The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a critical vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in.
The vulnerability, CVE-2026-21962, carries a CVSS score of 10.0 (Critical) and can be exploited remotely over the network without authentication. A successful attack can result in unauthorized access to or modification of critical data and potentially a complete compromise of affected systems.
The vulnerability affects several supported versions, including 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Oracle released fixes as part of its January 2026 Critical Patch Update (CPU) and strongly recommends applying security patches without delay.