The WebLogic Server Proxy Plug-in is a component within Oracle WebLogic Server that provides proxy functionality to route requests to backend WebLogic services.
Overview
The WebLogic Server Proxy Plug-in is a component within Oracle WebLogic Server that provides proxy functionality to route requests to backend WebLogic services. It has gained attention due to a recent critical vulnerability affecting Oracle products, including this plug-in, which could enable remote code execution or other severe impacts if exploited. This makes timely patching, configuration hardening, and traffic monitoring essential for affected Oracle deployments.
Related Threat Clusters
-
Critical Vulnerabilities in Oracle Coherence and Access Manager Disclosed
Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially…
10 articles · Updated July 23, 2026 -
Critical Vulnerability in Oracle HTTP Server and WebLogic Server
A critical vulnerability (CVE-2026-21962) has been identified in Oracle HTTP Server and WebLogic Server Proxy Plug-in, allowing unauthenticated attackers to create, delete, or modify critical data. Oracle has released…
2 articles · Updated January 22, 2026
Recent Intelligence Reports
- Oracle July 2026 CPU: pre-auth 10.0 RCE in WebLogic + more Suriq / 1d Strip it down to the software people actually self-host, and a much smaller set demands attention this week, a cluster of flaws an unauthenticated attacker can trigger over the network for full remote code execution, several scored a perfect CVSS 10.0. Any WebLogic Server, Oracle HTTP Server or Coherence instance reachable from the internet or an untrusted network, patched first, since these carry the unauthenticated 10.0 and — suriq.io · July 23, 2026
- CC-4739 — Digital.Nhs.Uk · January 22, 2026
- Critical Vulnerability in Oracle Products — Csa.Sg · January 22, 2026