
CISA Adds CVE-2026-21962 to KEV as Single IP Scans Oracle WebLogic and Related Targets
Active exploitation of CVE-2026-21962 demonstrates persistent attacker focus on Oracle WebLogic proxy components. Technical evidence from GreyNoise and CloudSEK shows coordinated probing of multiple legacy RCEs from one infrastructure node. Agencies face a hard August 27 deadline while broader enterprise exposure remains unmeasured.
The flaw stems from improper access control in the proxy plug-in, permitting network attackers to create, delete, or modify critical data without credentials. Oracle released patches in January 2026, yet exploitation persisted. Evidence shows IP 193.24.123[.]42 probing this CVE alongside CVE-2020-14882, CVE-2020-2551, and CVE-2017-10271, revealing reuse of a narrow set of high-impact WebLogic vectors. Procurement records and prior CISA directives indicate federal agencies continue operating unpatched WebLogic instances behind load balancers, where proxy plug-ins often receive delayed updates. CloudSEK honeypot data from March 2026 captured repeated attempts, confirming threat actors prioritize these components for initial access rather than zero-days. Federal Civilian Executive Branch agencies must remediate by 27 August 2026 under BOD 26-04. Independent telemetry suggests commercial entities lag further, increasing risk of supply-chain pivots from compromised proxies. Next observable signal will be whether scan volume from the known IP cluster exceeds 100 unique targets per day within 14 days of the KEV listing.
GreyNoise: IP cluster around 193.24.123.42 will exceed 100 unique WebLogic targets daily by 8 September 2026
Sources (3)
- [1]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [2]CloudSEK Threat Intelligence Report March 2026(https://cloudsek.com/blog/weblogic-exploitation-campaign)
- [3]GreyNoise CVE-2026-21962 Observations(https://viz.greynoise.io/ip/193.24.123.42)