THREAT OPS › Threat News › [CISA KEV] CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
[CISA KEV] CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
CVE: CVE-2026-21962 Vendor: Oracle Product: HTTP Server and Oracle Weblogic Server Proxy Plug-in Vulnerability: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability Date Added: 2026-08-24 Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations a
MITRE ATT&CK techniques
- Cloud ServicesT1021.007
Indicators of compromise
- CVE-2026-21962cve
- https://www.oracle.com/security-alerts/cpujan2026.htmlurl
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21962