CVE-2026-21962 – Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in

CVSS 10 CRITICAL Zero Day – Immediate Deployment

“A maximum-severity, actively exploited flaw can expose or alter critical data through unauthenticated HTTP access.”

Oracle addresses a Critical vulnerability in the WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. CVE-2026-21962 allows an unauthenticated remote attacker with HTTP access to compromise affected Oracle HTTP Server and WebLogic Server Proxy Plug-in deployments. Successful exploitation can provide unauthorized access to critical data and allow creation, deletion, or modification of protected information. The CVSS score is 10.0, which is Critical severity.

Active exploitation is confirmed. Affected versions include 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, with the IIS plug-in affected at 12.2.1.4.0. Oracle addressed the issue in its January 2026 Critical Patch Update.

Key Details

Affected Product
Oracle Http Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.