cbcvebase.
CVE-2026-21962
published 2026-01-20

CVE-2026-21962: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for…

PriorityP193critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
42.66%
98.6th percentile
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Affected

6 ranges
VendorProductVersion rangeFixed in
oraclehttp_server
oraclehttp_server
oraclehttp_server
oracleweblogic_server_proxy_plug-in
oracleweblogic_server_proxy_plug-in
oracleweblogic_server_proxy_plug-in

Detection & IOCsextracted from sources · hover to see the quote

path/bea_wls_internal/ProxyServlet
port7001
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Oracle WebLogic Server Proxy Plug-in Authentication Bypass (CVE-2026-21962)"; flow:established,to_server; http.uri; content:"/bea_wls_internal/ProxyServlet"; fast_pattern; pcre:"/(?:\x2e|\x252[eE]){2}(?:\x3b|\x253[bB])(?:\x2f|\x252[fF])bea_wls_internal\x2fProxyServlet/U"; http.header; content:"|3b|y21kO"; reference:url,isc.sans.edu/diary/Odd+WebLogic+Request+Possible+CVE202621962+Exploit+Attempt+or+AI+Slop/32662; reference:cve,2026-21962; classtype:web-application-attack; sid:2067187; rev:1; metadata:affected_product Oracle_WebLogic, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_29, cve CVE_2026_21962, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence Medium, signature_severity Major, tag Exploit, updated_at 2026_01_29, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
|3b|y21kO
  • The Snort/ET rule targets path traversal encoding variants in the URI: double-dot sequences encoded as \x2e or \x252e, semicolons as \x3b or \x253b, and slashes as \x2f or \x252f, all preceding /bea_wls_internal/ProxyServlet — look for URL-encoded path traversal attempts to this endpoint.
  • The dominant exploitation source IP (193.24.123.42, PROSPERO OOO AS200593) was observed conducting 2,902 exploitation sessions against Oracle WebLogic CVE-2026-21962 and rotates through 300+ unique user agent strings — do not rely solely on user-agent for detection.
  • Exploitation is unauthenticated and delivered over HTTP — monitor perimeter HTTP traffic to WebLogic proxy plug-in endpoints without requiring authentication context.
  • CloudSEK reported automated exploitation attempts shortly after exploit code became publicly available — treat any anomalous traffic to /bea_wls_internal/ProxyServlet as high-priority.
  • ·The IIS plug-in variant is only affected on version 12.2.1.4.0; the Apache HTTP Server plug-in is affected on 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 — scope detection rules accordingly.
  • ·Scope change is confirmed: while the vulnerability is in the proxy plug-in, successful exploitation can significantly impact additional backend products beyond Oracle HTTP Server itself.
  • ·Published IOC lists for concurrent campaigns were found to point to shared VPN exit nodes scanning for Oracle WebLogic rather than the actual exploitation source — validate IOC lists against live telemetry before blocking.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
vulncheck10.0CRITICAL
vendor_oracle10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.