decrypted · 25 august 2026 · vulnerabilities and patching · supply chain
The Oracle flaw patched in January, still being exploited seven months on
CISA has just added an Oracle flaw to its Known Exploited Vulnerabilities catalogue with a three-day fix deadline. The twist: Oracle patched it in January. CVE-2026-21962, a maximum-severity (CVSS 10.0) flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, has reportedly been under attack since the day a proof-of-concept exploit went public, seven months before CISA's own watchlist caught up. For UK organisations still running WebLogic behind an Apache or IIS proxy, a widely-used setup in enterprise and public sector estates, this is less a new emergency than a reminder of how long an old one can quietly run.
A checkpoint that stopped checking
The WebLogic Proxy Plug-in exists to do one job: sit in front of the public-facing web server and forward only legitimate requests through to the internal application server, filtering out anything that shouldn't get that far. CVE-2026-21962 is an improper access control flaw that lets an unauthenticated attacker skip that filter entirely, over plain HTTP, and reach the data the plug-in was built to protect: creating, deleting or modifying it at will. It is the security equivalent of a hotel's loading-dock door being wired to the same badge reader as reception, so anyone walking in round the back gets treated as a checked-in guest.
Patched in January, exploited since January, listed in August
Oracle shipped the fix in its January 2026 critical patch update. According to honeypot monitoring from CloudSEK, exploitation attempts began on 22 January, the same day a public proof-of-concept exploit appeared, and continued through the following months alongside attacks on older, unrelated WebLogic bugs dating back to 2017. CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue on 24 August, giving US federal agencies until 27 August to remediate.
That seven-month gap is the actual story. A KEV listing tells you a vulnerability has been exploited for long enough, and confirmed by enough independent researchers, to clear a government agency's evidentiary bar. It does not tell you when the danger started. Any UK organisation whose patch prioritisation waits for a CVE to show up on a watchlist, rather than treating "maximum severity, internet-facing, patch available" as sufficient grounds on its own, is managing risk on a seven-month delay by design. The fix here was never complicated: apply Oracle's January update. The failure, where it happened, was organisational, not technical.
Also this week
Phishing infrastructure that isn't malware at all. Researchers at OX Security found 24 npm packages being used not to infect anyone who installs them, but as free, trust-laundered web hosting. Once mirrored on services like unpkg, an ordinary HTML file inside the package becomes a fully-rendered fake Cloudflare CAPTCHA page, served from a domain that email and web filters generally treat as safe. When Google's Safe Browsing blocked the first typosquatted destination the page redirected to, the operators switched to using a public key-value store as a "dead drop resolver", updating where victims land without touching the npm packages again. The lesson is the same one behind most CDN-abuse campaigns: a filter that trusts a domain, rather than inspecting what's actually being served from it, is a blind spot by construction. Any UK organisation that allowlists unpkg or similar mirrors in its web or email security stack has inherited that blind spot too.
Your cloud provider's defaults are a security decision, not just yours. Intruder's 2026 Cloud Security Index, drawn from anonymised data across 3,000 organisations, found that 76% of AWS accounts have at least one publicly exposed service, against 64% on Azure and just 8% on Google Cloud. Weak identity controls and missing logging were near-universal regardless of provider. The gap in exposed services is largely a function of what each platform makes easy or hard to get wrong out of the box. Choosing a cloud provider is, in part, choosing how expensive your own team's mistakes are allowed to be.
Sources
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
- CISA Warns of Exploited Oracle WebLogic Vulnerability
- U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
- Weak IAM affects up to 98% of cloud environments
Working through what any of this means for your own systems? Get in touch.
More like this
- The Check Point VPN flaws that haven't been exploited yet 14 september 2026
- The bill comes due for the SSO flaw that hit 138 companies 13 september 2026
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.