Oracle WebLogic Server Flaw CVE-2026-21962 Under Active Attack
- Severity
- CRITICAL
- CVSS
- 10
- Affected component
- oracle weblogic (other)
- Patched version
- Not yet available
Oracle WebLogic Server is under investigation for a critical security flaw, tracked as CVE-2026-21962, that allows unauthenticated attackers to access critical data. This vulnerability is being actively exploited in the wild.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This flaw impacts Oracle HTTP Server and the WebLogic Server Proxy Plug-in, allowing unauthenticated attackers with network access via HTTP to compromise these servers. Successful exploitation can lead to unauthorized access to instances or modification of critical data.
Oracle released patches for this vulnerability in January 2026, but it has since been widely exploited. Reports indicate that multiple threat actors are attempting to exploit this and other known vulnerabilities in Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI.
What to do about it
- Upgrade to the latest version of Oracle WebLogic Server to mitigate the risk.
- Ensure that network access to Oracle WebLogic Server is properly secured.
- Monitor the primary sources for updates on this vulnerability and any official fixes.
- Consult the primary sources for the most current information on affected versions and patches.
How 0Day would have caught this
oracle weblogic is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Oracle WebLogic Server, you may be affected. Consult the primary sources for the latest information on affected versions.
What should I do right now?
Upgrade to the latest version of Oracle WebLogic Server and ensure that network access is properly secured. Monitor the primary sources for updates.
Has this been exploited in the wild?
Yes, this vulnerability is reportedly being actively exploited.