logo

Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server

ID: 51b88b61-1d48-5bed-a02f-a8cdf20cb180

STIX ID: report--51b88b61-1d48-5bed-a02f-a8cdf20cb180

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Oracle discloses CVE-2026-21962 — critical WebLogic Server Proxy Plug-in vulnerability**: A CVSS 3.1 10.0, unauthenticated remote flaw in Oracle HTTP Server and WebLogic Proxy Plug-ins (Apache and IIS) can bypass security controls, fully compromise confidentiality and integrity, and potentially allow attackers to pivot into backend WebLogic clusters; affected versions are listed and Oracle provides patches and temporary network-restriction mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.