Oracle HTTP Server — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
January 21, 2026
Last Seen
July 23, 2026

Oracle HTTP Server is a technology platform tracked across 5 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed January 21, 2026; most recent activity July 23, 2026.

Overview

Oracle HTTP Server (OHS) is Oracle’s web server offering built on the Apache HTTP Server stack with Oracle-specific modules, used to deliver Oracle Fusion Middleware, E-Business Suite, and other Oracle applications. In cybersecurity, it represents a web-facing surface whose security posture depends on timely patching of OHS and underlying components (e.g., Apache Tika), as evidenced by recent critical vulnerabilities and large patch releases affecting Oracle products.

Related Threat Clusters

Recent Intelligence Reports

  • Oracle July 2026 CPU: pre-auth 10.0 RCE in WebLogic + more Suriq / 1d Strip it down to the software people actually self-host, and a much smaller set demands attention this week, a cluster of flaws an unauthenticated attacker can trigger over the network for full remote code execution, several scored a perfect CVSS 10.0. Any WebLogic Server, Oracle HTTP Server or Coherence instance reachable from the internet or an untrusted network, patched first, since these carry the unauthenticated 10.0 and — suriq.io · July 23, 2026
  • Cyber alerts — Digital.Nhs.Uk · January 31, 2026
  • CVE-2026-21962 — Arcticwolf · January 23, 2026
  • CC-4739 — Digital.Nhs.Uk · January 22, 2026
  • Critical Vulnerability in Oracle Products — Csa.Sg · January 22, 2026
  • Oracle releases 337 security patches, including fix for critical Apache Tika flaw — Csoonline · January 21, 2026

CVSS v3.1 Breakdown