Oracle HTTP Server and WebLogic Proxy Plug-in Under Active Attack: CISA Adds Critical Flaw to Exploited Catalog

Category: CISA Advisories

Let me ask you something: would you leave your office unlocked if you knew someone was already trying the door?

Probably not. But that is the situation many organizations may face with CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in.

The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) Catalog on August 24, 2026. Organizations are expected to remediate it by August 27, 2026.

That gives you very little time.

What is CVE-2026-21962?

CVE-2026-21962 is an improper access control vulnerability, classified as CWE-284.

In everyday language, the affected component may fail to properly enforce who is allowed to access or change protected resources. An attacker does not need a username or password to attempt an attack. They only need network access to the vulnerable service through HTTP.

And here is where it gets serious: the vulnerability carries a CVSS 3.1 base score of 10.0 out of 10.0, the highest possible severity rating.

According to CISA, successful exploitation could allow unauthorized access to:

  • Create critical data
  • Delete critical data
  • Modify critical data
  • Access all data available through the affected Oracle components

That is sensitive information leaving the safety of your business.

CISA currently lists known use in ransomware campaigns as unknown. That does not make the vulnerability safe. It means there is no confirmed ransomware-campaign designation in the catalog at this time.

You can review the official entry through the CISA Known Exploited Vulnerabilities Catalog and the CVE record for CVE-2026-21962.

Which Oracle products and versions are affected?

The vulnerability affects the Oracle Fusion Middleware component identified as:

  • Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server
  • Oracle WebLogic Server Proxy Plug-in for Microsoft IIS

The affected versions are:

  • 12.2.1.4.0
  • 14.1.1.0.0
  • 14.1.2.0.0

The IIS plug-in is affected at version 12.2.1.4.0 only.

Oracle’s January 2026 Critical Patch Update also lists Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0 among the affected products addressed by the update.

Here is the problem: proxy plug-ins can be overlooked during routine patching. You may update the WebLogic application server and assume the front-end proxy is covered, but the proxy plug-in may be installed separately on an Apache or IIS server.

That is like changing the lock on your back door while leaving the side entrance untouched.

Layered secure web gateway protecting business servers from unauthorized traffic

Why CISA’s KEV listing changes the priority

CISA does not add every newly disclosed vulnerability to the KEV Catalog.

The catalog is designed to identify vulnerabilities that are known to be exploited in the wild. CISA advises organizations to use the catalog as an input to their vulnerability-management priorities.

For CVE-2026-21962, the timeline is especially important:

  • Date added: August 24, 2026
  • Remediation due date: August 27, 2026
  • Severity: Critical
  • CVSS score: 10.0
  • Authentication required: None
  • Attack path: Network access via HTTP
  • Known ransomware use: Unknown

That is a three-day window between catalog addition and the listed remediation deadline.

If your organization uses an affected Oracle deployment, this is not a vulnerability to place in the next monthly patch cycle. It belongs at the front of your queue.

What should you do first?

Start by identifying every instance of Oracle HTTP Server and every WebLogic Server Proxy Plug-in in your environment.

Do not limit the search to your main production server. Include:

  • Internet-facing systems
  • DMZ servers
  • Backup and disaster-recovery environments
  • Staging and test systems
  • Apache servers using the WebLogic proxy plug-in
  • Microsoft IIS servers using the WebLogic proxy plug-in
  • Older Oracle Fusion Middleware installations

Look beyond your primary asset list, too. A legacy application, forgotten virtual machine, or secondary web front end can still create an exposure.

Your inventory should record the product, version, host, network location, business owner, and whether the system is reachable from the internet or an untrusted network.

Apply Oracle’s January 2026 Critical Patch Update

Oracle’s primary remediation is to apply the security patches in its January 2026 Critical Patch Update.

Oracle strongly recommends applying Critical Patch Update security patches without delay, particularly when successful exploitation could have a serious impact.

As you plan the update:

  • Confirm the exact Oracle HTTP Server and plug-in versions installed.
  • Review Oracle’s Fusion Middleware patch-availability documentation.
  • Treat Apache and IIS plug-ins as components that require their own verification.
  • Test the update in a nonproduction environment when possible.
  • Schedule required service restarts and maintenance windows.
  • Patch production, failover, disaster-recovery, test, and staging systems.
  • Confirm that the updated binaries and Oracle installation records reflect the applied patch.

Do not assume that patching the WebLogic Server application alone resolves the issue. Verify each affected proxy plug-in separately.

IT administrator reviewing patch management and server health dashboards

What if you cannot patch by August 27?

Patching is the preferred solution. Workarounds and compensating controls do not correct the underlying flaw.

If you cannot complete remediation immediately, reduce exposure while you work toward the permanent fix:

  • Restrict access to affected services to trusted networks and approved IP ranges.
  • Remove direct public exposure wherever business operations allow.
  • Place necessary internet-facing services behind appropriate network security controls.
  • Segment proxy servers from critical backend systems.
  • Limit communication between the proxy layer and WebLogic servers to required traffic.
  • Restrict administrative interfaces to VPN or dedicated management networks.
  • Disable unused plug-ins, modules, and services.
  • Review firewall, load-balancer, and web-application-firewall rules.
  • Increase monitoring of Oracle HTTP Server, Apache, IIS, and WebLogic logs.

Most importantly, document what you changed, which systems remain exposed, who approved the temporary control, and when the permanent patch will be installed.

CISA’s listed action is to apply mitigations per vendor instructions, follow applicable BOD 26-04 guidance, or discontinue use if mitigations are unavailable. You can review the CISA BOD 26-04 guidance for additional direction.

Look for signs of attempted exploitation

Because CVE-2026-21962 is in the KEV Catalog, you should consider whether vulnerable systems may already have received malicious requests.

Review relevant logs for:

  • Unexpected requests from unfamiliar external addresses
  • Access to administrative or internal application paths
  • Unusual HTTP methods, headers, or request patterns
  • Unexpected changes to business data
  • New or modified accounts and permissions
  • Configuration changes on proxy or WebLogic systems
  • Activity outside normal business hours
  • Connections from web-facing servers to systems they do not normally contact

Do not delete logs during cleanup. Preserve relevant evidence before making major changes, especially if you suspect unauthorized access.

If you find suspicious activity, isolate the affected system when practical, preserve forensic data, and involve qualified incident-response professionals.

A practical remediation checklist

Use this checklist to organize your response:

  1. Identify exposure

    • Find all affected Oracle HTTP Server and WebLogic Proxy Plug-in installations.
  2. Confirm versions

    • Check Apache, IIS, Oracle HTTP Server, and proxy plug-in versions.
  3. Prioritize internet-facing systems

    • Address systems accessible from the public internet or untrusted networks first.
  4. Apply Oracle’s January 2026 security update

    • Follow the vendor’s installation and verification instructions.
  5. Protect systems that cannot be patched immediately

    • Restrict network access, segment systems, and apply appropriate filtering.
  6. Review logs

    • Investigate suspicious requests, access patterns, account changes, and data modifications.
  7. Verify and document

    • Confirm remediation, record exceptions, and maintain evidence of your response.

Small business owner and IT consultant reviewing a segmented secure network plan

Do not wait for the deadline

CVE-2026-21962 is a reminder that a proxy server is not merely a traffic director. It can be the front door to applications, databases, and business information.

If that door has a critical access-control problem — and attackers are already looking for it — you need to secure it quickly.

Platinum Web Services helps businesses identify vulnerable systems, improve network segmentation, coordinate security updates, and respond to urgent cybersecurity risks. You can learn more about our cybersecurity solutions and managed IT services.

If you would like help reviewing your environment, contact Platinum Web Services. We are available 24/7 for IT emergencies.

A locked door only protects you when it is the door attackers cannot get through.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *