CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

CISA has given federal civilian agencies until August 27 to patch the exploited Oracle flaw that can expose or alter critical data without prior authentication.

Listen to this article

0:00

Press play to start listening

CISA has ordered US federal civilian agencies to address a maximum-severity Oracle vulnerability by August 27 after confirming that attackers are exploiting it in real-world incidents.

Tracked as CVE-2026-21962, the flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. These components receive web traffic through Apache HTTP Server or Microsoft IIS and pass requests to applications running on WebLogic.

It is worth noting that the vulnerability does not impact every WebLogic installation, and exposure depends on whether an affected version of Oracle HTTP Server or the proxy plug-in is installed and reachable over HTTP.

Attackers Do Not Need Login Credentials

Many attacks, as we know them, begin by stealing or bypassing login credentials. This flaw skips that stage entirely. An attacker only needs network access to send malicious HTTP requests to a vulnerable component, with no username, password, or employee action required.

Oracle classifies the issue as an improper access-control vulnerability with low attack complexity. Successful exploitation can allow unauthorized access to critical information, including the ability to create, delete, or modify data available through the affected component.

Some researchers have described the flaw as a remote code execution vulnerability. CloudSEK used that description after recording exploit attempts against its honeypot, while SOCRadar reported evidence of blind remote code execution during a separate campaign. Oracle and CISA publicly classify the vulnerability as improper access control and do not label it remote code execution.

Shane Barney, chief information security officer at Keeper Security, told Hackread.com that the absence of authentication removes a control that many organizations expect attackers to overcome.

“There’s nothing to phish, steal or brute force,” Barney said. He warned that a compromised server may provide access to service accounts, database credentials, API secrets and connected systems. Limiting standing permissions and granting elevated access only when required can help contain the damage.

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Exploit Attempts Began After Public Code Appeared

Oracle released fixes through its January 2026 Critical Patch Update. Affected versions include 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, although Oracle says the WebLogic proxy plug-in for IIS is affected only in version 12.2.1.4.0.

CloudSEK recorded automated exploitation attempts from January 22 to February 3, beginning soon after public exploit code appeared. Its honeypot also received attacks targeting older WebLogic vulnerabilities, indicating that attackers were scanning exposed servers for available routes.

FalconFeeds later included CVE-2026-21962 in a June analysis of the cybercrime supply chain. In July, SOCRadar reported that the China-nexus SNOWLIGHT operation, connected by researchers with access brokers including UNC5174, included an exploit for the vulnerability among tools used against government infrastructure.

CISA has not named an attacker, disclosed affected organizations, or stated whether ransomware has been used with the flaw. Its KEV listing confirms active exploitation but does not establish how many systems have been compromised.

Federal Agencies Face August 27 Deadline

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24 and gave federal civilian agencies until August 27 to complete remediation.

Administrators should check Oracle HTTP Server installations and Apache or IIS servers using the WebLogic proxy plug-in, not only systems inventoried as WebLogic servers. Affected components should receive Oracle’s January updates, while unnecessary external HTTP access should be restricted.

Agencies running the affected products should also check their web server, proxy, and WebLogic logs for requests that bypassed authentication, access to protected data, or unusual outbound connections. If a server may have been compromised, any credentials stored on it or available through it should be changed.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts