Skip to content
Threat Feed
high threat exploited PoC

Active Exploitation of Oracle HTTP Server and WebLogic Server Proxy Plug-in

CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog due to confirmed in-the-wild exploitation of an improper access control vulnerability in Oracle HTTP and WebLogic proxy components.

CVE search metadata

CVE search record: CVE-2026-21962. Severity: critical. CVSS: 10.0. EPSS: 43.23%. KEV: no. Product: Oracle HTTP Server, Oracle Weblogic Server, HTTP Server, Weblogic Server Proxy Plug-in, Oracle Weblogic Server Proxy Plug-in. Brief: Active Exploitation of Oracle HTTP Server and WebLogic Server Proxy Plug-in. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-kev-addition/

What's new

  • 1. poc_available Aug 24, 21:55 via cccs
  • 2. new product Aug 24, 21:46 via cisa-kev

CISA has formally added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation. The vulnerability affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It is classified as an improper access control vulnerability. Successful exploitation of this vulnerability in proxy components can allow attackers to bypass security restrictions, potentially leading to unauthorized access to downstream application resources or total control of the affected asset. Given the critical position of proxy and load-balancing components in enterprise architectures, this vulnerability represents a significant risk for lateral movement and unauthorized information disclosure. Organizations are advised to prioritize patching according to Binding Operational Directive (BOD) 26-04 requirements.

Impact

Successful exploitation allows unauthenticated or unauthorized attackers to manipulate requests passing through the Oracle HTTP Server or WebLogic Proxy Plug-in. This can lead to the exposure of sensitive back-end application data, session hijacking, or full remote code execution if combined with other backend weaknesses. The vulnerability is confirmed to be under active exploitation in the wild, necessitating immediate remediation on all internet-facing Oracle infrastructure.

Recommendation

  • Prioritize the application of security patches for CVE-2026-21962 on all internet-facing Oracle HTTP Server and Oracle WebLogic Server instances.
  • Audit web access logs for anomalous request patterns targeting the WebLogic Proxy Plug-in (e.g., suspicious URI manipulation or unexpected headers).
  • Enforce strict access control policies for the management interfaces of Oracle WebLogic environments.
  • Conduct a review of system logs to determine if unauthorized access occurred prior to patch implementation, as outlined in the requirements of BOD 26-04.

Immediate actions

Patch Oracle HTTP Server and Oracle Weblogic Server for CVE-2026-21962

IT Operations 24h