THREAT OPS › Threat News › [NVD] CVE-2026-21962 (CRITICAL 10.0) — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1
[NVD] CVE-2026-21962 (CRITICAL 10.0) — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1
CVE-2026-21962 CVSS: 10.0 CRITICAL Published: 2026-01-20T22:15:59.110
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerab
Indicators of compromise
- CVE-2026-21962cve
- 12.2.1.4ipv4
- 14.1.1.0ipv4
- 14.1.2.0ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21962