The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies to patch a maximum-severity Oracle vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug-in within three days after adding the flaw, tracked as CVE-2026-21962, to its Known Exploited Vulnerabilities catalog on August 24, 2026.[1][4][8][9] The move follows evidence that attackers are already exploiting the issue in the wild and reflects CISA’s strictest remediation timeline for actively exploited, internet-facing weaknesses.[4][8][9]
CVE-2026-21962 is an improper access control vulnerability in Oracle Fusion Middleware that affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in components used to front-end WebLogic application servers.[1][2][3][7] Oracle and the US National Vulnerability Database describe it as an easily exploitable flaw that allows an unauthenticated attacker with network access over HTTP to compromise the affected products, earning it a CVSS v3.1 score of 10.0.[1][2][11][12] Successful exploitation can let an attacker create, delete, or modify any data accessible to the web tier, effectively granting complete control over applications and sensitive information behind the proxy.[1][3][5][11] Security advisories note that impacted supported versions include Oracle HTTP Server and its WebLogic proxy modules in releases 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, as well as the WebLogic Server Proxy Plug-in for Microsoft IIS in version 12.2.1.4.0.[1][2][3][5][7][10]
Oracle addressed CVE-2026-21962 in its January 20, 2026 Critical Patch Update, which shipped fixes for hundreds of vulnerabilities across its product line.[3][7][12] Both national and sectoral cybersecurity authorities, including the Canadian Centre for Cyber Security and the French health-sector CERT, urged organizations at the time to apply the January 2026 patches to Oracle HTTP Server and the WebLogic proxy plug-ins to prevent unauthorized access to critical systems.[5][7] Oracle and multiple security firms stressed that the vulnerability could be exploited remotely without authentication and with low attack complexity, making timely patching essential for any deployment that exposes Oracle HTTP Server or WebLogic proxy endpoints to the internet.[1][2][3][6][11] Within weeks of disclosure, security researchers documented public proof-of-concept exploit code and technical analyses showing how crafted HTTP requests could abuse the plug-in’s request handling to bypass access controls.[2][6][14]
As 2026 progressed, threat intelligence teams and incident responders began reporting real-world exploitation attempts against Oracle HTTP Server and WebLogic proxy deployments using this bug, particularly in environments where the proxy is deployed at the edge to front-end business-critical applications.[3][4][6][9] Analyses from multiple vendors describe unauthenticated attackers sending specially crafted HTTP requests to gain permissions equivalent to the plug-in itself, often under default or near-default configurations.[1][3][6] Observed attack activity has included broad, automated scanning of internet-exposed endpoints and opportunistic exploitation consistent with “spray and pray” campaigns targeting a mix of legacy and modern WebLogic-related vulnerabilities.[4][6][9] CISA’s decision to move CVE-2026-21962 into the Known Exploited Vulnerabilities catalog formalizes that this is no longer a theoretical risk but a live threat to government and enterprise networks.[4][8][9]
Under CISA’s updated directives governing KEV-listed flaws, a three-day remediation window is reserved for the highest-risk entries, combining rapid patching with required forensic triage to determine whether affected assets have already been compromised.[8] The same three-day timeline has recently been applied to other high-impact, widely exploitable issues, including a critical remote code execution vulnerability in the Ray distributed computing framework tracked as CVE-2025-62593.[13] By placing CVE-2026-21962 in this category, CISA is signalling that Oracle HTTP Server and WebLogic proxy deployments represent prime targets for attackers due to their frequent placement at network perimeters and their ability to broker access to downstream application servers and data stores.[2][3][6][8]
Organizations running Oracle HTTP Server or WebLogic Server Proxy Plug-in components should immediately inventory where these modules are deployed—especially in front of internet-exposed applications—and verify whether they are running an affected version.[1][2][3][5][7] Where possible, administrators should apply the January 2026 Critical Patch Update or later cumulative updates that include the fix for CVE-2026-21962, prioritizing systems that serve as front doors to sensitive applications or data.[3][5][7][12] For environments that cannot be patched quickly, security guidance recommends disabling or removing vulnerable proxy plug-ins where feasible, restricting access to the proxy via network controls or VPN, and deploying additional monitoring around HTTP traffic to detect suspicious requests.[3][4][6][7] Given CISA’s classification of the flaw as actively exploited, defenders should also conduct log reviews and forensic checks on affected servers to look for signs of compromise, treating unpatched or recently patched systems as potentially breached until proven otherwise.[4][8]
References
- CVE-2026-21962 Detail – NVD – NIST
- Oracle WebLogic Server Proxy Plugin (CVE-2026-21962) – NetSPI
- CVE-2026-21962 – Arctic Wolf
- CVE-2026-21962: Oracle HTTP Server and WebLogic …
- Oracle Corporation – CVE-2026-21962
- Authentication Bypass in Oracle WebLogic Server Proxy Plug-in …
- Oracle security advisory – January 2026 quarterly rollup (AV26-042)
- CISA KEV Deadlines Have Fallen From 21 Days to Three
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
- Oracle WebLogic is under active attack – and most teams …
- [PDF] CYBER ADVISORY
- Oracle January 2026 CPU Delivers 337 Security Patches Including CVE …
- CISA Adds Ray RCE Flaw CVE-2025-62593 to KEV, 3-Day Deadline
- CVE-2026-21962-Oracle-HTTP-Server-WebLogic-Proxy-Plug-in …
