CISA Flags Actively Exploited Oracle HTTP Server Flaw CVE-2026-21962, Patch Urgently
CISA added CVE-2026-21962, a critical unauthenticated vulnerability in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24, 2026. The flaw carries a maximum CVSS score of 10.0 and allows remote attackers with no credentials to read, create, modify, or delete sensitive data accessible to the affected plug-in. Affected versions include Oracle HTTP Server and WebLogic Server Proxy Plug-in 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, with IIS-based plug-ins impacted only on version 12.2.1.4.0. Oracle released patches in its January 2026 Critical Patch Update, and U.S. federal civilian agencies face a remediation deadline of August 27, 2026. As a temporary measure, Oracle recommends restricting network access to the exposed HTTP/HTTPS services until patches can be applied.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in