CVE-2026-21962

Published Jan 20, 2026

Last updated 12 days ago

Exploit knownCVSS critical 10.0
Cloud
Network
Zero-day
ICS
Business logic
Supply chain
Server
HTTP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-21962 is a recently disclosed vulnerability impacting Oracle Fusion Middleware, specifically affecting Oracle HTTP Server and the WebLogic Server Proxy Plug-ins. This flaw, identified as a heap-based buffer overflow or an improper access control vulnerability, allows an unauthenticated remote attacker to compromise affected systems. The vulnerability can be exploited by sending specially crafted HTTP requests to the exposed server, enabling unauthorized creation, deletion, or modification of critical data accessible through the Oracle HTTP Server and WebLogic Server Proxy Plug-in. Oracle has released patches to address this issue.

Description
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Source
secalert_us@oracle.com
NVD status
Analyzed
Products
http_server, weblogic_server_proxy_plug-in

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
5.8
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Exploit added on
Aug 24, 2026
Exploit action due
Aug 27, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-284

Social media

Hype score
Not currently trending
  1. 🚨 Patch Now | August 31, 2026 Bringing these patches to your attention. - cPanel (CVE-2026-65643) - Oracle WebLogic (CVE-2026-21962, CVSS 10.0) - Avada WordPress Theme (CVE-2026-18431, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/R87BUwfN5r

    @CERT_UG

    31 Aug 2026

    100 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Oracle WebLogic has a maximum severity flaw attackers are exploiting now. CVE-2026-21962 allows unauthenticated HTTP access to critical data: - CISA added it to its known exploited catalog - Federal agencies have until August 27 to patch https://t.co/jBVsFqS0KA

    @so_sthbryan

    29 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2026-21962 — Oracle WebLogic / HTTP Server Critical Vulnerability Oracle fixed the flaw in its January 2026 Critical Patch Update. Unpatched Internet-facing systems should be treated as high priority. https://t.co/f2ftyfiHEY #CVE #CVE202621962 #Oracle #WebLogic http

    @stem__shop

    26 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【緊急】Oracle HTTP Server / WebLogic Proxy Plug-in に深刻な脆弱性(CVE-2026-21962 / CVSS 3.1 10.0) 未認証でデータの窃取・改ざんが可能。CISAが8/24にKEV追加、是正期限は8/27。 対処: 2026年1月のOracle CPUを適用済みか確認する

    @ForsmileDNet

    26 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA Adds Oracle Plug-in Access Control Bug CVE-2026-21962 to KEV Catalog — CISA has added CVE-2026-21962, an improper access control vulnerability in… https://t.co/vweZ6BI5gA #Cybersecurity #SecOps #VulnerabilityManagement

    @VettedSecOps

    26 Aug 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Oracle WebLogic'te CVSS 10.0 Açık Aktif İstismar Ediliyor CVE-2026-21962 kodlu kritik açık CISA'nın KEV kataloğuna eklendi. Kimlik doğrulaması gerektirmeyen saldırganlar, HTTP üzerinden sisteme erişerek kritik verilere ulaşabiliyor. #CVE #SiberGüvenlik https:

    @KubbeSiber

    25 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2026-21962: Oracle HTTP Server and WebLogic Proxy Plug-in Exploited in the … "On August 24, 2026, CISA added CVE-2026-21962 — an improper access control vulnerability…" 🔗 https://t.co/6wsqQPwCl1 #CyberSecurity #ThreatIntel #critical #zeroday #

    @SecurityAr58409

    25 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔒 #CyberSecurity CVE-2026-21962: Oracle HTTP Server & WebLogic Proxy Plug-in Improper Access Con… "On August 24, 2026, CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/LsWCYlIVv1 #CyberSecurity #ThreatIntel #cve202621962 #critica

    @SecurityAr58409

    25 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-24 CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control… CVSS 10 · EPSS 43.2% · 12 public exploits Details, versions & intel → https://t.co/5GaFss12Ke https://t.co/

    @notCVE

    25 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ CVE-2026-21962: Vulnerabilidad Crítica CVSS 10.0 en Oracle HTTP Server y WebLogic Server Proxy Plug-in Análisis técnico de CVE-2026-21962, vulnerabilidad crítica de control de acceso en Oracle HTTP Server y WebLogic. CVSS 10.0, explotación activa confirmada.

    @CiberPlanetaOrg

    24 Aug 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Cisco SD-WAN (CVE-2026-20245) & Unified CM (CVE-2026-20230) actively exploited. Windows DNS Client RCE (CVE-2026-41096) & Oracle WebLogic Proxy (CVE-2026-21962) pose critical risks. Data privacy & integrity in transit are at stake. #Cybersecurity #News

    @YourAnon_irc

    5 Jun 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Exploitation infrastructure observed scanning for: CVE-2025-55182(React2shell) CVE-2026-21962(Oracle Weblogic) CVE-2025-31324(SAP NetWeaver) - actively exploited by China-linked APTs Targeting India-based critical infrastructure SAP exploit script "MADE BY SCATTERED LAPSUS$ ht

    @SansLimit3

    19 Mar 2026

    4038 Impressions

    7 Retweets

    48 Likes

    23 Bookmarks

    1 Reply

    1 Quote

  13. Top 5 Trending CVEs: 1 - CVE-2025-62186 2 - CVE-2023-28206 3 - CVE-2026-21962 4 - CVE-2026-24061 5 - CVE-2026-23760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Jan 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Top 5 Trending CVEs: 1 - CVE-2025-54957 2 - CVE-2026-21962 3 - CVE-2025-43529 4 - CVE-2026-0629 5 - CVE-2017-9506 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 Jan 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. ow ow ow, 2in1 bundle from Oracle 🟥 CVE-2026-21962, CVSS: 10.0 (Critical) Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in 🟥 CVE-2025-66516, CVSS: 10.0 (Critical) Apache Tika Oracle HTTP Server vulnerability allows unauthenticated attackers to compromise the serv

    @UjlakiMarci

    21 Jan 2026

    319 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations