Oracle has released security updates to address a critical vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in. Users and administrators of affected products are advised to update the affected products to the latest version immediately.
Oracle has released security updates to address a critical vulnerability (CVE-2026-21962) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10 out of 10.
Successful exploitation of the vulnerability could allow an unauthenticated attacker with HTTP network access to gain access to data or have full access to the vulnerable product, potentially enabling the attacker to create, delete or modify sensitive data.
The vulnerability affects the following product versions:
Oracle HTTP Server version 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0
Oracle WebLogic Server Proxy Plug-in version 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0
Oracle WebLogic Server Proxy Plug-in for IIS version 12.2.1.4.0
Users and administrators of affected products are advised to update the affected products to the latest version immediately.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
