ZeroDayAlert

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Added to KEV 2026-08-24 Federal due 2026-08-27 Known ransomware use

Required action — quoted from CISA

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Oracle HTTP Server and the Oracle Weblogic Server Proxy Plug-in. The record does not specify which versions are vulnerable, nor does it detail whether this affects on-premises deployments, cloud hosting, or both. If you run either product—particularly in a role where it handles authentication or access control—you should assume exposure until you have confirmed your specific version status with Oracle.

How to check whether this touches you

  • Inventory: Search your infrastructure for instances of Oracle HTTP Server or the Oracle Weblogic Server Proxy Plug-in. Include both production and non-production environments.
  • Exposure assessment: Determine whether these services are reachable from untrusted networks (the internet, partner networks, or cloud perimeters). An internal-only deployment carries lower immediate risk but is not exempt.
  • Version fingerprinting: Connect to the affected systems and note the reported version number. Check Oracle's security advisories for the specific version cutoffs; note that some backported fixes may not change the version string.
  • Configuration review: Examine access control rules and authentication configurations in both the HTTP Server and Proxy Plug-in. Look for any rules that may have been unexpectedly altered or bypass policies.

What to do

  1. Immediately locate Oracle's patch or mitigation guidance for your version. The CISA record requires remediation by 27 August 2026; federal systems are bound by this deadline, and it is a reasonable target for all organisations.
  2. Restrict network access to the HTTP Server and Proxy Plug-in to trusted sources only whilst you prepare patches. Use firewall rules, network segmentation, or security group policies to reduce the attack surface.
  3. Enable and review logging for all access control decisions, authentication attempts, and administrative changes to the Proxy Plug-in configuration. Ensure logs are forwarded to a central, tamper-resistant store.
  4. Test patches in a non-production environment before deployment to production, even under time pressure.
  5. If no patch is available and you cannot isolate the service, escalate to your change control board and executive stakeholders. Discontinuation may be the required action if mitigations remain unavailable after vendor consultation.

If you find you were exposed

Exploitation of access control flaws typically occurs before public disclosure, so you should search logs spanning at least the past 90 days for signs of unauthorised data creation, modification, or deletion. Focus on access patterns to sensitive data and any configuration changes made outside your normal change windows. Log retention is often the limiting factor; if your retention period is shorter than three months, work with your logging team to recover archived logs or to extend retention retroactively.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-21962 is being exploited. It cannot tell you whether HTTP Server and Oracle Weblogic Server Proxy Plug-in is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →