type: incident ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [incident, cisa, kev, oracle, weblogic, http-server, actively-exploited] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false
CISA KEV Addition โ Oracle HTTP Server CVE-2026-21962 (2026-08-24)
CISA added CVE-2026-21962, an improper access-control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities (KEV) Catalog on 24 August 2026 โ the sole addition that day.
Overview
| Attribute | Detail |
|---|---|
| Agency | CISA |
| Date | 2026-08-24 |
| CVE added | CVE-2026-21962 (Oracle HTTP Server / WebLogic Server Proxy Plug-in) |
| Catalogue | Known Exploited Vulnerabilities (KEV) |
| Additions that day | One (this CVE only) |
Impact
The KEV listing confirms the flaw is being exploited in practice, making it priority patching for any organisation fronting WebLogic with Oracle HTTP Server. US Federal Civilian Executive Branch agencies must patch on the standard two-week deadline from the KEV due date.
Context
Zimbra (CVE-2026-73570, added 21 August 2026) remains the other recent KEV entry under active remediation.
Source
Related
- Cve 2026 21962 โ the underlying vulnerability