Security Alert: Critical Oracle HTTP Server and WebLogic Server Vulnerability Under Active Exploitation (CVE-2026-21962
A critical vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in, identified as CVE-2026-21962 (CVSS 10.0), is being actively exploited. Oracle released security updates for the vulnerability in January 2026, but systems that have not been updated remain at risk of unauthorized access to critical data and system resources.
Affected Systems:
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in: Versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.
Security Risks
Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to protected data and system resources, including the ability to create, modify, or delete critical data.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
Apply the Oracle security updates released in January 2026 to affected Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in systems as soon as possible to address the vulnerability and reduce the risk of exploitation.
Before applying updates, ensure that a current and verified backup is available and can be restored if needed.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.