# CISA flags exploited Oracle server flaw

_Tuesday, August 25, 2026 at 2:12 AM EDT · Security · Latest · Tier 1 — Major_

![CISA flags exploited Oracle server flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl_xYf_N0l1MVU0TVJFootEd6UCngqtfmbbEKRc06D7-0-ehjKU2SrBoA3qKaSkUWrOzgAu6hkbtimW8U7M4zgfH_6jXzgy6w7aQEGQKni-doNdQFCmAm9_vI_Zq4I6tx7lO2q533pbWWOLKBuUUYLGdY9O7SfBcwcGrqvsMLaFMPL09xXK86vRu38JfEp/s1700-e365/oracle.jpg)

CISA added CVE-2026-21962, a maximum-severity flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog, citing active exploitation. The reported improper-access-control issue can allow an unauthenticated attacker with HTTP network access to obtain unauthorized access or create, delete or modify critical data. Oracle released patches in January, and federal civilian agencies have been recommended to apply fixes by August 27 under Binding Operational Directive 26-04.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html)

---
Canonical: https://techandbusiness.org/newswire/lBpQBvZ4TurFJRPltZAd4S
Retrieved: 2026-08-25T10:47:10.332Z
Publisher: Tech & Business (techandbusiness.org)
