CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-21962)
CISA has added CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Federal agencies are mandated to remediate this under BOD 26-04, while CISA advises all organizations to prioritize patching. The vulnerability poses significant risks to exposed assets.
- cveCVE-2026-21962Improper Access Control Vulnerability that is actively exploited in the wild.
Detection / Hunteropenrouter
What Happened
CISA has added a newly discovered security flaw in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in to its list of known exploited vulnerabilities. This means attackers are actively using this flaw to break into systems. Federal agencies are required to fix this issue quickly, and CISA recommends that all organizations patch it as soon as possible. Organizations should check if their systems were compromised before the patch was applied.
Key Takeaways
- CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.
- The vulnerability is an Improper Access Control flaw affecting Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in.
- Federal Civilian Executive Branch (FCEB) agencies are required to remediate this vulnerability under BOD 26-04.
- CISA encourages all organizations, not just federal agencies, to prioritize remediation of KEV Catalog vulnerabilities.
Affected Systems
- Oracle HTTP Server
- Oracle Weblogic Server Proxy Plug-in
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Improper Access Control Vulnerability that is actively exploited in the wild. |
Attack Chain
- Initial Access: Threat actors exploit CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server or Oracle Weblogic Server Proxy Plug-in.
- Impact: Exploitation grants attackers unauthorized access to the affected system, potentially leading to total control of the asset.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules are provided in the article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The vulnerability affects server-side proxy components. EDR visibility depends on agent coverage on server endpoints and may not capture network-level exploitation of the access control flaw. |
| Network Visibility | Medium | Network monitoring may detect post-exploitation activity or anomalous traffic to the Oracle HTTP Server or Weblogic Server, but the initial exploitation of an access control vulnerability may blend in with legitimate traffic. |
| Detection Difficulty | Hard | Improper access control vulnerabilities often involve legitimate credentials or sessions being used in unauthorized ways, making them difficult to distinguish from normal traffic without specific application-level logging. |
Required Log Sources
- Oracle HTTP Server access logs
- Oracle Weblogic Server logs
- Web Application Firewall (WAF) logs
- Network flow data
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for anomalous access patterns or unauthorized resource access in Oracle HTTP Server and Weblogic Server logs following the exploitation of an access control vulnerability. | Oracle HTTP Server access logs, Weblogic Server application logs, WAF logs | Initial Access / Execution | Medium - Legitimate administrative access or application errors may generate similar log entries. |
Control Gaps
- Standard signature-based network intrusion detection may not detect exploitation of an access control vulnerability using legitimate-looking requests.
- Endpoint detection may miss server-side exploitation if agents are not deployed on the affected server infrastructure.
Key Behavioral Indicators
- Anomalous HTTP requests targeting Oracle HTTP Server or Weblogic Server Proxy Plug-in endpoints
- Unauthorized access to administrative functions or restricted resources via the proxy plug-in
- Unexpected changes in user privilege levels or access patterns in application logs
False Positive Assessment
Medium - Detecting exploitation of an access control vulnerability may trigger on legitimate administrative activity or application errors if hunting rules are too broad.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Identify all internet-exposed instances of Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in and apply available security patches immediately.
- If patching is delayed, consider implementing temporary WAF rules to block anomalous requests targeting the affected components, if supported by your tooling.
- Review access logs for affected systems to identify potential compromise that may have occurred prior to patching.
Infrastructure Hardening
- Evaluate whether network segmentation can be improved to isolate Oracle HTTP Server and Weblogic Server instances from non-essential network segments.
- Consider enforcing strict access control lists (ACLs) on management interfaces for the affected Oracle products.
User Protection
- If applicable to your environment, ensure that multi-factor authentication (MFA) is enforced for administrative access to Oracle HTTP Server and Weblogic Server management consoles.
Security Awareness
- Consider notifying server administration teams about the active exploitation of CVE-2026-21962 and the importance of rapid patch application.
MITRE ATT&CK Mapping
Initial Access
Related
- CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2025-25249, CVE-2026-19490, CVE-2026-87491 +1 more)·1
- URGENT UPDATE: Active Exploitation of Two Chained PaperCut NG/MF Vulnerabilities CVE-2026-81578 and CVE-2026-82078 - Arctic Wolf·1
- CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-75650, CVE-2026-81963, CVE-2026-85880 +1 more)·1