Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
CISA KEV · ACTIVELY EXPLOITED
CRITICAL severity

CVE-2026-21962 — Http Server

CRITICAL

CVE-2026-21962 is a critical-severity (CVSS 10) CWE-284 vulnerability in oracle http server. It is in CISA's Known Exploited Vulnerabilities catalog (added 2026-08-24) — treat it as actively exploited and patch now. No vendor fix is recorded yet; mitigation options are listed below.

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic…

Published
Updated
Affected
2 products
Patched
See advisory
Exploits
5 known
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, CISA KEV, FIRST.org (EPSS)

Exploitation Status

Actively exploited in the wild

  • Confirmed by CISA's Known Exploited Vulnerabilities catalog on 2026-08-24. Federal agencies were required to remediate by 2026-08-27.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • A successful exploit gives an attacker total control of the affected component, not partial access.

Exploitation and automatability from CISA (KEV catalog and SSVC triage) for CVE-2026-21962.

EPSS Exploitation Probability

via FIRST.org ↗
73.2%probability of exploitation in next 30 days
Very High Risk+2.28%
Lower risk than most CVEs99th percentile — riskier than 99% of all scored CVEsHighest risk
0.00%31.7%63.4%95.1%0.0%73.2%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-21962 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).

Where this sits among everything scored

Of 384,534 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Affected Products

2 products · 6 configurations
Application
http serveroracle
3 versions
12.2.1.4.014.1.1.0.014.1.2.0.0
Application
weblogic server proxy plug-inoracle
3 versions
12.2.1.4.014.1.1.0.014.1.2.0.0
Exploits & PoCs
5

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every oracle http server deployment and check each version against the affected-products list above.

  2. Remediation status

    No patch has shipped for CVE-2026-21962 yet — track the oracle http server advisory for a fixed release and apply the workarounds below in the meantime.

  3. Mitigate without a patch

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional
O3 Security · Runtime Protection

Is CVE-2026-21962 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

Actively Exploited: CVE-2026-21962: Http Server (Critical 10)