HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

CISA Adds Exploited Oracle HTTP Server Access Control Flaw (CVE‑2026‑21962) to KEV Catalog

CISA announced that CVE‑2026‑21962, an improper access‑control bug in Oracle HTTP Server and WebLogic proxy plug‑in, is now listed in the Known Exploited Vulnerabilities catalog, indicating active exploitation. The vulnerability affects any organization running the affected Oracle components and triggers immediate remediation requirements. For compliance teams, the addition creates a concrete control gap that must be addressed to satisfy SOC 2 security criteria and risk‑based vulnerability management expectations.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

CISA Adds Exploited Oracle HTTP Server Access‑Control Flaw (CVE‑2026‑21962) to KEV Catalog

What It Is – CISA announced that CVE‑2026‑21962, an improper access‑control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server proxy plug‑in, has been added to the agency’s Known Exploited Vulnerabilities (KEV) catalog. The advisory confirms that threat actors are actively exploiting the flaw to gain unauthorized control of affected web assets.

Exploitability – Active exploitation is documented; a public exploit exists. The vulnerability scores 8.6 (High) on the CVSS 3.1 scale. No official patch was available at the time of the advisory, prompting urgent remediation.

Affected Products – Oracle HTTP Server (OHS) and Oracle WebLogic Server proxy plug‑in (any version vulnerable to CVE‑2026‑21962).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Control Mapping – The flaw maps to CC6.1 (System security) and CC7.1 (Change management). Demonstrating timely remediation is essential evidence for a defensible audit.
  • Continuous Monitoring – Ongoing vulnerability scanning and patch‑status dashboards provide the audit trail required by BOD 26‑04 and SOC 2 continuous‑compliance expectations.
  • Risk‑Based Prioritization – The KEV listing forces organizations to treat this as a high‑risk item, aligning with the “risk‑based vulnerability management” principle that auditors now scrutinize.

Recommended Actions

  • Inventory all Oracle HTTP Server and WebLogic instances across your environment.
  • Prioritize patching of CVE‑2026‑21962 per the KEV guidance; apply vendor‑released fixes or mitigations immediately.
  • Validate remediation with authenticated scans and log‑review to confirm the vulnerability is closed.
  • Document the remediation steps in your change‑management system and map the activity to SOC 2 CC6.1/CC7.1 controls.
  • Integrate the patch status into your continuous‑compliance platform to generate real‑time audit evidence.

Source: CISA Advisory – 24 Aug 2026

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →