Critical Vulnerability in Oracle HTTP Server Under Active Exploitation

Critical Vulnerability in Oracle HTTP Server Under Active Exploitation

First seen 25 Aug 2026, 07:20 UTC Heise.Denvd.nist.govgithub.com 80.0

Article Content

Browse articles
ThreatCluster

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active attacks exploiting a critical vulnerability (CVE-2026-21962) in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in. This vulnerability allows unauthenticated attackers to fully compromise affected systems, specifically versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. The flaw is a path traversal vulnerability that enables privilege escalation and code execution through manipulated URIs. Although updates were released in January 2026, many systems remain unpatched. CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 24, 2026, indicating confirmed exploitation in the wild. No specific indicators of compromise (IOCs) have been provided, complicating detection efforts. IT managers are urged to apply the available updates immediately to mitigate risks.

Key Points: • CISA warns of active exploitation of CVE-2026-21962 in Oracle software. • Affected versions include Oracle HTTP Server and Weblogic Server Proxy Plug-in. • Updates to patch the vulnerability have been available since January 2026.

Timeline

2026-01-20
CVE-2026-21962 published
Oracle disclosed a critical path traversal vulnerability affecting Oracle HTTP Server and Weblogic Server Proxy Plug-in.
nvd.nist.gov
2026-01-22
First public PoC released
Proof-of-concept code for exploiting CVE-2026-21962 was made publicly available on GitHub.
Heise.De
2026-08-24
CVE added to CISA KEV
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, confirming active exploitation.
nvd.nist.gov
Recent
CISA issues warning
CISA warns of ongoing attacks exploiting the vulnerability, urging immediate patching of affected systems.
Heise.De