CISA adds Oracle WebLogic bug to its list of exploited vulnerabilities
The Cybersecurity and Infrastructure Security Agency on Aug. 24 added a widely exploited maximum-severity Oracle WebLogic server bug to it Known Exploited Vulnerabilities (KEV) catalog.CISA gave federal agencies until Aug. 27 to patch CVE-2026-21962, an easily exploitable vulnerability that lets an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and the Oracle WebLogic Server Proxy plug-in.Adrian Culley, offensive security engineer at SafeBreach, said SOCRadar reported in July that this flaw was already one of several vulnerabilities a China-linked actor was using against government targets â and this was months before CISA's KEV listing and its three-day federal deadline caught up in August.âOracle's fix shipped in January,â said Culley. âThe window between âpatchedâ and âstate-linked actor operationalâ was measured in weeks, not the compressed panic the KEV date suggests.â
Culley said security teams have taken note of this bug because WebLogic Server Proxy Plug-in functions as the HTTP front door bridging Apache or IIS to the application server behind it: once exploited, the flaw lets an unauthenticated, network-based attacker read, create, or modify whatever data that proxy reaches. âReported campaigns like this rarely win on novel tooling,â said Culley. âThey win because internet-facing proxy components sit outside the inventory and monitoring that the application server itself gets.
Patched since January isn't the same as watched since January.âSam Decker, threat intelligence engineer at Blackpoint Cyber, pointed out that CISA doesn't add something to the KEV without confirmed real-world exploitation, and this one has been under active attack since January, including against government targets.Decker explained that this CVE needs no credentials: just network access gets attackers full remote code execution on Oracle WebLogic, which sits at the core of a lot of internet-facing enterprise app stacks.âThat combination: no login required and a high-value target, means working exploits get weaponized and scanned for at internet scale within days,â said Decker. âA KEV listing should be read as a forcing function: the patch window is already closing, and every day after that is borrowed time.âRogier Fischer, co-founder and CEO of Hadrian, noted that CloudSEK observed exploitation immediately after public exploit code appeared on Jan. 22 and described high-volume automated attacks against its WebLogic honeypot as âwidespreadââThis is potentially going to become an important distinction for security teams, particularly as July was a record-breaking month for CVE disclosures,â said Fischer. âAttackers canât turn every vulnerability into reliable, low-touch exploitation at scale, and those that can are more likely to be used in widespread, opportunistic attacks.â
Culley said security teams have taken note of this bug because WebLogic Server Proxy Plug-in functions as the HTTP front door bridging Apache or IIS to the application server behind it: once exploited, the flaw lets an unauthenticated, network-based attacker read, create, or modify whatever data that proxy reaches. âReported campaigns like this rarely win on novel tooling,â said Culley. âThey win because internet-facing proxy components sit outside the inventory and monitoring that the application server itself gets.
Patched since January isn't the same as watched since January.âSam Decker, threat intelligence engineer at Blackpoint Cyber, pointed out that CISA doesn't add something to the KEV without confirmed real-world exploitation, and this one has been under active attack since January, including against government targets.Decker explained that this CVE needs no credentials: just network access gets attackers full remote code execution on Oracle WebLogic, which sits at the core of a lot of internet-facing enterprise app stacks.âThat combination: no login required and a high-value target, means working exploits get weaponized and scanned for at internet scale within days,â said Decker. âA KEV listing should be read as a forcing function: the patch window is already closing, and every day after that is borrowed time.âRogier Fischer, co-founder and CEO of Hadrian, noted that CloudSEK observed exploitation immediately after public exploit code appeared on Jan. 22 and described high-volume automated attacks against its WebLogic honeypot as âwidespreadââThis is potentially going to become an important distinction for security teams, particularly as July was a record-breaking month for CVE disclosures,â said Fischer. âAttackers canât turn every vulnerability into reliable, low-touch exploitation at scale, and those that can are more likely to be used in widespread, opportunistic attacks.â
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.