{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/weblogic-server-proxy-plug-in/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:http_server:14.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.2.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-21962"}],"_cs_exploited":true,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["Oracle HTTP Server","Oracle Weblogic Server","HTTP Server","Weblogic Server Proxy Plug-in","Oracle Weblogic Server Proxy Plug-in"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Oracle"],"content_html":"\u003cp\u003eCISA has formally added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation. The vulnerability affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It is classified as an improper access control vulnerability. Successful exploitation of this vulnerability in proxy components can allow attackers to bypass security restrictions, potentially leading to unauthorized access to downstream application resources or total control of the affected asset. Given the critical position of proxy and load-balancing components in enterprise architectures, this vulnerability represents a significant risk for lateral movement and unauthorized information disclosure. Organizations are advised to prioritize patching according to Binding Operational Directive (BOD) 26-04 requirements.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or unauthorized attackers to manipulate requests passing through the Oracle HTTP Server or WebLogic Proxy Plug-in. This can lead to the exposure of sensitive back-end application data, session hijacking, or full remote code execution if combined with other backend weaknesses. The vulnerability is confirmed to be under active exploitation in the wild, necessitating immediate remediation on all internet-facing Oracle infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize the application of security patches for CVE-2026-21962 on all internet-facing Oracle HTTP Server and Oracle WebLogic Server instances.\u003c/li\u003e\n\u003cli\u003eAudit web access logs for anomalous request patterns targeting the WebLogic Proxy Plug-in (e.g., suspicious URI manipulation or unexpected headers).\u003c/li\u003e\n\u003cli\u003eEnforce strict access control policies for the management interfaces of Oracle WebLogic environments.\u003c/li\u003e\n\u003cli\u003eConduct a review of system logs to determine if unauthorized access occurred prior to patch implementation, as outlined in the requirements of BOD 26-04.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T21:55:14Z","date_published":"2026-08-24T19:53:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-oracle-kev-addition/","summary":"CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog due to confirmed in-the-wild exploitation of an improper access control vulnerability in Oracle HTTP and WebLogic proxy components.","title":"Active Exploitation of Oracle HTTP Server and WebLogic Server Proxy Plug-in","url":"https://feed.craftedsignal.io/briefs/2026-08-oracle-kev-addition/"}],"language":"en","title":"CraftedSignal Threat Feed - Weblogic Server Proxy Plug-In","version":"https://jsonfeed.org/version/1.1"}