Skip to content
COOEY

EXPOSURES › CVE-2026-21962

CVE-2026-21962

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-21962 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatcheddata-breach

Oracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access.

This improper access control vulnerability in Oracle HTTP Server and Weblogic Server Proxy Plug-in allows attackers to create, delete, or modify critical data and gain complete access to all accessible data. For DIB organizations, this means unpatched Oracle infrastructure could lead to massive data breaches and compliance failures under NIST 800-171. Organizations must immediately patch Oracle HTTP Server and Weblogic Server Proxy Plug-in to prevent unauthorized data exposure and maintain compliance.

Shame score — A high-severity improper access control flaw in widely deployed Oracle products that allows complete data access and manipulation, representing a negligent failure to secure critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized