Critical Oracle WebLogic Vulnerability Under Active Attack—Patch Now
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog, confirming it is being actively used by attackers. The flaw, tracked as CVE-2026-21962, has received the highest possible severity score of 10.0 out of 10.
What makes this vulnerability especially dangerous is that it requires no authentication at all. An attacker simply needs network access to a vulnerable server via HTTP to potentially access critical data. This means businesses running affected Oracle systems could be exposed to data breaches without any warning signs, as attackers don't need stolen credentials or insider access to exploit the flaw.
While Oracle WebLogic Server is more commonly used by larger enterprises and organisations running complex web applications, Australian small businesses that rely on third-party vendors or managed service providers using Oracle infrastructure should confirm with their providers that patches have been applied. Given the flaw is already being exploited in the wild, delaying action increases risk significantly.