CVE-2026-21962 · Critical · CISA KEV

Oracle HTTP Server Proxy Plug-in: Critical Improper Access Control Vulnerability (KEV)

Threat Engine Auto-Feed · data current as of 2026-08-25

CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, is actively exploited in the wild, as confirmed by its inclusion in CISA KEV. This flaw allows unauthorized creation, deletion, or modification of critical data, and complete access to all accessible data. Its high EPSS score (99th percentile) indicates a significant likelihood of future exploitation.

  • CVSS:
  • EPSS percentile: 0.9862
  • Exploitation pressure: 84/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 99th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

Improper access control means that the software does not correctly restrict who can perform certain actions or access specific resources. This can allow an attacker to bypass security checks and gain unauthorized permissions to view, change, or delete sensitive information, or even take full control over data that should be protected.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
  • Financial services organizations (targeted by FIN7, LockBit affiliates, APT38)
  • Technology sector organizations (targeted by APT29, Scattered Spider)

Misconfigurations that escalate it

  • Lack of robust access control policies
  • Insufficient monitoring of proxy plug-in activity
  • Outdated or unpatched Oracle HTTP Server and Weblogic Server Proxy Plug-in installations

High-impact scenarios

  • Unauthorized creation, deletion, or modification of critical data
  • Complete unauthorized access to all data accessible by the Oracle HTTP Server and Proxy Plug-in
  • Data exfiltration and integrity compromise, particularly for sensitive financial or technological data

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor logs for unusual access patterns or unauthorized data modifications related to Oracle HTTP Server and Weblogic Server Proxy Plug-in.
  • Implement robust file integrity monitoring on critical data stores managed or accessed by the affected components.

Contain

  • Isolate affected systems from the network if unauthorized activity is detected.
  • Review and tighten access control lists (ACLs) for all resources managed by the Oracle HTTP Server and Proxy Plug-in.

Patch

  • Apply vendor-provided security patches for Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in immediately upon release.

Frontier verdict — Critical

This critical vulnerability requires immediate attention due to active exploitation (CISA KEV) and high predicted exploitability (EPSS 99th percentile), posing a severe risk of data compromise.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.