CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
CSIRTS triage
- What
- Improper access control allowing unauthorized creation, deletion, modification, and complete read access to all accessible data.
- Who is affected
- All users of Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in.
- Urgency
- Critical — affects confidentiality, integrity, and availability of critical data with active exploitation.
- Action
- Apply security patches from Oracle immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
Get an email when a new Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-21962
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-21962Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-21962 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [critical] Oracle Fusion Middleware: Multiple Vulnerabilitiescert-bund
- criticalexploitedOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
Recent advisories for Oracle HTTP Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-60530: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ht…nvd · 2026-07-21
- highCVE-2026-60454: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).…nvd · 2026-07-21
- criticalCVE-2026-60438: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ss…nvd · 2026-07-21
- highCVE-2026-60431: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_pr…nvd · 2026-07-21
- criticalCVE-2026-60363: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache…nvd · 2026-07-21
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-60004: Gitea Code Injection Vulnerability2026-08-25
- criticalCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-21
- criticalCVE-2026-72530: TrueConf Server Code Injection Vulnerability2026-08-20
- criticalCVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-20
- criticalCVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability2026-08-19