VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 45 minutes ago

CVE-2026-21962

10.0 Critical Not applicable

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

CWE-284 · Improper access control

Exploitation Status

Exploited in the wild

Confirmed real-world exploitation.

CVSS E:A

  • CISA KEV listed Confirmed exploitation in the wild. Added 2026-08-24 · remediation due 2026-08-27 · ransomware use: unknown
  • CISA Vulnrichment exploitation: active CISA records active exploitation. Automatable: yes, technical impact: total.
  • Indexed PoC 10 indexed Published artifacts you can open, in GitHub PoC; first seen 2026-01-22.
  • EPSS 42% chance in 30 days A model prediction, not an observation. Higher than 99% of all scored CVEs.

8 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC CVE-2026-21962 6 2026-01-22
GitHub PoC Unauthenticated vulnerability that may allow remote attackers to compromise confidentiality and integrity, potentially leading to full system compromise. 6 2026-01-22
GitHub PoC gregk4sec/cve-2026-21962 4 2026-03-08
GitHub PoC zeetee1235/CVE-2026-21962 3 2026-08-27
GitHub PoC Oracle Fusion Middleware Oracle HTTP Server / WebLogic Server Proxy Plug-in has an easily exploitable, unauthenticated, network-reachable flaw allowing compromise over HTTP. Affected supported versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0. 3 2026-02-09
GitHub PoC CVE-2026-21962 Açığı için blog sayfası oluşturdum. 2 2026-08-29
GitHub PoC naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool 2 2026-03-21
GitHub PoC CVE-2026-21962-EXP 2 2026-01-26
GitHub PoC CVE-2026-21962 1 2026-04-24
GitHub PoC CVE Finder 2026-02-03

Waratek Defense Posture

Not applicable

Not a Java vulnerability. Outside ARMR's domain entirely.

  • Protection none
  • Action not-needed none
  • Review automated inferred
  • Record active
Decided by oracle-component : The defect being in a component of a tracked product the agent does not reach: JavaFX, the Java SE installer, the native WebLogic proxy plug-in. Oracle gives these no CPE of their own and names them only in the description.
Finding This CVE is in the WebLogic Server Proxy Plug-in (Weblogic Server Proxy Plug-in for Apache HTTP Server), the native module Oracle ships for Apache HTTP Server, Oracle HTTP Server and IIS to forward requests to WebLogic. The plug-in is C code running inside a web server, not Java running in a JVM, so there is no bytecode for ARMR to instrument. Oracle files these CVEs under the WebLogic and HTTP Server CPE products, which is why CPE data alone reads them as in scope.

CVSS

10.0 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N 1 metric

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N secalert_us@oracle.com Secondary published

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update January 2026 CPU 2026-Q1 Oracle Fusion Middleware / Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Fusion Middleware Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0

🖥️ Product CPEs & Version Ranges

2 product(s) over 6 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd oracle http server generic 12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0
nvd oracle weblogic server proxy plug-in generic 12.2.1.4.0 · 14.1.1.0.0 · 14.1.2.0.0

References

URLTags
https://www.oracle.com/security-alerts/cpujan2026.html
https://github.com/Ashwesker/Ashwesker-CVE-2026-21962/issues/1 Broken Link, Not Applicable
https://web.archive.org/web/20260129165916/https://github.com/Ashwesker/Ashwesker-CVE-2026-21962/issues/1 Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21962 US Government Resource
https://x.com/0xacb/status/2015473216844620280 Not Applicable

Timeline

Published 2026-01-20 Last modified 2026-08-25
Published2026-01-20By the CVE Program.
NVD record modified2026-08-25NVD's own last-modified date for this record.