Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds Maximum-Severity Oracle Flaw to its Known Exploited Vulnerabilities Catalog: A Critical Alert for Organizations




U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog, alerting organizations to the critical nature of this vulnerability. This critical flaw could allow attackers to access, modify, or delete critical data, potentially gaining broad access to information available through the affected components. Organizations must take immediate action to protect themselves against this vulnerability, which has a CVSS score of 10.0 and affects versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

  • Oracle has added a critical, unauthenticated vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities (KEV) catalog.
  • The vulnerability affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS with a CVSS score of 10.0.
  • Exploiting the flaw allows an attacker to access, modify, or delete critical data without authentication.
  • The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
  • CISA has issued a warning to federal agencies to fix the flaw by August 27, 2026, and experts recommend private organizations review and address the vulnerabilities.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a maximum-severity Oracle flaw to its Known Exploited Vulnerabilities (KEV) catalog, alerting organizations to the critical nature of this vulnerability. The added flaw, CVE-2026-21962, is a critical, unauthenticated vulnerability affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. This vulnerability has a CVSS score of 10.0, indicating a high level of severity.

    According to CISA, an attacker does not need an account or valid credentials to exploit this flaw remotely through HTTP, potentially compromising the affected server. Successful exploitation could allow the attacker to access, modify, or delete critical data, potentially gaining broad access to information available through the affected components. Furthermore, the vulnerability has a scope-change impact, meaning an attacker who exploits it could potentially affect other systems or applications connected to the vulnerable Oracle components.

    The flaw affects versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. In practical terms, this is dangerous because an internet-accessible Oracle WebLogic proxy component could provide an attacker with a path into critical backend systems without requiring authentication.

    The discovery of this vulnerability is not an isolated incident. In March 2026, CloudSEK researchers detected attacks targeting several known flaws in Oracle WebLogic against its honeypot network. Attackers also targeted CVE-2026-21962 along with older WebLogic RCE vulnerabilities, including CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271.

    CISA has issued a warning to federal agencies to fix the flaw by August 27, 2026, and experts recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. This alert serves as a reminder to organizations to prioritize security and take immediate action to protect themselves against this critical vulnerability.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Maximum-Severity-Oracle-Flaw-to-its-Known-Exploited-Vulnerabilities-Catalog-A-Critical-Alert-for-Organizations-ehn.shtml

  • https://securityaffairs.com/197801/security/u-s-cisa-adds-maximum-severity-oracle-flaw-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2020-14882

  • https://www.cvedetails.com/cve/CVE-2020-14882/

  • https://nvd.nist.gov/vuln/detail/CVE-2020-14883

  • https://www.cvedetails.com/cve/CVE-2020-14883/

  • https://nvd.nist.gov/vuln/detail/CVE-2020-2551

  • https://www.cvedetails.com/cve/CVE-2020-2551/

  • https://nvd.nist.gov/vuln/detail/CVE-2017-10271

  • https://www.cvedetails.com/cve/CVE-2017-10271/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-21962

  • https://www.cvedetails.com/cve/CVE-2026-21962/


  • Published: Tue Aug 25 05:09:53 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us