The US Cybersecurity and Infrastructure Security Agency (CISA) warns of attacks targeting a vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, which can allow attackers to fully compromise instances. Updates have been available since Oracle’s Critical Patch Update (CPU) in January of this year.
In its alert, CISA provides no further details on the observed attacks. However, it is a vulnerability that attackers can easily exploit from the network without prior authentication to fully compromise vulnerable versions of the Oracle software Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Attacks on other products may also be possible ( CVE-2026-21962 , CVSS 10.0 , Risk “ critical ”).
The reporters of the vulnerability provide more information on GitHub what the gap is. According to them, it is a path traversal vulnerability that allows privilege escalation and the execution of injected code. The error lies in the mechanisms for normalizing URIs. This allows attackers to bypass security mechanisms with carefully manipulated URIs. Proof-of-concept code is also available in the repository.
Updated software has been available since January to close the security vulnerability. IT managers should apply the updates at least now to reduce the attack surface. If the Oracle systems are accessible from the network, they should also be considered compromised and treated accordingly. Since CISA provides no further information on the attacks, unfortunately, no helpful indicators of compromise (IOCs) are available.
Most recently, attacks on Oracle’s WebLogic servers were reported in June of this year . Malicious actors targeted a vulnerability that had been known since mid-2024.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
