CISA added a critical vulnerability to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. This CVE-2026-21962 Oracle flaw carries a maximum CVSS score of 10.0 and allows unauthenticated attackers to access sensitive data. Therefore, federal agencies and enterprise administrators must apply vendor security patches immediately.
- CVE: CVE-2026-21962
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
- Affected: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
- Impact: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle...
- Status: Exploited in the wild
- EPSS: 43.2% (30-day)
- Action: See vendor advisory
Why This Vulnerability Matters
This flaw represents an extreme risk to enterprise environments. Unauthenticated remote threat actors can exploit this weakness over standard HTTP connections. Furthermore, a successful attack enables unauthorized creation, modification, or deletion of critical server data. The flaw also allows scope changes, which means attackers can compromise additional interconnected systems. Because adversaries actively target this vector in the wild, unpatched servers face imminent compromise.
How the Attack Works
The security issue stems from improper access control within the WebLogic Server Proxy Plug-in. Attackers craft malicious HTTP requests directed at the web server endpoint. Consequently, the proxy component fails to enforce proper authorization checks. This failure allows remote attackers to bypass access barriers without providing any login credentials.
Affected Versions
The vulnerability affects Oracle Fusion Middleware components, specifically the WebLogic Server Proxy Plug-in for Apache and IIS. Affected software releases include versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. However, the IIS plug-in vulnerability specifically impacts version 12.2.1.4.0. Industry estimates suggest that thousands of enterprise servers utilize these proxy modules globally.
Patch and Mitigation Steps
Oracle released security fixes to resolve this CVE-2026-21962 Oracle flaw across all supported releases. Administrators should apply the official vendor updates immediately to protect exposed endpoints. Additionally, CISA issued a binding directive requiring federal civilian agencies to remediate this issue by August 27, 2026.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!