Critical Oracle HTTP and WebLogic Servers Vulnerability Exploited
- Severity
- HIGH
- Affected component
- oracle http server (other)
- Patched version
- Not yet available
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized access to critical data. This vulnerability is actively exploited in the wild.
What happened
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in have an improper access control vulnerability tracked as CVE-2026-21962. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the servers. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data as well as unauthorized access to all accessible data.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. While patches were released by Oracle earlier this year, exploitation efforts have been observed by multiple sources.
What to do about it
- Upgrade to the latest version of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to mitigate the improper access control vulnerability.
- Monitor networks for unusual activity that may indicate exploitation of this vulnerability.
- Consult the primary sources for updates on the vulnerability and any official fixes.
How 0Day would have caught this
oracle http server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using Oracle HTTP Server or Oracle WebLogic Server Proxy Plug-in. No authoritative version range has been published yet.
What should I do right now?
Upgrade to the latest version of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Monitor your networks for unusual activity.
Has this been exploited in the wild?
Yes, this vulnerability is actively exploited in the wild.