Oracle WebLogic Proxy Plug-in exploited, CVSS 10 (CVE-2026-21962)
CVE-2026-21962
CVE-2026-21962: Oracle WebLogic Proxy Plug-in 12.2.1.4, 14.1.1, 14.1.2 RCE/unauth data compromise, CVSS 10. Actively exploited. Update to patched versions per Oracle's January CPU.
Actively exploited in the wild - CVE-2026-21962 is a critical unauthenticated compromise of Oracle HTTP Server and WebLogic Server Proxy Plug-in 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 that grants attackers full read and write access to all accessible data. Oracle has released patches in the January 2026 Critical Patch Update; apply immediately.
Overview
CVE-2026-21962 affects the WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS, integral components of Oracle Fusion Middleware that route traffic between web servers and WebLogic backends. The flaw requires no authentication and no user interaction, and it is exploitable remotely over HTTP with low attack complexity.
The vulnerability carries the maximum CVSS 3.1 score of 10.0. Its scope is changed, meaning a successful attack can compromise systems beyond the proxy plug-in itself. Attackers can achieve both unauthorized creation, deletion, or modification of critical data and complete unauthorized access to all application data flowing through the affected proxy components.
While the plug-in is also supported on IIS, Oracle notes that only version 12.2.1.4.0 is affected in the IIS deployment. Apache HTTP Server deployments are affected across all three supported versions.
CISA has confirmed this vulnerability is actively exploited in the wild and has added it to the Known Exploited Vulnerabilities catalog. The EPSS model estimates a 43.2 percent probability of exploitation within the next 30 days, indicating widespread attacker interest.
Affected Products
- Oracle HTTP Server: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
- Oracle WebLogic Server Proxy Plug-in for Apache: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
- Oracle WebLogic Server Proxy Plug-in for IIS: 12.2.1.4.0 only
Remediation
Oracle addressed this vulnerability in the January 2026 Critical Patch Update. Administrators should apply the relevant patches for their exact version and platform component immediately. Given active exploitation and the unauthenticated, network-based attack vector, treat this as a priority incident response item rather than routine maintenance.
For environments where immediate patching is not feasible, restrict network access to the affected proxy plug-in ports and monitor for anomalous HTTP traffic. Review WebLogic proxy logs for unauthorized data access patterns. This vulnerability follows a pattern of critical WebLogic proxy flaws; see Oracle WebLogic CVE-2024-21182 exploited in the wild for related activity.
Security Insight
Oracle Fusion Middleware proxy components are becoming a preferred initial access vector because they sit unprotected at the network perimeter while holding privileged connections to backend application servers. The CVSS 10.0 score combined with confirmed in-the-wild exploitation signals that attackers are weaponizing these edge components faster than organizations are patching them. This mirrors the recent Apache ActiveMQ CVE-2026-34197 added to CISA KEV amid active exploitation, reinforcing that proxy and middleware layers deserve the same patching urgency as core application servers.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution....
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network....
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers...
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network....