StratosAlly – Cybersecurity for digital safety

Oracle WebLogic Flaw Is Being Exploited, And CISA Wants It Patched Now

Picture of StratosAlly

StratosAlly

Oracle WebLogic Flaw Is Being Exploited, And CISA Wants It Patched Now

A vulnerability that organizations were supposed to have patched months ago has suddenly become an urgent cybersecurity problem.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962, a maximum-severity flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability carries a CVSS score of 10.0, the highest possible rating.

What makes this flaw particularly dangerous is how little an attacker needs to get started. The vulnerability is an improper access-control issue that can be exploited remotely through HTTP without authentication. A successful attack could allow unauthorized access to critical data or give attackers the ability to create, delete, or modify data accessible through the affected Oracle components.

And this isn’t just a theoretical risk. Oracle released a fix for the vulnerability in January 2026, but attackers have continued looking for systems that never received the update. Security researchers reported exploitation attempts againsthoneypots shortly after public exploit code appeared. Imperva also observed more than 140,000 attack attempts across 21 countries within six days of the flaw’s disclosure, with IT and financial services among the most targeted sectors.

The situation becomes even more concerning because the flaw has reportedly been incorporated into attack activity linked to the SNOWLIGHT campaign. According to researchers, the campaign targeted government and commercial infrastructure across more than 100 countries, with significant activity observed against Taiwan.

CISA has now put a hard deadline on federal agencies: August 27, 2026. Agencies are required to apply Oracle’s January Critical Patch Update under Binding Operational Directive 26-04.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles