CISA adds a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that it is being actively exploited. The flaw is tracked as CVE-2026-21962 and has a CVSS score of 10.0.

According to the reports, CVE-2026-21962 can be exploited by unauthenticated attackers that have network access over HTTP to gain access to critical information. SecurityWeek and the Hacker News both describe broad targeting of WebLogic servers by threat actors, consistent with CISA’s determination that exploitation is occurring in the wild.

While both outlets focus on CISA’s KEV designation and the vulnerability’s public identification, they do not substantially diverge on the core technical premise: the issue is internet-reachable via HTTP, does not require authentication, and is linked to unauthorized access to sensitive data. The differing emphasis is mainly on framing—one highlights the “actively exploited” aspect and the data exposure outcome, while the other underscores the widespread exploitation by threat actors following CISA’s warning.