CVE-2026-21962
published 2026-01-20CVE-2026-21962: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for…
PriorityP193critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
42.66%
98.6th percentile
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | weblogic_server_proxy_plug-in | — | — |
| oracle | weblogic_server_proxy_plug-in | — | — |
| oracle | weblogic_server_proxy_plug-in | — | — |
Detection & IOCsextracted from sources · hover to see the quote
path/bea_wls_internal/ProxyServlet
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)"; flow:established,to_server; http.uri; content:"/bea_wls_internal/ProxyServlet"; fast_pattern; pcre:"/(?:\x2e|\x252[eE]){2}(?:\x3b|\x253[bB])(?:\x2f|\x252[fF])bea_wls_internal\x2fProxyServlet/U"; http.header; content:"|3b|y21kO"; reference:url,isc.sans.edu/diary/Odd+WebLogic+Request+Possible+CVE202621962+Exploit+Attempt+or+AI+Slop/32662; reference:cve,2026-21962; classtype:web-application-attack; sid:2067187; rev:1; metadata:affected_product Oracle_WebLogic, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_29, cve CVE_2026_21962, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence Medium, signature_severity Major, tag Exploit, updated_at 2026_01_29, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)bytes
|3b|y21kO
- →The Snort/ET rule targets path traversal encoding variants in the URI: double-dot sequences encoded as \x2e or \x252e, semicolons as \x3b or \x253b, and slashes as \x2f or \x252f, all preceding /bea_wls_internal/ProxyServlet — look for URL-encoded path traversal attempts to this endpoint.
- →The dominant exploitation source IP (193.24.123.42, PROSPERO OOO AS200593) was observed conducting 2,902 exploitation sessions against Oracle WebLogic CVE-2026-21962 and rotates through 300+ unique user agent strings — do not rely solely on user-agent for detection. ↗
- →Exploitation is unauthenticated and delivered over HTTP — monitor perimeter HTTP traffic to WebLogic proxy plug-in endpoints without requiring authentication context. ↗
- →CloudSEK reported automated exploitation attempts shortly after exploit code became publicly available — treat any anomalous traffic to /bea_wls_internal/ProxyServlet as high-priority. ↗
- ·The IIS plug-in variant is only affected on version 12.2.1.4.0; the Apache HTTP Server plug-in is affected on 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 — scope detection rules accordingly. ↗
- ·Scope change is confirmed: while the vulnerability is in the proxy plug-in, successful exploitation can significantly impact additional backend products beyond Oracle HTTP Server itself. ↗
- ·Published IOC lists for concurrent campaigns were found to point to shared VPN exit nodes scanning for Oracle WebLogic rather than the actual exploitation source — validate IOC lists against live telemetry before blocking. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
vulncheck10.0CRITICAL
vendor_oracle10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wp9-cf5h-v2g5: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl
ghsa_unreviewed·2026-01-21
CVE-2026-21962 [CRITICAL] CWE-284 GHSA-4wp9-cf5h-v2g5: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Pl
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server
VulnCheck
Oracle http_server Improper Access Control
vulncheck·2026·CVSS 10.0
CVE-2026-21962 [CRITICAL] Oracle http_server Improper Access Control
Oracle http_server Improper Access Control
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all
VulnCheck
Oracle Fusion Middleware Unspecified Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-2551 [CRITICAL] Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
Affected: Oracle Fusion Middleware
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://blog.eclecticiq.com/chinese-threat-actor-used-modified-cobalt-strike-variant-to-attack-taiwanese-critical-infrastructure; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/09055246/Modern-Asian-APT-groups-TTPs_report_eng.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://media.kaspersky
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability
vulncheck·2020·CVSS 7.2
CVE-2020-14883 [HIGH] Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html; https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/initial-access-techniques-in-kubernetes-environments-used-by/ba-p/3697975; https://cisa.gov/news-events/cybersecurity-advisories/aa23-215a; https://www.microsoft.com/content/dam/microsoft/final/en-us/microsoft
VulnCheck
Oracle WebLogic Server Remote Code Execution Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-14882 [CRITICAL] Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.vulncheck.com/v3/index/sans-dshield?cve=CVE-2020-14882; https://blog.netlab.360.com/necro-upgrades-again-using-tor-dynamic-domain-dga-and-aiming-at-both-windows-linux/; https://blogs.juniper.net/en-us/threat-research/sysrv-botnet-expands-and-gains-persistence; https://www.lacework.com/blog/sysrv-hello-expands-infrastructure/; https://www.bleepingcomputer.com/news/security/new-cryptomining-malware-builds-an-army-of-windows-linux-bo
VulnCheck
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://unit42.paloaltonetworks.com/malware-used-by-rocke-group-evolves-to-evade-detection-by-cloud-security-products/; https://blog.netlab.360.com/botnet-muhstik-is-actively-exploiting-drupal-cve-2018-7600-in-a-worm-style-en/; https://isc.sans.edu/diary/Criminals+Dont+Read+Instructions+or+Use+Strong+Passwords/23850; https://blog.talosintelligence.com/2018/08/rocke-champion-of-monero-miners.html; https://www.lacework.com/blog/elf-of-the-month-new-lucky-ransomware-sample
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS — CVE-2026-21962
vendor_oracle·2026-01-15·CVSS 10.0
CVE-2026-21962 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS — CVE-2026-21962
Oracle Oracle Fusion Middleware Risk Matrix: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS vulnerability
CVE: CVE-2026-21962
CVSS: 10.0
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Suricata
ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)
suricata·2026-01-29·CVSS 10.0
CVE-2026-21962 [CRITICAL] ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)
ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)"; flow:established,to_server; http.uri; content:"/bea_wls_internal/ProxyServlet"; fast_pattern; pcre:"/(?:\x2e|\x252[eE]){2}(?:\x3b|\x253[bB])(?:\x2f|\x252[fF])bea_wls_internal\x2fProxyServlet/U"; http.header; content:"|3b|y21kO"; reference:url,isc.sans.edu/diary/Odd+WebLogic+Request+Possible+CVE202621962+Exploit+Attempt+or+AI+Slop/32662; reference:cve,2026-21962; classtype:web-application-attack; sid:2067187; rev:1; metadata:affected_product Oracle_WebLogic, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_29, cve CVE_2026_21962, deploy
No public exploits indexed.
Hackernews
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
blogs_hackernews·2026-06-02·CVSS 7.5
CVE-2024-21182 [HIGH] Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities ( KEV ) Catalog, based on evidence of active exploitation.
The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was patched by Oracle in July 2024.
"Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Bleepingcomputer
One threat actor responsible for 83% of recent Ivanti RCE attacks
blogs_bleepingcomputer·2026-02-14·CVSS 9.8
CVE-2026-1286 [CRITICAL] One threat actor responsible for 83% of recent Ivanti RCE attacks
## One threat actor responsible for 83% of recent Ivanti RCE attacks
## Bill Toulas
Update: The article initially listed the wrong CVEs. This has now been corrected to list the CVEs: CVE-2026-1286 and CVE-2026-1340
Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340.
The security issues have been flagged as actively exploited in zero-day attacks in Ivanti's security advisory, where the company also announced hotfixes.
Both flaws received a critical severity rating and allow an attacker to inject code without authentication, leading to remote code execution (RCE) on vulnerable systems.
A single IP address h
Greynoiseio
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
blogs_greynoiseio·2026-02-10
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Wiz
CVE-2026-21962 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-21962 [CRITICAL] CVE-2026-21962 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21962 :
Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerability analysis and mitigation
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthori
2026-01-20
Published
Exploited in the wild