Exploits

Oracle HTTP Server CVE-2026-21962 Under Active Attack

Published  ·  3 min read

CISA just added a critical Oracle flaw to its Known Exploited Vulnerabilities catalog. The bug is being actively exploited right now. If you run Oracle HTTP Server or WebLogic Server, you need to act fast.

The vulnerability is CVE-2026-21962. It has a CVSS score of 10.0, the highest possible. This impacts Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

The exploitation of this vulnerability does not require any user credentials. The only requirement is having access to the server via the network through HTTP protocol.

If you use Oracle WebLogic, then this information is relevant for you. Let me give some explanation here.

Quick Summary

What

Details

Vulnerability

CVE-2026-21962

CVSS Score

10.0 (Maximum)

Affected Products

Oracle HTTP Server, Oracle WebLogic Proxy Plug-in

Impact

Unauthorized access, data modification

Status

Actively exploited

Patch Available

Yes (January 2026)

CISA Deadline

August 27, 2026

What's the Problem?

The CVE-2026-21962 Vulnerability of Oracle HTTP Server is that of improper access. It lets attackers:

  • Create, delete, or modify critical data
  • Access critical data without permission
  • Get complete access to all data

What CISA Said:

"Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data."

Active Exploitation Confirmed

The Oracle HTTP Server CVE-2026-21962 vulnerability has been actively exploited since at least February 2026.

GreyNoise and CloudSEK Reports:

Security firms GreyNoise and CloudSEK confirmed the attacks. One IP address was seen trying to exploit multiple vulnerabilities. CloudSEK also caught exploitation attempts on their honeypot network.

Other WebLogic Flaws Being Targeted:

Attackers aren't just using this one flaw. They're also going after older WebLogic vulnerabilities:

CVE

Description

CVE-2020-14882/14883

Console RCE

CVE-2020-2551

IIOP RCE

CVE-2017-10271

WLS-WSAT RCE

What CloudSEK Said:

"This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments."

What You Should Do

1. Apply the Patch Now

Oracle released patches in January 2026. If you haven't applied them, do it today.

2. Check Your Logs

Look for suspicious activity. Check for any access without authorization.

3. Meet the CISA Deadline

Federal agencies have until August 27, 2026. Don't wait.

4. Patch Older WebLogic Flaws Too

Attackers are also exploiting older vulnerabilities. Patch them while you're at it.

The Bottom Line

Oracle HTTP Server CVE-2026-21962 is a critical flaw under active attack. No credentials needed. Full access to critical data.

What You Need to Know:

Key Point

Detail

Vulnerability

CVE-2026-21962

CVSS Score

10.0

Impact

Unauthorized access, data modification

Status

Actively exploited

Patch

Available since January 2026

CISA Deadline

August 27, 2026

Here Is What You Should Do:

  • Apply Oracle’s patch right away
  • Look for any indicators of compromise
  • Patch other WebLogic vulnerabilities
  • Follow CISA’s guidelines

FAQ Section

What is CVE-2026-21962?

This is a critical vulnerability present in Oracle HTTP Server and WebLogic Proxy Plug-in. The attackers have the ability to view or change critical information without any credentials at all.

What is the CVSS score?

10.0, the highest possible.

Is it being exploited?

Yes. GreyNoise and CloudSEK have confirmed active exploitation.

What should I do?

Patch Oracle as soon as you can. See whether there have been any signs of intrusion. Patch all other WebLogic vulnerabilities.

When is the CISA deadline?

August 27, 2026.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067