Critical 10.0 Actively Exploited

Oracle WebLogic Proxy Plug-in exploited, CVSS 10 (CVE-2026-21962)

CVE-2026-21962

By Yazoul AI · automated

CVE-2026-21962: Oracle WebLogic Proxy Plug-in 12.2.1.4, 14.1.1, 14.1.2 RCE/unauth data compromise, CVSS 10. Actively exploited. Update to patched versions per Oracle's January CPU.

Affected: Oracle Http Server Oracle Weblogic Server Proxy Plug-In

Actively exploited in the wild - CVE-2026-21962 is a critical unauthenticated compromise of Oracle HTTP Server and WebLogic Server Proxy Plug-in 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 that grants attackers full read and write access to all accessible data. Oracle has released patches in the January 2026 Critical Patch Update; apply immediately.

Overview

CVE-2026-21962 affects the WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS, integral components of Oracle Fusion Middleware that route traffic between web servers and WebLogic backends. The flaw requires no authentication and no user interaction, and it is exploitable remotely over HTTP with low attack complexity.

The vulnerability carries the maximum CVSS 3.1 score of 10.0. Its scope is changed, meaning a successful attack can compromise systems beyond the proxy plug-in itself. Attackers can achieve both unauthorized creation, deletion, or modification of critical data and complete unauthorized access to all application data flowing through the affected proxy components.

While the plug-in is also supported on IIS, Oracle notes that only version 12.2.1.4.0 is affected in the IIS deployment. Apache HTTP Server deployments are affected across all three supported versions.

CISA has confirmed this vulnerability is actively exploited in the wild and has added it to the Known Exploited Vulnerabilities catalog. The EPSS model estimates a 43.2 percent probability of exploitation within the next 30 days, indicating widespread attacker interest.

Affected Products

  • Oracle HTTP Server: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for Apache: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for IIS: 12.2.1.4.0 only

Remediation

Oracle addressed this vulnerability in the January 2026 Critical Patch Update. Administrators should apply the relevant patches for their exact version and platform component immediately. Given active exploitation and the unauthenticated, network-based attack vector, treat this as a priority incident response item rather than routine maintenance.

For environments where immediate patching is not feasible, restrict network access to the affected proxy plug-in ports and monitor for anomalous HTTP traffic. Review WebLogic proxy logs for unauthorized data access patterns. This vulnerability follows a pattern of critical WebLogic proxy flaws; see Oracle WebLogic CVE-2024-21182 exploited in the wild for related activity.

Security Insight

Oracle Fusion Middleware proxy components are becoming a preferred initial access vector because they sit unprotected at the network perimeter while holding privileged connections to backend application servers. The CVSS 10.0 score combined with confirmed in-the-wild exploitation signals that attackers are weaponizing these edge components faster than organizations are patching them. This mirrors the recent Apache ActiveMQ CVE-2026-34197 added to CISA KEV amid active exploitation, reinforcing that proxy and middleware layers deserve the same patching urgency as core application servers.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.