type: cve ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [cve, oracle, weblogic, http-server, access-control, actively-exploited, kev] ยท confidence: high ยท severity: high ยท affected_sectors: [government, technology] ยท au_impact: false
CVE-2026-21962
CVE-2026-21962 is an improper access-control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA added it to the Known Exploited Vulnerabilities (KEV) Catalog on 24 August 2026 โ the sole addition that day โ confirming the flaw is being exploited in practice rather than remaining theoretical.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-21962 |
| Products | Oracle HTTP Server; Oracle WebLogic Server Proxy Plug-in |
| Type | Improper access control |
| Exploitation | Actively exploited (CISA KEV listing) |
| KEV added | 2026-08-24 |
Impact
The KEV listing makes CVE-2026-21962 priority patching for any organisation fronting WebLogic with Oracle HTTP Server. US Federal Civilian Executive Branch agencies must patch on the standard two-week deadline from the KEV due date.
Mitigation
- Apply Oracle's patch for CVE-2026-21962 immediately, prioritising internet-facing OHS instances
- Review the KEV entry for the required due date and any vendor guidance
- Zimbra (CVE-2026-73570, added 21 August 2026) remains the other recent KEV entry under active remediation โ confirm both remediation tracks are progressing
Source
Related
- Cisa Kev Addition Oracle Http Server Cve 2026 21962 2026 08 24 โ KEV addition incident note