JAVA · AUGUST 2026 · EARLY WARNING

Oracle WebLogic Server Flaw CVE-2026-21962 Under Active Attack

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
10
Affected component
oracle weblogic (other)
Patched version
Not yet available
CVE-2026-21962

Oracle WebLogic Server is under investigation for a critical security flaw, tracked as CVE-2026-21962, that allows unauthenticated attackers to access critical data. This vulnerability is being actively exploited in the wild.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This flaw impacts Oracle HTTP Server and the WebLogic Server Proxy Plug-in, allowing unauthenticated attackers with network access via HTTP to compromise these servers. Successful exploitation can lead to unauthorized access to instances or modification of critical data.

Oracle released patches for this vulnerability in January 2026, but it has since been widely exploited. Reports indicate that multiple threat actors are attempting to exploit this and other known vulnerabilities in Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If oracle weblogic is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Oracle WebLogic Server, you may be affected. Consult the primary sources for the latest information on affected versions.

What should I do right now?

Upgrade to the latest version of Oracle WebLogic Server and ensure that network access is properly secured. Monitor the primary sources for updates.

Has this been exploited in the wild?

Yes, this vulnerability is reportedly being actively exploited.

Sources

Join the 0Day waitlist →

← Back to all threats