The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for government organizations to swiftly patch a severe vulnerability within Oracle WebLogic servers. This flaw, designated as CVE-2026-21962, carries a CVSS score of 10, highlighting its critical nature. It affects both the Oracle HTTP Server and the WebLogic Server Proxy plugin, which connects the HTTP Server to WebLogic, making it a significant security risk.

The vulnerability allows attackers to execute remote code without needing authentication, which places affected servers at grave risk of being compromised. Oracle addressed this security hole with their January 2026 updates, yet the urgency to patch remains due to ongoing threats. CISA included CVE-2026-21962 in its Known Exploited Vulnerabilities catalog on August 24, urging federal agencies to implement the fix by August 27.

While the KEV list is tailored for government use, organizations across the board can utilize it to prioritize their patching strategies. The specific incidents that prompted CISA's alert remain unspecified, but reports indicate that exploitation of this vulnerability has been ongoing since January. Initial attacks were identified by CloudSEK, who noted exploitation attempts as early as January 22, shortly after a proof-of-concept exploit was released.

FalconFeeds highlighted the vulnerability's use within the cybercrime supply chain in June, noting its role among several exploited weaknesses. Additionally, SOCRadar reported in July that the flaw was part of a broader campaign by a China-linked threat actor targeting government infrastructure.

Oracle WebLogic servers frequently attract malicious actors, and the CISA's KEV catalog already lists over a dozen vulnerabilities associated with them. The immediate patching of CVE-2026-21962 is crucial to defend against potential attacks that leverage this critical weakness.