Unauthenticated access to all data behind Oracle HTTP Server / WebLogic Proxy Plug-in (CVE-2026-21962)
CISA added this CVSS-10 flaw to KEV yesterday with an unusually short 2026-08-27 remediation deadline, and multiple outlets report it is being widely exploited — teams that leave the proxy plug-in unpatched this week should expect their WebLogic-fronted data to be accessed or tampered with.
An improper access control flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in lets a remote, unauthenticated attacker read, create, modify or delete any data the proxy can reach — full compromise of confidentiality and integrity with scope change (CVSS 10.0). Public exploit code exists and exploitation has been observed since at least February.
Affected: Oracle HTTP Server / WebLogic Server Proxy Plug-in 12.2.1.4.0; Oracle HTTP Server / WebLogic Server Proxy Plug-in 14.1.1.0.0; Oracle HTTP Server / WebLogic Server Proxy Plug-in 14.1.2.0.0
How to Test
Inventory Oracle HTTP Server instances and check whether the WebLogic Server Proxy Plug-in (mod_wl) is at 12.2.1.4.0, 14.1.1.0.0 or 14.1.2.0.0 without the January 2026 CPU applied; review OHS access logs for unauthenticated requests hitting WebLogic-proxied paths from unfamiliar IPs, and treat any anomalous access to backend admin or data endpoints via the proxy as a compromise indicator.
How to Patch
Apply the Oracle Critical Patch Update from January 2026 (cpujan2026) to all affected OHS and WebLogic Proxy Plug-in installations; if the patch cannot be applied immediately, restrict internet exposure of the proxy front-end or take the product offline per CISA's BOD 22-01 required action until patched.