The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as an improper access control vulnerability, meaning it could allow threat actors to bypass authorization controls and access sensitive resources that should remain protected.
Critical Oracle HTTP Server Flaw
Being included in CISA’s KEV Catalog indicates that this vulnerability poses an immediate operational risk, particularly for organizations that expose Oracle web infrastructure to the internet.
If successfully exploited, attackers could gain access to, alter, or manipulate sensitive data handled by affected web services. This could result in application compromises, data theft, unauthorized configuration changes, or a foothold for further intrusion.
Oracle HTTP Server is often used as a web tier component in enterprise environments, while the WebLogic Server Proxy Plug-in routes web requests to backend Oracle WebLogic Server instances.
Weaknesses in access control at this layer are particularly dangerous because proxy and web server components frequently sit at the boundary between external users and internal applications.
CISA has noted that vulnerabilities of this type are a common attack vector for malicious cyber actors and pose significant risks to federal environments.
However, the agency has not publicly disclosed technical details on exploitation, attacker attribution, or indicators of compromise for CVE-2026-21962. The confirmed exploitation status means that security teams should assume that scanning and opportunistic targeting may already be in progress.
Federal Civilian Executive Branch agencies are mandated to address this flaw under Binding Operational Directive 26-04, which outlines risk-based vulnerability management requirements.
This directive emphasizes the need for accelerated remediation of KEV-listed vulnerabilities affecting publicly exposed systems, especially when potential post-exploitation impacts could result in the loss of total asset control.
For private-sector organizations, CISA recommends employing the same risk-based approach. Security teams should first identify all deployments of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, including those that are internet-facing, part of disaster-recovery environments, or externally managed. Administrators should apply Oracle-provided security updates or mitigations as quickly as possible.
Organizations should also investigate whether any affected systems were compromised before implementing remediation.
Relevant indicators may include unusual HTTP requests, unexpected access to restricted application paths, unexplained configuration changes, anomalous administrator activity, and suspicious connections between web-tier systems and backend services.
Network defenders are advised to restrict access to administrative interfaces, enforce least-privilege access controls, place Oracle web components behind web application firewalls when feasible, and review proxy routing rules for any unauthorized changes.
Continuous asset discovery and external attack-surface monitoring are also crucial, as legacy Oracle deployments may remain exposed.
CISA urges all organizations to prioritize the remediation of vulnerabilities listed in the KEV Catalog, regardless of whether they are subject to federal directives.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

