CVE-2026-21962

CVSS 10.0 · CRITICAL
Exploited in the wild
Remediation overdue by 29 days
EPSS p99
Higher than 99% of all CVEs — imminent exploitation likely.
Patch available
Vendor advisory or patch linked

Published 1/20/2026 · updated 8/25/2026 · CWE-284

Share
Get asset-aware triage

Summary

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS 10.0 — CRITICAL

10.0 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS exploitation probability

43.2%

Percentile p99 — Higher than 99% of all CVEs — imminent exploitation likely.

Affected products

2 vendor/product entries
  • Oracle Http Serverv12.2.1.4.0, v14.1.1.0.0, v14.1.2.0.0
  • Oracle Weblogic Server Proxy Plug Inv12.2.1.4.0, v14.1.1.0.0, v14.1.2.0.0
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Jan 20, 2026 · Disclosed / published in NVD
  2. Aug 24, 2026 · Added to CISA KEV catalog
  3. Aug 25, 2026 · Intel last updated
  4. Aug 27, 2026 · CISA remediation deadline

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 30 days ago
  • CVE.org· 30 days ago
  • FIRST EPSS· 30 days ago
  • CISA KEV· 12 days ago
  • OSV· 30 days ago

Listed in CISA KEV

Added 2026-08-24 · Remediation overdue by 29 days.

References

Unlock the full report

See how CVE-2026-21962 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.