Threat+Constellation
Live UTC
← Incidents
INCIDENT 236Exploited vulnerabilityHIGH CONFIDENCESourced

CVE-2026-21962 added to CISA KEV: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

<p>CISA has added one new vulnerability to its <a href="https://edit.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-21962" target="_blank">CVE-2026-21962</a> Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability</li> </ul> <p>This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.</p> <p><a href="https://e…

Last evidence update
24 AUG 2026 · 12:00 UTC
Source count
3
Status
high confidence
GovernmentCVE-2026-21962
Observation history

How this record has evolved as evidence accumulated.

25 AUG · 05:17 UTC
Initial report
25 AUG · 05:17 UTC
Second independent source
25 AUG · 05:17 UTC
Confidence upgraded
25 AUG · 05:17 UTC
Status changed
25 AUG · 05:17 UTC
Second independent source
25 AUG · 05:17 UTC
Summary updated from new evidence
Evidence