Menu
Technology lights

CISA confirms active exploitation of Oracle CVSS 10.0 Vulnerability

Posted on 22 September 2026

Reading time 3 minutes

What happened?

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalogue after confirming active exploitation in the wild.

The vulnerability, which affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in - a component commonly used to route traffic between internet-facing web servers and backend WebLogic applications - leverages an improper access control vulnerability, allowing an unauthenticated attacker to bypass security controls and gain access to sensitive data through specially crafted HTTP requests. Successful exploitation of this flow can facilitate the creation, modification, or deletion of data, as well as potentially enabling broader access to systems and applications protected by the proxy layer.

This vulnerability is significant because it targets a trusted component that sits at the boundary between external users and internal applications; by exploiting inconsistencies in how the proxy layer and backend WebLogic servers process requests, attackers can bypass intended access restrictions and reach protected resources.

CISA's designation is notable because it triggered the agency's shortest remediation window under Binding Operational Directive (BOD) 26-04, requiring Federal Civilian Executive Branch agencies to remediate affected systems within 72 hours and assess whether compromise occurred prior to patching. Despite Oracle releasing patches in its January 2026 Critical Patch Update, exploitation activity began almost immediately after a public proof-of-concept became available on Github on January 22nd 2026.

So what?

CVE-2026-2196 carries a CVSS v3.1 score of 10.0, the maximum possible severity rating. This reflects a particularly dangerous combination of characteristics – not only can this vulnerability be exploited remotely over HTTP, it requires no authentication or user interaction, and can provide access beyond the vulnerable component itself into protected backend systems.

For organisations exposing Oracle HTTP Server or WebLogic Proxy Plug-in instances to the internet, exploitation could result in unauthorised access to sensitive applications and data, potentially leading to operational disruption, data compromise, or further lateral movement within the environment. This, combined with public-disclosed exploit code, automated scanning activity, and confirmed active exploitation shows that this vulnerability that is both easy to exploit and capable of causing substantial business impact.

In practical terms, this means that an internet-facing vulnerable server can be targeted directly by attackers without stolen credentials or user involvement.

Unlikely severity scores, KEV entries are based on confirmed exploitation - while BOD 26-04 applies only to U.S. federal agencies, many organisations view KEV inclusion as a de facto prioritisation signal because it demonstrates that threat actors are actively exploiting the vulnerability against real-world targets.

The case also highlights a recurring challenge in vulnerability management; exploitation continued for more than seven months before CISA's emergency action. Organisations that delayed patching may face increased scrutiny following an incident, particularly where vulnerability management processes, regulatory obligations, contractual requirements, or cyber-insurance conditions require timely remediation of known security flaws.

What should I do?

Oracle has addressed CVE-2026-21962 through its January 2026 Critical Patch Update - organisations running affected versions of Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in should treat deployment of the update as an urgent priority. Where patching cannot be completed immediately, organisations should implement additional controls and review affected systems for evidence of previous compromise.

Organisations should begin by identifying their exposure through an inventory of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in deployments, with particular attention to versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. This should be accompanied by retrospective compromise assessments, including reviews of logs for suspicious unauthenticated requests, unusual access patterns, data modifications and indicators of lateral movement. Where affected proxy components are exposed externally, access should be restricted through network segmentation, firewall controls and IP allowlisting where possible, while compensating controls such as Web Application Firewall protections should be deployed to detect path traversal and access-control bypass attempts.

Monitoring should also be strengthened through detailed logging, SIEM correlation rules, file-integrity monitoring and network traffic analysis. Internet-facing assets should be verified against the KEV Catalog, with KEV monitoring incorporated into routine vulnerability management processes to ensure that actively exploited vulnerabilities are prioritised appropriately.

Finally, remediation and investigation activities should be documented to support regulatory, audit and cyber-insurance requirements should a future incident occur.

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else