
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21962 is a maximum-severity improper access control vulnerability (CWE-284) in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, components of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 (note: the IIS plug-in variant is only affected in version 12.2.1.4.0). The vulnerability was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update, which addressed 337 vulnerabilities in total. It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its unauthenticated, network-exploitable, scope-changing nature (Oracle CPU Jan 2026, Feedly).
The root cause is improper access control (CWE-284) in the WebLogic Server Proxy Plug-in for both Apache HTTP Server and Microsoft IIS. An unauthenticated attacker with network access via HTTP can exploit this flaw without any user interaction or special privileges, making it trivially exploitable. The vulnerability has a scope change, meaning successful exploitation can impact additional Oracle Fusion Middleware products beyond the directly affected proxy plug-in component. Multiple public proof-of-concept scripts have been published on GitHub (e.g., Ashwesker-CVE-2026-21962, samael0x4/CVE-2026-21962, ThumpBo/CVE-2026-21962, gregk4sec/CVE-2026-21962), and Nuclei templates have been submitted for automated detection (Oracle CPU Jan 2026, SANS ISC, Feedly).
Successful exploitation allows an unauthenticated remote attacker to perform unauthorized creation, deletion, or modification of critical data accessible to Oracle HTTP Server and WebLogic Server Proxy Plug-in, as well as complete unauthorized read access to all such data — resulting in total loss of confidentiality and integrity (CVSS Availability impact is None). Due to the scope change, attacks can cascade to additional Oracle Fusion Middleware products beyond the directly compromised component, significantly amplifying the blast radius. CloudSEK's honeypot research confirmed active attacker interest in these WebLogic proxy vulnerabilities, with exploitation observed within hours of public PoC release (CloudSEK Honeypot, GBHackers).
Ashwesker/Ashwesker-CVE-2026-21962, samael0x4/CVE-2026-21962, or ThumpBo/CVE-2026-21962). Nuclei templates have also been submitted for automated scanning.curl, wget) executed under the Oracle service context (SANS ISC, CloudSEK Honeypot).Oracle released patches for CVE-2026-21962 as part of the January 2026 Critical Patch Update (CPU); organizations should apply the relevant Fusion Middleware patches for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 immediately via the Oracle patch delivery mechanism. Until patches are applied, restrict network access to affected Oracle HTTP Server and WebLogic Proxy Plug-in instances via firewall rules, limiting HTTP access to only authorized and trusted systems. Implement network segmentation to isolate Fusion Middleware components, monitor HTTP traffic for anomalous requests to proxy plug-in endpoints, and consider disabling the WebLogic Server Proxy Plug-in for Apache HTTP Server or IIS if not operationally required. Oracle strongly recommends customers remain on actively supported versions and apply CPU patches without delay (Oracle CPU Jan 2026, Arctic Wolf).
The vulnerability generated significant attention across the security community immediately after disclosure. Arctic Wolf, Field Effect, Imperva, Sangfor, Fortinet (FortiWeb/FortiAppSec), and Check Point all published advisories or confirmed protection for their customers (Arctic Wolf, Field Effect, Imperva via Security Boulevard). SANS ISC published a diary entry on January 28, 2026, documenting "odd WebLogic requests" that may represent early exploitation attempts or AI-generated exploit noise, sparking community debate (SANS ISC). National CERTs including Canada (CCCS), Belgium (CCB), Singapore (CSA), Ireland (NCSC-IE), and Australia (WA SOC) issued advisories urging immediate patching. The Hacker News, BleepingComputer, and multiple security outlets covered the vulnerability as part of broader Oracle CPU coverage, and the CVSS 10.0 score drew widespread social media commentary on Mastodon, Bluesky, and Reddit.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."