Critical Actively exploited
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
What this means
- Weakness
- Access control is applied incorrectly, leaving a protected resource reachable without the required rights.
- Likelihood
- Exploitation is not hypothetical: CISA has observed it in the wild.
What to doTop priority: CISA sets the remediation deadline at 27 August 2026.
Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.