Daily Wire · Free EditionConfirmed Threats. Zero Noise.

The Exploit Bulletin

What Security Teams Must Act On Today

From the edition of

Tuesday, August 25, 2026

CISA KEV · due 2026-08-27Data ExposurecriticalCVSS 10.0CVE-2026-21962

Unauthenticated access to all data behind Oracle HTTP Server / WebLogic Proxy Plug-in (CVE-2026-21962)

CISA added this CVSS-10 flaw to KEV yesterday with an unusually short 2026-08-27 remediation deadline, and multiple outlets report it is being widely exploited — teams that leave the proxy plug-in unpatched this week should expect their WebLogic-fronted data to be accessed or tampered with.

An improper access control flaw in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in lets a remote, unauthenticated attacker read, create, modify or delete any data the proxy can reach — full compromise of confidentiality and integrity with scope change (CVSS 10.0). Public exploit code exists and exploitation has been observed since at least February.

Affected: Oracle HTTP Server / WebLogic Server Proxy Plug-in 12.2.1.4.0; Oracle HTTP Server / WebLogic Server Proxy Plug-in 14.1.1.0.0; Oracle HTTP Server / WebLogic Server Proxy Plug-in 14.1.2.0.0

How to Test

Inventory Oracle HTTP Server instances and check whether the WebLogic Server Proxy Plug-in (mod_wl) is at 12.2.1.4.0, 14.1.1.0.0 or 14.1.2.0.0 without the January 2026 CPU applied; review OHS access logs for unauthenticated requests hitting WebLogic-proxied paths from unfamiliar IPs, and treat any anomalous access to backend admin or data endpoints via the proxy as a compromise indicator.

How to Patch

Apply the Oracle Critical Patch Update from January 2026 (cpujan2026) to all affected OHS and WebLogic Proxy Plug-in installations; if the patch cannot be applied immediately, restrict internet exposure of the proxy front-end or take the product offline per CISA's BOD 22-01 required action until patched.