(TLP:CLEAR) Vulnerability Notification – Oracle HTTP Server & WebLogic Proxy Plug-in Actively Exploited
Created: Wednesday, August 26, 2026 - 9:24
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using Oracle HTTP Server or the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server or Microsoft IIS. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: A critical improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited in the wild. Tracked as CVE-2026-21962 (CVSS 10.0), the vulnerability allows an unauthenticated remote attacker with HTTP access to send crafted requests to the affected proxy components and bypass intended access controls, potentially enabling unauthorized creation, deletion, or modification of critical data and access to backend WebLogic systems.
Yesterday, CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.
Analyst Note: Because the WebLogic Server Proxy Plug-in and Oracle HTTP Server typically sit at the network perimeter—often in DMZ environments front-ending backend application servers—a successful bypass could give attackers a foothold inside trusted network environments, potentially enabling lateral movement, credential theft, or access to systems that support OT environments.
WaterISAC strongly encourages members to determine whether Oracle HTTP Server or the WebLogic Server Proxy Plug-in is deployed within their environment, review Oracle’s January 2026 advisory, and apply the fixes immediately.
Additional Reading
