CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-21962, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, and involves improper access control that attackers are actively exploiting in the wild.
Vulnerabilities of this type are commonly used by cybercriminals as an entry point into networks, making them a significant risk for any organisation running affected software. While CISA's related Binding Operational Directive (BOD 26-04) technically applies only to US federal agencies, it sets a useful benchmark: prioritise patching vulnerabilities that could give attackers total control of an exposed system, and check for signs of prior compromise before applying fixes.
Australian businesses using Oracle HTTP Server or WebLogic Server Proxy Plug-in should treat this as an urgent patching priority, even though local regulations don't mandate it. Cybercriminals often target the same known vulnerabilities globally, regardless of which government catalog lists them.