As cited
Citation snapshot as of .
vulnerabilities
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-21962, an Oracle HTTP Server and Weblogic Server proxy plug-in improper access control vulnerability, to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. The vulnerability poses significant risk because it can grant total control of affected assets after exploitation. Federal agencies are required under Binding Operational Directive 26-04 to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed systems.
Why it matters: Organizations running Oracle HTTP Server or Weblogic Server with exposed proxy plug-ins must patch CVE-2026-21962 immediately, as it is actively exploited and grants complete post-exploitation control; federal agencies face compliance deadlines under BOD 26-04.
- Source published
- First seen by Cybersecurity Tracker