LiveActive security incident?Get immediate response
CVE Record

CVE-2026-21962: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Midd...

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

CriticalCVSS 10Known exploitedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

This critical Oracle middleware flaw can let an unauthenticated network attacker read, create, delete, or alter critical data through exposed HTTP services. Because exploitation is listed in CISA’s Known Exploited Vulnerabilities catalog, affected internet-facing systems should be treated as potentially targeted and investigated promptly.

Executive priority

Treat this as an emergency remediation and compromise-assessment item. Active-exploitation status, unauthenticated network reachability, and potential complete data exposure or modification justify immediate ownership, exposure reduction, patch verification, and incident-response review. Business systems relying on these middleware components may require coordinated maintenance.

Technical view

CVE-2026-21962 is an access-control vulnerability (CWE-284) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-ins. It is remotely exploitable over HTTP without credentials or user interaction. CVSS 3.1 is 10.0, with high confidentiality and integrity impact, no stated availability impact, and possible impact beyond the vulnerable component because scope changes.

Likely exposure

Exposure is highest where affected Oracle HTTP Server or WebLogic proxy plug-ins accept HTTP traffic from untrusted networks. Affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. Internal deployments remain exposed to attackers with network reachability.

Exploitation context

CISA KEV status supports active exploitation in the wild. The supplied evidence does not establish exploitation volume, targeted sectors, indicators of compromise, or a reliable public exploit. Public social-media and GitHub references exist, but their technical claims are not substantiated within the provided bundle.

Researcher notes

The vendor assigns CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. The provided material identifies improper authorization but does not describe the vulnerable request path, root cause, indicators, patch identifiers, or exploitation mechanics. Do not infer availability impact from the 10.0 score; the supplied vector specifies A:N.

Mitigation direction

  • Follow Oracle’s January 2026 advisory and apply the applicable vendor update for each affected deployment.
  • Prioritize internet-facing and externally reachable HTTP endpoints for emergency remediation.
  • Restrict untrusted network access to vulnerable services until vendor remediation is verified.
  • Assess connected applications and data stores because successful attacks may cross component boundaries.

Validation and detection

  • Inventory Oracle HTTP Server and WebLogic proxy plug-in installations, including exact versions and web-server type.
  • Confirm whether affected HTTP endpoints are reachable from internet or other untrusted networks.
  • Verify the applicable Oracle January 2026 update is installed using authoritative patch records.
  • Review HTTP, authentication, and data-change telemetry for unexplained unauthenticated activity or integrity changes.
  • Investigate downstream systems accessible through the affected proxy because the vulnerability has changed scope.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-21962 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
10 (3.1)
Known Exploited
Yes
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
1ADP providers
6Source links

CISA KEV status

Status
Known exploited
Source
CISA-ADP
Date added
KEV reference

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: activeAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
10CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N3.95.8oracle

Vulnerability scoring details

Base CVSS 3.1 score

10Critical
CVSS 3.1 vector shape for CVE-2026-21962Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. Added to KEVCISA-ADP

    CISA Known Exploited Vulnerabilities metadata lists this CVE as known exploited.

  4. ADP timelineCISA-ADP

    CVE-2026-21962 added to CISA KEV

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvcother:kev
  • 2026-08-24T00:00:00.000Z: CVE-2026-21962 added to CISA KEV
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationOracle HTTP Server, Oracle Weblogic Server Proxy Plug-in12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.