Organizations should apply vendor-provided patches for CVE-2026-21962 as soon as possible. FCEB agencies must follow BOD 26-04 requirements, including prioritizing remediation on publicly exposed assets and checking for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor for indicators of compromise.
Quick answers
What is CVE-2026-21962?
Organizations should apply vendor-provided patches for CVE-2026-21962 as soon as possible. FCEB agencies must follow BOD 26-04 requirements, including prioritizing remediation on publicly exposed assets and checking for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor for indicators of compromise.
How severe is CVE-2026-21962?
high
Is CVE-2026-21962 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-21962 be mitigated?
Organizations should apply vendor-provided patches for CVE-2026-21962 as soon as possible. FCEB agencies must follow BOD 26-04 requirements, including prioritizing remediation on publicly exposed assets and checking for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor for indicators of compromise.
CVSS
—
Vendor
Oracle
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in
Mitigation
Organizations should apply vendor-provided patches for CVE-2026-21962 as soon as possible. FCEB agencies must follow BOD 26-04 requirements, including prioritizing remediation on publicly exposed assets and checking for signs of compromise before patching. All organizations are encouraged to adopt risk-based vulnerability management and monitor for indicators of compromise.
CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The advisory, published August 24, 2026, highlights the risk to federal enterprise and urges all organizations to adopt risk-based vulnerability management.