Vulnerability
Published 2026-08-24
Verified 2026-09-19
Oracle HTTP Server / WebLogic proxy plug-in access control (CVE-2026-21962)
Oracle Critical Patch Update (January 2026) lists CVE-2026-21962 in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. Supported affected versions: 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. NVD rates CVSS 10.0. Unauthenticated network access via HTTP. Apply the January 2026 CPU for the plug-in builds you run.
- Product
- Oracle HTTP Server / WebLogic Server Proxy Plug-in
- Versions
- 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
- CVSS
- (CVSS 3.1, Oracle CNA via NVD)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- January 2026 CPU
Primary: Oracle CPU January 2026 · Vendor: NVD · CVE: CVE-2026-21962
