CISA has flagged a critical CVSS 10 vulnerability in Oracle WebLogic servers that is being actively exploited by threat actors, including China-linked groups. Organizations are urged to patch immediately to prevent remote code execution.

  • CVE-2026-21962 is a critical-rated vulnerability (CVSS 10) allowing unauthenticated remote code execution.
  • CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
  • Threat actors, including China-linked groups, are actively targeting government infrastructure.

The cybersecurity agency CISA has issued an urgent directive to government organizations to immediately patch a critical vulnerability that is being widely exploited in targeted attacks against Oracle WebLogic servers. The flaw poses a severe risk to enterprise infrastructure worldwide.

Identified as CVE-2026-21962, this remote code execution (RCE) vulnerability carries a maximum CVSS score of 10. It specifically affects the Oracle HTTP Server and the WebLogic Server Proxy plugin, which acts as a bridge between the HTTP Server and the WebLogic environment. The most alarming aspect is that the vulnerability can be exploited without any authentication, allowing hackers to gain full control of affected servers.

Timeline of Exploitation

The exploitation of this flaw has been an ongoing threat since early 2026. Security firm CloudSEK first flagged exploitation attempts in late January, shortly after a Proof of Concept (PoC) was made public. In June, FalconFeeds highlighted its role in the cybercrime supply chain, and by July, SOCRadar reported that China-linked threat actors were utilizing this specific vulnerability to target critical government infrastructure.

Why This Matters

BozokMedia analysis shows that vulnerabilities with a CVSS score of 10 represent the highest tier of digital risk. Because this flaw bypasses authentication, it effectively leaves the front door of an organization's server wide open. For government agencies and large enterprises, this provides a direct pathway for espionage, data exfiltration, and large-scale ransomware deployment.

An unauthenticated RCE vulnerability is the 'holy grail' for threat actors, providing immediate and total system compromise.

Oracle released patches for this vulnerability as part of its January 2026 updates. Following the discovery of active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on August 24, mandating that federal agencies remediate the issue by August 27.

Historical Background

Oracle WebLogic servers have historically been a high-value target for advanced persistent threat (APT) groups due to their central role in managing complex enterprise applications. Previous years have seen numerous critical vulnerabilities discovered in these systems, making consistent patching a cornerstone of modern cybersecurity posture.

Frequently Asked Questions

1. How do I know if my system is vulnerable?
Check if you are running Oracle HTTP Server or the WebLogic Server Proxy plugin without the January 2026 security updates.

2. Is this vulnerability being used by state-sponsored actors?
Yes, reports from SOCRadar indicate that China-linked actors are actively exploiting this flaw.