[KEV] CVE-2026-21962 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-21962 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-21962 is an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in.
Technical Detail
The vulnerability results from insufficient access control enforcement in the affected Oracle components. An attacker able to exploit the flaw may obtain unauthorized access to data exposed through the affected deployment and may create, modify, or delete critical data. The available information does not confirm the required access level, attack vector, or specific vulnerable request path.
Exploitation Status
Exploit maturity is assessed as operational, indicating that a usable exploit capability is available for real-world use. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities Catalog on August 24, 2026.
Who Is Targeting This
Reported (research-inferred): no public attribution. The supplied reporting references CISA KEV and the vendor but does not identify a specific threat actor, origin, or motivation.
What To Do
Apply Oracle's security update for the affected Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in deployments as a priority. For federal civilian executive branch agencies, patch by September 14, 2026, or apply mitigations in accordance with CISA Binding Operational Directive 22-01. Where patching cannot be completed immediately, restrict access to affected administrative and proxy interfaces, limit exposure to trusted networks, review access-control configurations, and monitor for unexpected data creation, modification, deletion, or access involving Oracle HTTP Server and WebLogic Proxy Plug-in services.