THREAT OPS › CVEs › CVE-2026-21962
CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Vulnerability details
- Affected productsHTTP Server and Oracle Weblogic Server Proxy Plug-in
- KEV remediation due2026-08-27
Related reporting
- August 2026 CVE Landscaperecordedfuture
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Datathehackernews
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [NVD] CVE-2026-21962 (CRITICAL 10.0) — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1nvd
- Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2cccs_ca
- [CISA KEV] CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabilitycisa_kev