Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [cve, oracle, weblogic, http-server, access-control, actively-exploited, kev] ยท confidence: high ยท severity: high ยท affected_sectors: [government, technology] ยท au_impact: false

CVE-2026-21962

CVE-2026-21962 is an improper access-control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA added it to the Known Exploited Vulnerabilities (KEV) Catalog on 24 August 2026 โ€” the sole addition that day โ€” confirming the flaw is being exploited in practice rather than remaining theoretical.

Vulnerability Details

Attribute Detail
CVE CVE-2026-21962
Products Oracle HTTP Server; Oracle WebLogic Server Proxy Plug-in
Type Improper access control
Exploitation Actively exploited (CISA KEV listing)
KEV added 2026-08-24

Impact

The KEV listing makes CVE-2026-21962 priority patching for any organisation fronting WebLogic with Oracle HTTP Server. US Federal Civilian Executive Branch agencies must patch on the standard two-week deadline from the KEV due date.

Mitigation

  1. Apply Oracle's patch for CVE-2026-21962 immediately, prioritising internet-facing OHS instances
  2. Review the KEV entry for the required due date and any vendor guidance
  3. Zimbra (CVE-2026-73570, added 21 August 2026) remains the other recent KEV entry under active remediation โ€” confirm both remediation tracks are progressing

Source

Related