CYBERSECURITYTRACKER
TRACKING4,538 stories855 vuln stories
Permanent story citation

CISA Adds One Known Exploited Vulnerability to Catalog

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4949

As cited

Citation snapshot as of .

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-21962, an Oracle HTTP Server and Weblogic Server proxy plug-in improper access control vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. The vulnerability poses significant risk because it can grant total control of affected assets after exploitation. Federal agencies are required under Binding Operational Directive 26-04 to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed systems.

Why it matters: Organizations running Oracle HTTP Server or Weblogic Server with exposed proxy plug-ins must patch CVE-2026-21962 immediately, as it is actively exploited and grants complete post-exploitation control; federal agencies face compliance deadlines under BOD 26-04.

Source published
First seen by Cybersecurity Tracker

Source attribution