highZero-Day

CISA KEV Catalog Addition: Oracle HTTP Server / WebLogic Proxy Plug-in Improper Access Control (CVE-2026-21962)

First seen Aug 25, 2026 · Updated Aug 25, 2026

oracleweblogichttp-serverknown-exploited-vulnerabilityCISAaccess-controlagent-relevant

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.

Technical Analysis

CVE-2026-21962 is an improper access control flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows attackers to bypass intended access restrictions, potentially enabling unauthorized access to backend resources or administrative functions on affected servers. This class of vulnerability is a common initial access vector for threat actors targeting internet-facing middleware, and CISA's inclusion in the KEV catalog confirms it is being actively exploited rather than theoretical. No technical exploitation details, PoC, or CVSS scoring have been published in this alert; organizations should consult Oracle's advisory for the full impact chain and affected component versions. Because WebLogic and Oracle HTTP Server are frequently used as reverse proxies and application front-ends for enterprise middleware, any organization running LLM/RAG backends, agent orchestration APIs, or tool-serving microservices behind these components could see unauthorized access to internal agent endpoints, exposed API keys, or manipulation of agent tool-call routing if the proxy layer is compromised.

Affected Systems

Oracle HTTP Server (various versions); Oracle WebLogic Server Proxy Plug-in (versions to be confirmed via Oracle Critical Patch Update advisory); publicly exposed instances are highest risk.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) published in this CISA alert; organizations should monitor Oracle security advisories and CISA KEV catalog entry for updates.

Remediation Steps

  1. 1

    Apply Oracle Patches

    Review Oracle's Critical Patch Update advisories and apply the fix for CVE-2026-21962 to all affected Oracle HTTP Server and WebLogic Proxy Plug-in installations immediately.

  2. 2

    Prioritize Internet-Facing Assets

    Identify and prioritize remediation on publicly exposed Oracle HTTP Server/WebLogic instances per BOD 26-04 risk-based guidance.

  3. 3

    Compromise Assessment

    Per BOD 26-04 requirements, check whether systems were compromised prior to patching, including reviewing access logs for anomalous authentication or access-control bypass attempts.

  4. 4

    Network Segmentation

    Restrict administrative interfaces and backend access from the WebLogic proxy layer, especially where it fronts sensitive services such as AI agent APIs, RAG data stores, or credential vaults.

  5. 5

    Rotate Exposed Credentials

    If the proxy layer serves as a gateway to agent tooling or API keys, rotate any credentials that may have been exposed and audit for unauthorized API calls.

CVE / Advisory IDs

CVE-2026-21962

Industries Most Exposed

GovernmentFederal Civilian Executive BranchTechnologyFinanceHealthcareCritical Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.