๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Summary
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability (a flaw in the rules that decide who can access what data) that allows attackers to unauthorized create, delete, or modify critical data, or gain complete access to all data these systems can reach. This vulnerability is currently being exploited by attackers in the real world.
Solution / Mitigation
Apply mitigations per vendor instructions (Oracle), follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The due date for remediation is 2026-08-27. For detailed instructions, see Oracle's security alert at https://www.oracle.com/security-alerts/cpujan2026.html
Vulnerability Details
EPSS: 43.2%
Yes
๐ฅ Actively Exploited
August 23, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21962
First tracked: August 24, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%