CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change).
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline for federal agencies: 2026-08-27.
10 articles across 8 outlets · first covered Aug 24, 2026 · latest Aug 31, 2026
Coverage timeline
-
Weekly CVE Report: 11 Exploited Flaws Added to KEVsecurityonline.info · Aug 31, 2026
-
CISA flags Oracle flaw CVE-2026-21962, orders patch by Aug 27securityaffairs.com · Aug 25, 2026
-
Clop uses Oracle CVE-2026-21962 to hit PTC Windchill credentialssecurityonline.info · Aug 25, 2026
-
CISA urges patch of critical Oracle WebLogic flaw CVE-2026-21962www.securityweek.com · Aug 25, 2026
-
Oracle Flaw CVE-2026-21962 Lets Attackers Access Critical Datasecurityonline.info · Aug 25, 2026
-
CISA Adds Oracle HTTP Server Flaw CVE-2026-21962 to KEV Catalogwww.cisa.gov · Aug 25, 2026
-
CISA warns of critical Oracle HTTP Server flaw, urges patchcisa.gov · Aug 24, 2026
-
Attackers Rapidly Weaponize Critical Oracle WebLogic RCE, Honeypot Study Findswww.infosecurity-magazine.com · Mar 26, 2026
-
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructurethehackernews.com · Feb 12, 2026
-
Oracle January 2026 CPU Delivers 337 Security Patches Including CVE-2025-66516 & CVE-2026-21962socradar.io · Jan 22, 2026