Digital.Nhs.Uk
Critical Vulnerability in Oracle HTTP Server and WebLogic Server
First seen 22 Jan 2026, 21:42 UTC
•
•45.3
Export
Article Content
Browse articles
A critical vulnerability (CVE-2026-21962) has been identified in Oracle HTTP Server and WebLogic Server Proxy Plug-in, allowing unauthenticated attackers to create, delete, or modify critical data. Oracle has released security updates to address this vulnerability, which has a CVSS v3.1 score of 10. Users and administrators are urged to update their systems immediately.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
Date unknown
Vulnerability discovered
Recent
Exploit released
Date unknown
Patch released
More articles in this cluster
Continue Reading
Clop Hackers Exploit Oracle Zero-Day, Breaching Barts Health NHS and Dartmouth Data
Data Breach at University of Phoenix Due to Oracle EBS Zero-Day Exploit
Logitech Confirms Data Breach from Zero-Day Exploit by Clop Gang
Critical Oracle WebLogic Flaw Under Active Exploitation
Operation Escaneo Targets Latin American Critical Infrastructure
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015