments.\n\nTo mitigate the risk, organizations are advised to inventory all instances of Oracle HTTP Server and WebLogic Proxy Plug-in, apply the January 2026 Critical Patch Update or later, and close the legacy WebLogic Remote Code Execution (RCE) bugs. It is also recommended to remove the WebLogic admin console and the WLS-WSAT endpoint from internet reachability. If a change window is not immediately available, restricting affected virtual hosts at the load balancer or Web Application Firewall (WAF) to known consumer source ranges is suggested. Detection and hunting for the vulnerability involve reviewing access logs for anomalous paths, looking for new or modified files, and checking WebLogic managed server logs for requests that do not correlate to legitimate front-end sessions. The window of opportunity for exploitation is assumed to have been open for months, indicating that the patch deployment gap is a significant concern.",
  "summary": "TL;DR what: CISA added CVE-2026-21962, a CVSS 10.0 improper access control flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24, 2026. impact: An unauthenticated attacker with network access over HTTP can gain unauthorized access to critical data and create, delete, or modify it across everything the proxy tier can…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "SecurityWeek",
        "title": "CISA Warns of Exploited Oracle WebLogic Vulnerability",
        "url": "https://urgent.news/2026/08/25/cisa-warns-of-exploited-oracle-weblogic-vulnerability",
        "published": "2026-08-25T07:46:34.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}