CISA_KEV · AUGUST 2026 · CONFIRMED

Critical Oracle HTTP and WebLogic Servers Vulnerability Exploited

Severity
HIGH
Affected component
oracle http server (other)
Patched version
Not yet available
CVE-2026-21962

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized access to critical data. This vulnerability is actively exploited in the wild.

What happened

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in have an improper access control vulnerability tracked as CVE-2026-21962. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the servers. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data as well as unauthorized access to all accessible data.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. While patches were released by Oracle earlier this year, exploitation efforts have been observed by multiple sources.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If oracle http server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in. No authoritative version range has been published yet.

What should I do right now?

Upgrade to the latest version of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Monitor your networks for unusual activity.

Has this been exploited in the wild?

Yes, this vulnerability is actively exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats