CVE Tools
Back to feed
Exploited in the wild Oracle HTTP Server SnowLight rce WebLogic Server Proxy plugin Oracle

CISA Warns of Exploited Oracle WebLogic Vulnerability

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, warning that this critical remote code execution flaw is being actively used against Oracle WebLogic environments. The vulnerability, rated with a perfect CVSS score of 10, affects both the Oracle HTTP Server and the WebLogic Server Proxy plugin, allowing attackers to compromise systems without authentication. Federal agencies were directed to apply the fix from Oracle's January 2026 security update by August 27, following reports that the bug has been targeted by China-linked threat actors since early in the year.