Oracle WebLogic Under Active Nation-State Exploitation — CVSS 10.0, 100+ Countries Hit
CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog with a 72-hour remediation deadline that expires today, August 27. The vulnerability carries a maximum CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This is not theoretical.
What's Happening
A China-linked threat actor is exploiting CVE-2026-21962 in an active campaign across more than 100 countries, delivering the SNOWLIGHT downloader to government and commercial infrastructure targets. The flaw is an improper access control vulnerability that allows an unauthenticated attacker with network access via HTTP to gain complete access to all accessible data on the affected Oracle HTTP Server or WebLogic Server Proxy Plug-in instance, including unauthorized creation, deletion, and modification of critical data.
Honeypot data from CloudSEK confirms attackers are chaining CVE-2026-21962 with older WebLogic RCE flaws (CVE-2020-14882/14883, CVE-2020-2551, CVE-2017-10271), showing a sustained, multi-vector campaign against Oracle middleware.
Why This Matters Now
The vulnerability was disclosed and patched by Oracle in January 2026. Seven months later, it remains widely unpatched and under active nation-state exploitation. CISA's three-day deadline for federal agencies underscores the urgency. If you run Oracle HTTP Server or WebLogic Server Proxy Plug-in versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 and have not applied the January 2026 Critical Patch Update, you should assume hostile access.
Also This Week: NetScaler Double Trouble
Citrix disclosed CVE-2026-19490 (CVSS 9.3 authentication bypass) on August 19, two days after confirming active exploitation of CVE-2026-8452 (pre-auth memory overflow, CVSS 8.8) on the same NetScaler ADC and Gateway appliances. Both target perimeter-facing AAA and Gateway virtual servers. A public PoC exists for CVE-2026-8452. The authentication bypass requires no credentials and no user interaction. Fix versions differ between the two CVEs (14.1-73.32+ for CVE-2026-19490, 14.1-72.61+ for CVE-2026-8452), meaning patching one does not patch the other. If you run NetScaler in Gateway or AAA mode, patch both to the latest available build immediately.
So What / Action
Check your asset inventory for Oracle HTTP Server and WebLogic Server Proxy Plug-in (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and Citrix NetScaler ADC/Gateway. Apply the January 2026 Oracle Critical Patch Update now. Patch NetScaler to 14.1-73.32 or later (which covers both CVEs). Hunt for SNOWLIGHT IOCs on any Oracle middleware exposure. If you cannot patch immediately, isolate or disable internet-facing Oracle HTTP Server and WebLogic Proxy Plug-in instances. This is a CVSS 10.0 flaw being exploited by a state actor to compromise government infrastructure. The three-day window is not a suggestion.

