Full Report
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
Analysis Summary
# Vulnerability: Oracle HTTP Server and WebLogic Server Proxy Plug-in Improper Access Control
## CVE Details
- **CVE ID:** CVE-2026-21962
- **CVSS Score:** 10.0 (Critical)
- **CWE:** CWE-284 (Improper Access Control)
## Affected Systems
- **Products:** Oracle HTTP Server and WebLogic Server Proxy Plug-in
- **Versions:** 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0
- **Configurations:** Systems running on Windows Virtual Machines (VMs) are specifically highlighted as the primary target in current exploitation trends.
## Vulnerability Description
CVE-2026-21962 is a maximum-severity improper access control flaw. The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the Oracle HTTP Server or WebLogic Server Proxy Plug-in. Technically, the flaw permits unauthorized creation, deletion, or modification of critical data and can result in "complete access" to all data stored on the affected system.
## Exploitation
- **Status:** Exploited in the wild. Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on August 24, 2026.
- **Complexity:** Low
- **Attack Vector:** Network
- **PoC Availability:** Publicly available (released shortly after January 2026 disclosure).
## Impact
- **Confidentiality:** Critical (Complete access to all data)
- **Integrity:** Critical (Unauthorized modification/deletion of data)
- **Availability:** Critical (Potential for total system compromise)
## Remediation
### Patches
Oracle released patches for this vulnerability as part of the **January 20, 2026, Critical Patch Update (CPU)**.
- Organizations should update to the latest patched versions of Oracle HTTP Server and WebLogic Server Proxy Plug-in (versions exceeding 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 or applying the specific security patches provided by Oracle).
### Workarounds
- No specific software workarounds were provided in the article; immediate patching is the mandated course of action for FCEB agencies within a three-day window.
## Detection
- **Indicators of Compromise:**
- High-volume, automated scanning traffic.
- User-agent strings associated with automated tools such as `libredtail-http` and the `Nmap Scripting Engine`.
- **Detection methods and tools:**
- Monitoring HTTP logs for unauthorized attempts to access administrative or proxy plug-in endpoints.
- Deployment of honeypots to identify "spray and pray" scanning patterns targeting WebLogic-specific vulnerabilities.
## References
- **Vendor Advisory:** hxxps[://]www[.]oracle[.]com/security-alerts/cpujan2026[.]html
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **CISA Directive:** hxxps[://]www[.]cisa[.]gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- **CloudSEK Analysis:** hxxps[://]www[.]cloudsek[.]com/blog/honey-for-hackers-a-study-of-attacks-targeting-the-recent-cve-2026-21962-and-other-critical-weblogic-vulnerabilities-on-a-high-interactive-oracle-honeypot