LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 24, 2026
Elevated⚠ Actively exploited (CISA KEV)
Elevated
Severity
Active
CISA KEV
No
Ransomware use
Aug 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on Aug 24, 2026, with a federal patch deadline of Aug 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data…

CVE-2026-21962 is an improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. In plain terms, the software does not correctly enforce who is allowed to create, change, delete, or read certain data it can reach. CISA describes the impact as unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to data accessible through these components. For IT and security teams, that means a path from a network-facing web tier into sensitive application or configuration data if the flaw is reachable and unmitigated. Confirm affected releases, fixed builds, and exact conditions only against Oracle’s advisory.

This matters because HTTP Server and the WebLogic proxy plug-in often sit at the edge of Java application stacks, terminating or forwarding HTTP(S) traffic. Weak access control there can expand an attacker’s reach beyond a single virtual host or proxy rule set. Ransomware use is not documented for this CVE in the provided facts; treat prioritization by exposure and data sensitivity rather than by unstated threat branding.

How it works

The weakness is classified as CWE-284 (Improper Access Control). Products in this class fail to apply the intended authorization checks before allowing an operation on a resource. An attacker who can reach the vulnerable component—typically over HTTP(S) to the server or plug-in—may perform actions or read data that should have been denied by policy. The CISA summary frames the outcome as unauthorized create/delete/modify access to critical data and unauthorized or complete access to data the Oracle HTTP Server and WebLogic Server Proxy Plug-in can reach.

Do not assume a specific request path, header, or authentication bypass without the vendor write-up. In general, abuse of improper access control on a reverse-proxy or HTTP front end looks like crafted or unexpected requests that the plug-in or server handles without enforcing the same controls the backend application expects. Exact exploit mechanics, preconditions (authenticated vs. unauthenticated), and scope must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in commonly appear in front of WebLogic and related Oracle middleware: reverse proxy, load-balancing, SSL termination, and routing to application servers. Inventory anywhere you run Oracle HTTP Server (standalone or as part of Fusion Middleware-style deployments) and any WebLogic proxy plug-in modules loaded into supported HTTP servers.

How to remediate

Patch first. Apply the vendor updates and mitigations named in Oracle’s advisory for CVE-2026-21962 for both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in as applicable. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Reduce reachability and blast radius until the vendor fix is installed.

If your data may have been exposed

Actively exploited access-control flaws on internet-facing middleware can lead to unauthorized data access or modification and, in broader incidents, to follow-on compromise. If logs or detections suggest abuse, preserve evidence, assess which data the HTTP Server or plug-in could reach, involve your incident response process, and follow legal/regulatory notification duties as applicable. Ransomware use is not documented in the facts for this CVE. As a routine hygiene step, individuals and admins can run a free exposure scan of their email addresses against known breach datasets to see whether those identities already appear in public breach collections, then prioritize password resets and MFA where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in
WeaknessCWE-284
Added to CISA KEVAug 24, 2026
Federal patch deadlineAug 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities