Vulnerability
Published 2026-08-24
Verified 2026-09-19

Oracle HTTP Server / WebLogic proxy plug-in access control (CVE-2026-21962)

Oracle Critical Patch Update (January 2026) lists CVE-2026-21962 in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. Supported affected versions: 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. NVD rates CVSS 10.0. Unauthenticated network access via HTTP. Apply the January 2026 CPU for the plug-in builds you run.

Product
Oracle HTTP Server / WebLogic Server Proxy Plug-in
Versions
12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
CVSS
(CVSS 3.1, Oracle CNA via NVD)
Exploited in Australia?
unknown
Patch to
January 2026 CPU

Primary: Oracle CPU January 2026 · Vendor: NVD · CVE: CVE-2026-21962

vulnerabilities