WebLogic Server Proxy Plug-in — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 22, 2026
Last Seen
July 23, 2026

The WebLogic Server Proxy Plug-in is a component within Oracle WebLogic Server that provides proxy functionality to route requests to backend WebLogic services.

Overview

The WebLogic Server Proxy Plug-in is a component within Oracle WebLogic Server that provides proxy functionality to route requests to backend WebLogic services. It has gained attention due to a recent critical vulnerability affecting Oracle products, including this plug-in, which could enable remote code execution or other severe impacts if exploited. This makes timely patching, configuration hardening, and traffic monitoring essential for affected Oracle deployments.

Related Threat Clusters

Recent Intelligence Reports

  • Oracle July 2026 CPU: pre-auth 10.0 RCE in WebLogic + more Suriq / 1d Strip it down to the software people actually self-host, and a much smaller set demands attention this week, a cluster of flaws an unauthenticated attacker can trigger over the network for full remote code execution, several scored a perfect CVSS 10.0. Any WebLogic Server, Oracle HTTP Server or Coherence instance reachable from the internet or an untrusted network, patched first, since these carry the unauthenticated 10.0 and — suriq.io · July 23, 2026
  • CC-4739 — Digital.Nhs.Uk · January 22, 2026
  • Critical Vulnerability in Oracle Products — Csa.Sg · January 22, 2026

CVSS v3.1 Breakdown