CVE-2026-21962
Known exploited · CISA KEV
CVSS 10 CRITICAL: vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware… EPSS 42% (99th percentile).
CISA federal remediation date Aug 27
Vulnerabilities & Exploits · Web App Attack
CloudSEK honeypot logs show exploitation of CVE-2026-21962 against Oracle WebLogic began on Jan 22, the same day exploit code was published.
1 source · Mar 26
Known exploited · CISA KEV
CVSS 10 CRITICAL: vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware… EPSS 42% (99th percentile).
CISA federal remediation date Aug 27
Infosecurity Magazine
Rapid Exploitation of CVE-2026-21962 Hits Oracle WebLogic
Attackers rapidly exploited a critical Oracle WebLogic RCE flaw the same day exploit code was released, according to a CloudSEK honeypot study
originalPart of the PlainSec briefing for 2026-03-27
Every edition of this story: Immediate Attacks Target Oracle WebLogic RCE Flaw