
CISA Adds Critical Oracle WebLogic Server Vulnerability to Exploited Catalog Amid Active Attacks
CybersecurityVulnerabilitiesExploitsEnterpriseSecurity
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity vulnerability (CVE-2026-21962, CVSS score: 10.0) affecting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog on Monday, citing active exploitation. The flaw allows unauthenticated attackers with network access via HTTP to compromise critical systems. No specific attack vectors, affected versions, or exploitation details beyond active abuse were provided in the notice. The inclusion in the KEV catalog indicates confirmed in-the-wild attacks targeting the vulnerability. Oracle has not yet released a public advisory or patch timeline for CVE-2026-21962.