Vulnerabilities · 173 days ago

Immediate Attacks Target Oracle WebLogic RCE Flaw

CloudSEK honeypot logs show exploitation of CVE-2026-21962 against Oracle WebLogic began on Jan 22, the same day exploit code was published.

CVE-2026-21962

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware… EPSS 42% (99th percentile).

CISA federal remediation date Aug 27

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-27

Editions

Related stories