Successful exploitation could allow an unauthenticated attacker with HTTP network access to create, delete, or modify critical data accessible through the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in
Successful exploitation could allow an unauthenticated attacker with HTTP network access to create, delete, or modify critical data accessible through the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in
The following platforms are known to be affected:
Oracle Weblogic Server Proxy Plug-in
Weblogic Server Proxy Plug-in for Apache HTTP Server Component
Weblogic Server Proxy Plug-in for IIS Component
Proof-of-Concept Exploit for CVE-2026-21962
A proof-of-concept exploit for CVE-2026-21962 is publicly available. The NHS England National CSOC assesses exploitation as highly likely.
Oracle has published a security advisory addressing a critical a vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in within Oracle Fusion Middleware. Successful exploitation of CVE-2026-21962 could allow an unauthenticated attacker with HTTP network access to create, delete, or modify critical data accessible through the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in.
Both Weblogic Server Proxy Plug-in for Apache HTTP Server and Weblogic Server Proxy Plug-in for IIS components are affected by the vulnerability.
Affected organisations are strongly advised to review Oracle's Critical Patch Update Advisory and apply the relevant updates as soon as possible.
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Last edited: 22 January 2026 4:26 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
