A critical vulnerability, CVE-2026-21962, affecting Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in was detected today, risking unauthorized access to sensitive data. Assigned a maximum CVSS score of 10.0, this flaw is actively exploited in the wild. It allows unauthenticated attackers to modify or delete crucial server information through improper access control.
The affected versions include 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, necessitating immediate patching by federal agencies and enterprise administrators. Oracle has released fixes, and CISA mandates remediation by August 27, 2026.