Skip to content
Critical Vulnerability in Oracle Products

Critical Vulnerability in Oracle Products

Csa.Sg January 22, 2026

Oracle has released security updates to address a critical vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in. Users and administrators of affected products are advised to update the affected products to the latest version immediately.

Oracle has released security updates to address a critical vulnerability (CVE-2026-21962) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10 out of 10.

Successful exploitation of the vulnerability could allow an unauthenticated attacker with HTTP network access to gain access to data or have full access to the vulnerable product, potentially enabling the attacker to create, delete or modify sensitive data.

The vulnerability affects the following product versions:

Oracle HTTP Server version 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0

Oracle WebLogic Server Proxy Plug-in version 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0

Oracle WebLogic Server Proxy Plug-in for IIS version 12.2.1.4.0

Users and administrators of affected products are advised to update the affected products to the latest version immediately.