Hackers have started exploiting a CVSS 10-rated Oracle bug patched in January, according to the US government’s cybersecurity agency, which added CVE-2026-21962 to its exploited bug database this week.

The Cybersecurity and Infrastructure Security Agency (CISA) gave security teams its tightest three-day deadline to patch the improper access bug in Oracle’s HTTP Server and Weblogic Server Proxy Plug-in, after adding it to its Known Exploited Vulnerabilities Catalogue.

A notice on 24 August said the vulnerability could “result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.”

The trivially exploitable bug affects Oracle’s Fusion Middleware and was patched in January 2026, but neither Oracle nor security researchers flagged exploitation in the wild at the time.

Honeypot exploitation

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now

Already a member? Sign in