CVE-2026-21962Active Exploitation(oracle / http_server)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 51 mentions and remains active

Immediate actions

  • Patch oracle http_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server
  • weblogic_server_proxy_plug-in

Threat summary

  • Active exploitation appears in 111 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 143 mentions across 37 observed days

What's happening

  • Active exploitation reported across 111 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 24 signals
  • Patch or workaround mentioned in 61 signals
  • Technical details provided in 90 signals
  • General: 20 classified signals
  • Disclosure: 9 classified signals
  • Peaked 7d ago at 51 mentions (2026-08-25); latest day: 1
  • 143 total mentions across 37 days

Affected systems

Vendors
Products
http_serverweblogic_server_proxy_plug-in

3 versions affected across 2 products

Deep dive

Activity timeline143 mentions / 37d
013263851Mentions · 2026-01-27: 1Mentions · 2026-01-28: 7Mentions · 2026-01-30: 3Mentions · 2026-01-31: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1Mentions · 2026-02-04: 1Mentions · 2026-02-09: 2Mentions · 2026-02-14: 4Mentions · 2026-02-15: 4Mentions · 2026-02-16: 1Mentions · 2026-02-18: 1Mentions · 2026-03-08: 1Mentions · 2026-03-19: 1Mentions · 2026-03-25: 4Mentions · 2026-03-26: 1Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 8Mentions · 2026-04-02: 2Mentions · 2026-04-03: 2Mentions · 2026-04-08: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-06-02: 2Mentions · 2026-06-05: 2Mentions · 2026-08-24: 9Mentions · 2026-08-25: 51Mentions · 2026-08-26: 14Mentions · 2026-08-27: 5Mentions · 2026-08-28: 1Mentions · 2026-08-29: 1Mentions · 2026-08-31: 1Mentions · 2026-09-02: 1Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-31: 2PoC Mentioned / Linked · 2026-04-01: 7PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-08-25: 7PoC Mentioned / Linked · 2026-08-26: 2PoC Mentioned / Linked · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-04-01: 3Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-04-03: 1Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-26: 1Exploit Tool / Code · 2026-08-27: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-01-30: 2Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-14: 4Active Exploitation · 2026-02-15: 4Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-25: 3Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 2Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 2Active Exploitation · 2026-04-01: 6Active Exploitation · 2026-04-02: 2Active Exploitation · 2026-04-03: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-02: 2Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-08-24: 8Active Exploitation · 2026-08-25: 45Active Exploitation · 2026-08-26: 13Active Exploitation · 2026-08-27: 2Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-29: 1Active Exploitation · 2026-09-02: 1Active Exploitation · 2026-09-27: 1Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-02-14: 2Patch / Workaround · 2026-02-15: 3Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 5Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-08-24: 3Patch / Workaround · 2026-08-25: 27Patch / Workaround · 2026-08-26: 7Patch / Workaround · 2026-08-27: 3Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 2Technical Details · 2026-01-31: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-14: 3Technical Details · 2026-02-15: 3Technical Details · 2026-02-18: 1Technical Details · 2026-03-25: 3Technical Details · 2026-03-26: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 8Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-08: 1Technical Details · 2026-06-02: 2Technical Details · 2026-06-05: 2Technical Details · 2026-08-24: 4Technical Details · 2026-08-25: 35Technical Details · 2026-08-26: 9Technical Details · 2026-08-27: 2Technical Details · 2026-08-28: 1Technical Details · 2026-08-29: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-27: 101-2701-3102-0402-1503-0803-2603-3004-0204-1706-0508-2608-2909-27
Signal classification6 categories
Active Exploitation
10875.5%
General
2014.0%
Disclosure
96.3%
Exploit
32.1%
Patch
21.4%
PoC
10.7%
Referenced assets100 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Active Exploitation1
2026-01-287
Disclosure1General6
2026-01-303
Active Exploitation1Disclosure1General1
2026-01-311
Active Exploitation1
2026-02-011
General1
2026-02-021
General1
2026-02-041
Disclosure1
2026-02-092
Disclosure1General1
2026-02-144
Active Exploitation4
2026-02-154
Active Exploitation4
2026-02-161
Active Exploitation1
2026-02-181
Disclosure1
2026-03-081
General1
2026-03-191
Active Exploitation1
2026-03-254
Active Exploitation3General1
2026-03-261
Active Exploitation1
2026-03-272
Active Exploitation2
2026-03-281
Active Exploitation1
2026-03-301
Active Exploitation1
2026-03-312
Active Exploitation1Exploit1
2026-04-018
Active Exploitation6Disclosure1Exploit1
2026-04-022
Active Exploitation2
2026-04-032
Active Exploitation2
2026-04-081
Active Exploitation1
2026-04-171
General1
2026-04-191
General1
2026-06-022
Active Exploitation2
2026-06-052
Active Exploitation2
2026-08-249
Active Exploitation8Disclosure1
2026-08-2551
Active Exploitation45Disclosure1General5
2026-08-2614
Active Exploitation13Disclosure1
2026-08-275
Active Exploitation2General1Patch1PoC1
2026-08-281
Exploit1
2026-08-291
Active Exploitation1
2026-08-311
Patch1
2026-09-021
Active Exploitation1
2026-09-271
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are actively exploiting a CVSS 10.0 Oracle WebLogic flaw. CVE-2026-21962 can let unauthenticated attackers access or modify critical data in Oracle HTTP Server and WebLogic Server Proxy Plug-in via HTTP. See the exploitation details - https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html

    Post summary

    The post reports that CVE-2026-21962, a CVSS 10.0 Oracle WebLogic flaw, is being actively exploited by attackers, enabling unauthenticated access or modification of critical data, but provides no PoC, exploit tool, or patch details.

    59042537262.7K
    2.4M followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️ While no confirmed POC has yet been released for the recent Oracle vulnerability (CVE-2026-21962; CVSS 10), a wide range of actors are attempting multiple pathways to trigger the vulnerability Here are various pathways we've seen in the past week: /weblogic/..;/bea_wls_internal/ProxyServlet /wl_proxy/..;/bea_wls_internal/ProxyServlet /weblogic//weblogic/..;/bea_wls_internal/ProxyServlet /wl_proxy//weblogic/..;/bea_wls_internal/ProxyServlet /console;/bypass/ /_proxy//weblogic/..;/bea_wls_internal/ProxyServlet /proxy//weblogic/..;/bea_wls_internal/ProxyServlet /_proxy/..;/bea_wls_internal/ProxyServlet /weblogic/../bea_wls_internal/ProxyServlet /static/..;/ Some IPs / IOCs of associated actors: 27.36.129.14 China Unicom 🇨🇳 5.34.218.210 Akari Networks 🇺🇸 204.194.51.134 Turing Group Limited 🇺🇸 113.142.69.91 CHINANET SHAANXI 🇨🇳 151.242.152.13 EDGENAT CLOUD 🇭🇰 137.220.176.225 CTG Server Limited 🇯🇵 31.40.212.167 BrainStorm Network 🇦🇷 107.174.95.25 HostPapa 🇺🇸 222.128.62.127 China Unicom Beijing 🇨🇳 212.32.76.16 GSL Networks 🇯🇵 212.193.3.188 Advin Services 🇩🇪 78.46.16.8 Hetzner Online 🇩🇪 146.70.224.46 M247 Europe 🇭🇰 160.160.149.196 Maroc Telecom 🇲🇦 49.156.40.126 WiCAM Corporation 🇰🇭 45.196.236.71 Hytron Network 🇭🇰 45.196.236.70 Hytron Network 🇭🇰 39.100.75.158 Alibaba 🇨🇳 103.137.247.44 Pittqiao Network 🇹🇼 80.225.236.192 Oracle Corporation 🇮🇳 110.54.134.153 Globe Telecoms 🇵🇭 205.147.22.3 Proton AG 🇺🇸 Most exploit attempts embed a base64-encoded subpayload uncloaking further infrastructure. View live Oracle threat intelligence 👉 https://console.defusedcyber.com/intel

    Post summary

    The post documents active exploitation attempts against CVE-2026-21962 by various actors, though no PoC or patch information has been shared.

    02921537918.6K
    6.0K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-21962 (CVSS 10.0): Unauthenticated access-control bypass in Oracle HTTP Server & WebLogic Server Proxy Plug-in 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJCRUEtV2ViTG9naWMtU2VydmVyIg%3D%3D 🎯1.4M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="BEA-WebLogic-Server" 🔖Refer: https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑21962 is a critical access‑control bypass in Oracle HTTP and WebLogic Server, and the CISA alert indicates it is currently being exploited, though no PoC or patch guidance is provided.

    13101215721.8K
    14.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA CONFIRMS ACTIVE EXPLOITATION OF CRITICAL ORACLE VULNERABILITY CISA has officially added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The vulnerability affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in and carries a maximum CVSS score of 10.0. * CVE: CVE-2026-21962 * CVSS: 10.0 — CRITICAL * CWE: CWE-284 — Improper Access Control * Authentication required: NONE * Attack vector: Network / HTTP * Attack complexity: LOW * User interaction: NONE * CISA exploitation status: ACTIVE * CISA KEV added: August 24, 2026 * Federal remediation deadline: August 27, 2026 * Known ransomware use: UNKNOWN 🎯 What Can Successful Exploitation Do? According to Oracle's vulnerability description, successful exploitation can result in: * Unauthorized access to critical data * Complete access to data accessible through affected components * Unauthorized modification of critical data * Creation or deletion of accessible data The vulnerability can also significantly impact additional products because of a scope change. Affected versions include: * Oracle HTTP Server 12.2.1.4.0 * Oracle HTTP Server 14.1.1.0.0 * Oracle HTTP Server 14.1.2.0.0 * Oracle WebLogic Server Proxy Plug-in 12.2.1.4.0 * Oracle WebLogic Server Proxy Plug-in 14.1.1.0.0 * Oracle WebLogic Server Proxy Plug-in 14.1.2.0.0 For the WebLogic Server Proxy Plug-in for IIS, Oracle identifies 12.2.1.4.0 as affected. ⚠️ CISA REQUIRED ACTION: Apply vendor mitigations, follow applicable federal guidance for cloud services, or discontinue use of the affected product if mitigations are unavailable. ⚠️ Analyst Note: This is no longer a theoretical vulnerability or simply a CVSS 10.0 patching priority. CISA's KEV designation means there is evidence that CVE-2026-21962 has actually been exploited. The combination of: * CVSS 10.0 * Remote network exploitation * No authentication * Low attack complexity * No user interaction * Confirmed exploitation makes exposed Oracle HTTP Server and WebLogic proxy infrastructure a high-priority remediation target. Organizations should not only patch affected systems but also review potentially exposed servers for evidence of compromise that may have occurred BEFORE remediation. Sources: CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog CISA Alert: https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog CVE: https://www.cve.org/CVERecord?id=CVE-2026-21962 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-21962 #DDW #CyberSecurity #CISA #Oracle #WebLogic #CVE #Vulnerability #ThreatIntelligence

    Post summary

    CISA has added CVE-2026-21962 to its KEV catalog, confirming active exploitation in the wild and urging stakeholders to immediately apply vendor mitigations or discontinue use of affected components.

    5320873413.4K
    206.6K followersView on X
  • X@SansLimit3
    Active Exploitation

    Exploitation infrastructure observed scanning for: CVE-2025-55182(React2shell) CVE-2026-21962(Oracle Weblogic) CVE-2025-31324(SAP NetWeaver) - actively exploited by China-linked APTs Targeting India-based critical infrastructure SAP exploit script "MADE BY SCATTERED LAPSUS$ HUNTERS" → likely tool reuse. Tooling includes fscan & Neo-reGeorg - commonly seen in China-linked intrusion tradecraft. C2s: 160[.]191.183.147:80 160[.]191.183.126:80 Seen on @Huntio ~ 1 month ago. @malwrhunterteam @polygonben @WhichbufferArda

    Post summary

    The text describes attackers scanning multiple CVEs and reports that CVE-2025-31324 (SAP NetWeaver) is actively exploited by China‑linked APTs using known tools and an exploit script against Indian critical infrastructure.

    27154244.6K
    231 followersView on X
  • Nawaf Alkeraithe نواف الكريثي@alkeraithenw
    Active Exploitation

    🚨 ثغرة Oracle WebLogic تُستغل حالياً بقوة CVE-2026-21962 🔹️درجة خطورة 10.0 🔹️تسمح لمهاجم غير مصادق بالوصول إلى بيانات حرجة أو تعديلها في Oracle HTTP Server وWebLogic Proxy. 🔹️قامت CISA بإضافتها لقائمة الثغرات المستغلة فعلياً، والتصحيح متوفر منذ يناير 2026 لكن الهجمات مستمرة. 🔹️المهاجمون يستخدمون مسحاً جماعياً ويستهدفون الخوادم المكشوفة مع ثغرات WebLogic قديمة أيضاً.

    Post summary

    CVE-2026-21962 is a high‑severity vulnerability (score 10.0) actively exploited in the wild, with patches available but attacks continue.

    3106515136.6K
    286 followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Oracle HTTP Server & Oracle WebLogic Server Proxy Plug-in vulnerability CVE-2026-21962 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations. #Cybersecurity #InfoSec https://t.co/7MIYgjir4E

    Post summary

    CVE-2026-21962 is confirmed as actively exploited and users are directed to apply mitigations via the DHS link.

    312244410.9K
    303.2K followersView on X
  • Nicolas Krassas@Dinosn
    General

    CVE-2026-21962 Oracle Weblogic (CVSS 10) starts with the well known /..;/ bypass it seems, but pain to find sources to end this chain.

    Post summary

    The tweet merely references CVE-2026-21962 with a CVSS 10 score and a brief mention of a known bypass, but provides no further details, PoC, or exploitation evidence.

    14041105.2K
    162.1K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-21962 Vendor: Oracle Corporation Product: Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in Description: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. Link: https://github.com/zeetee1235/cve-2026-21962 #dbugs_vuln

    Post summary

    A Proof‑of‑Concept and exploit code for CVE‑2026‑21962 targeting Oracle HTTP Server and Weblogic Server Plug‑in has been published on GitHub.

    011028152.0K
    3.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 Oracle HTTP Server / WebLogic Server Proxy Plug-in'deki kritik CVE-2026-21962 açığı için PoC yayınlandı. PoC, hatalı URI normalizasyonundan yararlanarak erişim kontrolünün nasıl bypass edilebildiğini ve yetkisiz erişimin nasıl sağlanabildiğini gösteriyor. ⚠️ Açık aktif olarak istismar ediliyor ve CVSS skoru 10.0 PoC: https://github.com/zeetee1235/cve-2026-21962

    Post summary

    A PoC for CVE‑2026‑21962 has been released, detailing how URI normalization flaws allow access‑control bypass; the vulnerability is actively exploited in the wild and is being handled with a CVSS of 10.0.

    02012102.5K
    2.4K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CloudSEK warn of instant exploitation for Oracle WebLogic's CVE-2026-21962. With a 10.0 CVSS score, this RCE allows full server takeover. Patch now! #Oracle #WebLogic #CyberSecurity #InfoSec #RCE #CVE #PatchNow #ZeroDay #Vulnerability https://securityonline.info/oracle-weblogic-rce-vulnerability-cve-2026-21962-exploitation/ https://t.co/lnFnKULnmO

    Post summary

    The post reports that CVE‑2026‑21962, an Oracle WebLogic RCE with a 10.0 CVSS score, is being actively exploited, urging immediate patching.

    0601331.0K
    12.3K followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    General

    CVE-2026-21962 — Oracle WebLogic Proxy Plug-in (CVSS 10.0, CISA KEV) going to wait a little bit more before publishing this #pruva repro but you can use the detection suggested by pruvie DETECTION — what to alert on: • Proxy access logs: any URI containing ..; (also encoded: %2e%2e%3b) with HTTP 200 — near-zero legitimate use. • Any external request reaching bea_wls_internal contexts or HTTPClnt* servlets with a 2xx status. • 403→200 differential: same client denied directly, then succeeds with a modified path within minutes. • Front-end/backend log mismatch: WebLogic logs an internal-context hit whose true client IP (WL-Proxy-Client-IP) is external.

    Post summary

    The statement offers detection guidance for CVE‑2026‑21962, mentions a forthcoming PoC, but provides no exploit code, patch, or evidence of active exploitation.

    1101061.2K
    13.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/24追加) #vulnerability 🛡CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / Oracle (CNA) ・種別:不適切なアクセス制御 (CWE-284) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Oracle HTTP Server および Oracle WebLogic Server Proxy Plug-in に存在する不適切なアクセス制御の脆弱性です。 未認証の攻撃者がHTTP経由で悪用することで、対象コンポーネントがアクセス可能な重要データまたはすべてのデータを不正に参照、作成、削除、変更できる可能性があります。 影響を受けるバージョンは12.2.1.4.0、14.1.1.0.0、14.1.2.0.0で、IIS向けWebLogic Server Proxy Plug-inは12.2.1.4.0のみが対象です。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月27日 ・BOD 26-04 対処期限(露出なし):2026年8月27日 ✅攻撃前提条件 ・Oracle HTTP Server または Oracle WebLogic Server Proxy Plug-in の影響を受けるバージョンを使用している ・攻撃者が対象コンポーネントへHTTP経由でネットワークアクセスできる ・攻撃者は認証情報を必要としない ・ユーザー操作を必要としない ・修正を含むOracle提供のセキュリティ更新が適用されていない ✅悪用時影響 ・対象コンポーネントがアクセス可能な重要データまたはすべてのデータを不正に閲覧される可能性がある ・対象コンポーネントがアクセス可能な重要データまたはすべてのデータを不正に作成、削除、変更される可能性がある ・スコープ変更により関連する他の製品にも重大な影響が及ぶ可能性がある ・CVSS上、可用性への直接的な影響は評価されていない ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(CloudSEK) ・概要:CloudSEKは、2026年1月22日から2月3日までのハニーポット観測で、CVE-2026-21962を狙う攻撃試行を3つの送信元IPから確認したと公表しています。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-21962 ・https://www.oracle.com/security-alerts/cpujan2026.html ・https://github.com/cisagov/vulnrichment/blob/develop/2026/21xxx/CVE-2026-21962.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21962 ・https://www.cloudsek.com/blog/honey-for-hackers-a-study-of-attacks-targeting-the-recent-cve-2026-21962-and-other-critical-weblogic-vulnerabilities-on-a-high-interactive-oracle-honeypot ・https://x.com/0xacb/status/2015473216844620280 ・https://web.archive.org/web/20260129165916/https://github.com/Ashwesker/Ashwesker-CVE-2026-21962/issues/1 ・https://www.ipa.go.jp/security/reports/vuln/jvn/rcu1hd000000gcec-att/JVNiPedia2026q1.pdf ・https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CISA added CVE‑2026‑21962 to its KEV catalog after confirming in‑the‑wild exploitation; Oracle has released a patch and the post supplies detailed vulnerability information.

    0101227.6K
    45.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🚨 Oracle WebLogic'te kritik açık aktif olarak istismar ediliyor! CISA, Oracle HTTP Server ve WebLogic Server Proxy Plug-in'i etkileyen CVE-2026-21962 açığını KEV kataloğuna ekledi. 🔴 CVSS: 10.0 🔴 Kimlik doğrulama gerektirmiyor 🔴 HTTP üzerinden uzaktan istismar edilebiliyor 🔴 Kritik verilere yetkisiz erişim/değişiklik mümkün Oracle yamayı Ocak ayında yayınlamıştı. CISA ise gerekli güncellemelerin uygulanması için uyarıyor.

    Post summary

    Oracle WebLogic CVE-2026-21962 is actively exploited, with a CVSS score of 10.0; a patch was released in January and CISA is urging timely application.

    011743.5K
    2.4K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、Oracle HTTP Server/Oracle Weblogic Server Proxy Plug-inのCVE-2026-21962を追加。CVSSスコア10。対処期限は3日後の8/27。ランサムウェアによる悪用は不知。 https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog 差分:https://kev.kokumoto.com/#/cveId:CVE-2026-21962

    Post summary

    CISA has added CVE-2026-21962 to its known‑exploited vulnerability catalog with a CVSS score of 10, noting the issue exists and there is no current patch or exploit detail provided.

    000721.1K
    7.8K followersView on X
  • 보안프로젝트@ngnicky
    Active Exploitation

    오라클 웹로직 취약점은 계속 이슈... “패치 안 된 서버는 필패”... 오라클 웹로직 노린 해커들의 ‘무차별 폭격’ CVSS 10.0 최고 등급 취약점 CVE-2026-21962 익스플로잇 공개 직후 공격 급증 2017년 구형 결함까지 재활용하는 ‘Spray and pray’ 전술로 방어망 타격 https://share.google/1ysmQZFZnkCBCu8CK

    Post summary

    The post highlights that the CVE-2026-21962 vulnerability, rated CVSS 10.0, has just had its exploit released, triggering a surge in attacks against Oracle WebLogic servers and underscoring the need for urgent patching.

    00062378
    6.7K followersView on X
  • Andre Gironda@AndreGironda
    Active Exploitation

    Honey for hackers study of attacks targeting the recent CVE-2026-21962 and other critical WebLogic vulnerabilities on a high-interactive Oracle honeypot -- https://www.cloudsek.com/blog/honey-for-hackers-a-study-of-attacks-targeting-the-recent-cve-2026-21962-and-other-critical-weblogic-vulnerabilities-on-a-high-interactive-oracle-honeypot

    Post summary

    The article reports on a study of real‑world attacks against CVE‑2026‑21962—and other WebLogic vulnerabilities—observed on a highly interactive Oracle honeypot.

    00014114
    3.6K followersView on X
  • SANS.edu Internet Storm Center@sans_isc
    General

    Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop? https://isc.sans.edu/diary/32662 https://t.co/2yIltUq0Sk

    Post summary

    The post hints at a potential WebLogic request anomaly possibly related to CVE-2026-21962, but it lacks concrete details, evidence of exploitation, or mitigation information.

    020301.2K
    116.7K followersView on X
  • L7@L_Seven_LLC
    General

    Prompt injections, agentic AI, and CVE-2026-21962. How do these things affect us and companies at large? What dangers do they pose? Find out in today's newsletter where we go more indepth. Fell free to view it here: https://l7it.substack.com/p/castle-wall-cd1?r=8ubjz1&utm_campaign=post-expanded-share&utm_medium=web https://t.co/9AJhwNsB5f

    Post summary

    The message references CVE-2026-21962 while promoting a newsletter about prompt injections and agentic AI, but it supplies no PoC, exploit, patch, or technical details about the vulnerability.

    0202028
    2 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Oracle WebLogic 脆弱性 CVE-2026-21962 (CVSS 10.0):実環境での継続的な悪用を確認 https://iototsecnews.jp/2026/04/01/hackers-actively-exploit-critical-weblogic-rce-vulnerabilities-in-ongoing-attacks/ Oracle WebLogic Server の脆弱性である CVE-2026-21962 が、実環境で積極的に悪用され続けています。この脆弱性を悪用する攻撃者は、認証を必要とせずに外部から OS コマンドを実行できます。攻撃者はパス・トラバーサルという手法を悪用し、本来アクセスできない領域を操作することで、システムの制御権を奪おうとします。また、過去に報告された CVE-2020-14882 や CVE-2017-10271 といった既知の脆弱性も、依然として攻撃の入り口として狙われています。これらは、設定の不備や修正プログラムの未適用を突くものであり、自動化されたツールにより日々スキャンされています。ご利用のチームは、ご注意ください。 #CVE202621962 #Exploit #Oracle #Vulnerability #WebLogic

    Post summary

    The post confirms that CVE-2026-21962 is being actively exploited in the wild, enabling unauthenticated remote code execution through path traversal. No patch or mitigation is cited, raising immediate concern for affected organizations.

    02011161
    483 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclehttp_server12.2.1.4.0--
Apporaclehttp_server14.1.1.0.0--
Apporaclehttp_server14.1.2.0.0--
Apporacleweblogic_server_proxy_plug-in12.2.1.4.0--
Apporacleweblogic_server_proxy_plug-in14.1.1.0.0--
Apporacleweblogic_server_proxy_plug-in14.1.2.0.0--

Explore more