Active Exploitation of Vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In
26 August 2026
Attackers are exploiting a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In to access, change or delete critical data. Patch immediately.
Last updated on 2 Sep 2026 to include Indicators of Compromise
Background
Oracle has released security updates to address a critical vulnerability (CVE-2026-21962) affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10.0 out of 10.
Impact
The vulnerability lies in the WebLogic Server Proxy Plug-in for Apache HTTP Server and the WebLogic Server Proxy Plug-in for IIS, and is easily exploitable. An unauthenticated attacker could compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, gaining unauthorised access to critical data or complete access to all data accessible to these products, including the ability to create, delete or modify.
Known Exploitation
This vulnerability is reportedly being actively exploited, and a proof-of-concept exploit is publicly available.
Affected Products
The vulnerability affects the following products:
Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0
Oracle WebLogic Server Proxy Plug-In versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0
Indicators of Compromise
Indicators of Compromise (IOCs) from a campaign targeting this vulnerability can be found at: https://socradar.io/blog/snowlight-government-chinese-campaign/ (opens in new tab).
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.oracle.com/security-alerts/cpujan2026.html (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-21962 (opens in new tab)
https://socradar.io/blog/snowlight-government-chinese-campaign/ (opens in new tab)
