Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Palm oil firms kept zero-deforestation pledges, but forests saw little extra benefit

    August 25, 2026

    30-year-old North Sea project gets gas boost with early start to its next chapter

    August 25, 2026

    From Scotland, I look at England’s water privatisation disaster. I wish you had done what we did | Devi Sridhar

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Palm oil firms kept zero-deforestation pledges, but forests saw little extra benefit
    • 30-year-old North Sea project gets gas boost with early start to its next chapter
    • From Scotland, I look at England’s water privatisation disaster. I wish you had done what we did | Devi Sridhar
    • Trump Administration to Return Diplomats to Middle East Embassies
    • Government lays out housing plans but Burnham backtracks on social renting pledge – UK politics live | Politics
    • Amazon hikes prices on Echos, Kindles, Fire TVs as much as 60% – here’s what you’ll pay now
    • CISA Warns of Exploited Oracle WebLogic Vulnerability
    • Tether’s $120 million Uruguay mining failure now shadows its next Bitcoin bet in Brazil
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Warns of Exploited Oracle WebLogic Vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against Oracle WebLogic servers.

    The remote code execution flaw, identified as CVE-2026-21962 with a CVSS score of 10, affects Oracle HTTP Server and the WebLogic Server Proxy plugin, which bridges HTTP Server to WebLogic.

    The security hole can be exploited without authentication to hack affected servers. Oracle patched the vulnerability with its January 2026 updates. 

    CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog on August 24 and instructed federal agencies to address it by August 27. 

    [ Read: CISA Tells Federal Agencies to Prioritize Patches Based on Risk ]

    While the KEV list is primarily designed for government agencies, all organizations can use it to prioritize patching, alongside other tools and resources. 

    Advertisement. Scroll to continue reading.

    It’s unclear which attacks triggered CISA’s alert for CVE-2026-21962. The vulnerability has been exploited since January, with the first attacks flagged by CloudSEK.

    The security firm warned in March that its honeypots had seen exploitation attempts aimed at Oracle WebLogic servers since January 22, immediately after a PoC exploit was made public.

    FalconFeeds mentioned the vulnerability’s exploitation in June, in a post describing the cybercrime supply chain. This was one of the several weaknesses exploited against enterprises, but not specific details were shared. 

    SOCRadar reported in July that CVE-2026-21962 had been one of the several vulnerabilities exploited by a China-linked threat actor in attacks targeting government infrastructure.

    WebLogic servers are often targeted by hackers. CISA’s KEV catalog currently includes more than a dozen such vulnerabilities. 

    Related: 91 Vulnerabilities Patched in Spring Application Framework

    Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Related: Hackers Target Zimbra Servers in Active Exploitation Campaign

    CISA Exploited Oracle Vulnerability warns WebLogic
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TikTok reaches $400M settlement with US over COPPA violations

    US Treasury’s Scott Bessent ‘will lose’ battle with bond markets, former mentor warns | US economy

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    91 Vulnerabilities Patched in Spring Application Framework

    Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

    Foul Language: WordlistLoader Disguises Malware as Ordinary Text

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Palm oil firms kept zero-deforestation pledges, but forests saw little extra benefit

    August 25, 2026

    30-year-old North Sea project gets gas boost with early start to its next chapter

    August 25, 2026

    From Scotland, I look at England’s water privatisation disaster. I wish you had done what we did | Devi Sridhar

    August 25, 2026

    Trump Administration to Return Diplomats to Middle East Embassies

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Palm oil firms kept zero-deforestation pledges, but forests saw little extra benefit

    August 25, 2026

    30-year-old North Sea project gets gas boost with early start to its next chapter

    August 25, 2026

    From Scotland, I look at England’s water privatisation disaster. I wish you had done what we did | Devi Sridhar

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.