CISA added CVE-2026-21962, a maximum-severity improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on 2026-08-24 with a three-day remediation deadline.
What Is It
CVE-2026-21962 is an improper access control flaw (CWE-284) in the Oracle HTTP Server / Oracle WebLogic Server Proxy Plug-in product of Oracle Fusion Middleware, specifically in the WebLogic Server Proxy Plug-in for Apache HTTP Server and the plug-in for IIS. Oracle rates it CVSS 3.1 base score 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. It is described as easily exploitable by an unauthenticated attacker with network access over HTTP.
Why It Matters
CISA's SSVC assessment for this CVE marks exploitation as active, automatable yes, and technical impact total: and the KEV listing itself confirms known exploitation in the wild. Ransomware campaign use is listed as Unknown.
Successful attacks allow unauthorized creation, deletion, or modification of critical data, plus unauthorized read access up to complete access to all data accessible to the HTTP Server and Proxy Plug-in. The CVSS scope is Changed: Oracle notes attacks may significantly impact additional products beyond the vulnerable component itself. Availability impact is None; this is a confidentiality and integrity problem.
What's Vulnerable
Affected supported versions:
- Oracle HTTP Server, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
- Oracle WebLogic Server Proxy Plug-in, 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
Oracle notes that for the WebLogic Server Proxy Plug-in for IIS, only 12.2.1.4.0 is affected.
Patch Status
Fixes are covered by Oracle's January 2026 Critical Patch Update. CISA's required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The KEV due date is 2026-08-27, three days after the 2026-08-24 addition. The KEV entry also cross-references BOD 26-04 and its forensic triage implementation guidance.
Sources
- Oracle Critical Patch Update Advisory, January 2026, https://www.oracle.com/security-alerts/cpujan2026.html
- CISA Known Exploited Vulnerabilities Catalog (CVE-2026-21962), https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21962
- NVD, CVE-2026-21962, https://nvd.nist.gov/vuln/detail/CVE-2026-21962
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements), https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk