• Sources: NVD, KEV catalog, Oracle advisory
  • Summary: CVE-2026-21962 is an access-control flaw in the Oracle HTTP Server and WebLogic Proxy Plug-in. CISA lists it as known exploited with a federal remediation deadline of 2026-08-27, and its required action is the generic instruction to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product. NVD gives the affected versions as 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, notes that the WebLogic Server Proxy Plug-in for IIS is affected in 12.2.1.4.0 only, and rates it CVSS 3.1 base 10.0 for an unauthenticated network attack with scope change. Oracle's January 2026 critical patch update is carried on the CVE record as the patch and vendor advisory.
  • Why it matters: The fix shipped in Oracle's January 2026 critical patch update, so the exposed population is proxy plug-ins left unpatched for seven months rather than systems waiting on a vendor, and at CVSS 10.0 the attack needs no credentials.

send feedback on this story