Oracle’s top-severity WebLogic flaw hits CISA urgent patch list

CISA adds a CVSS 10.0 Oracle WebLogic flaw to its exploited list and gives federal agencies a three-day patch window.

CSBadmin
1 Min Read

Federal agencies have three days to patch a maximum-severity Oracle flaw that the US cybersecurity watchdog added to its exploited-vulnerability catalog on Monday.

The bug, tracked as CVE-2026-21962 with a perfect CVSS score of 10.0, is an improper access control issue in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache and IIS. No authentication is needed. An attacker with network access over HTTP can create, delete, or modify critical data, and CISA warns the flaw can yield complete access to everything the affected components can reach.

Exploitation surfaced quickly after Oracle shipped fixes on January 20. GreyNoise and CloudSEK logged attack attempts, and a CloudSEK honeypot observed the bug probed alongside older WebLogic remote code execution flaws, including CVE-2020-14882, CVE-2020-2551, and CVE-2017-10271. The mix suggests attackers keep recycling a short list of proven WebLogic holes.

Affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Under Binding Operational Directive 26-04, civilian federal agencies must remediate by August 27, a three-day window that is the tightest CISA is authorized to set.

Private organizations should treat the catalog entry as a signal to patch immediately, since internet-facing WebLogic proxies offer a direct path into backend systems.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.