Hackers exploit a maximum severity Oracle server flaw

CISA has added a maximum severity Oracle flaw to its catalog of vulnerabilities under active attack. CVE-2026-21962 carries a CVSS base score of 10.0, the highest the scale goes, and an attacker needs no password and no help from a user to reach it.

The bug sits in Oracle HTTP Server and in the Oracle WebLogic Server Proxy Plug-in, the component organizations put in front of WebLogic so that Apache HTTP Server or Microsoft IIS can hand web traffic to it. That is deliberately internet facing infrastructure, which is what makes a 10.0 there worse than a 10.0 somewhere quiet.

What the published record actually says

Oracle classifies the issue as improper access control, exploitable by an unauthenticated attacker with network access over HTTP, and calls it easily exploitable. Successful attacks can result in unauthorized creation, deletion or modification of critical data, and unauthorized access to all data the affected component can reach. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N) also records a scope change, meaning the impact is not confined to the vulnerable component itself. Availability is untouched, so this is a confidentiality and integrity problem rather than a crash.

Affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, with one exception: for the IIS build of the proxy plug-in, only 12.2.1.4.0 is listed. Neither CISA's alert nor the CVE record says how the flaw is being exploited, by whom, or against what, and Oracle's own advisory carries the remediation detail. Anything beyond that is not in the published record.

Old bug, new urgency

This is not a fresh disclosure. The CVE record dates from January 20, 2026, so defenders have had months of notice rather than days, and the EPSS model already put the probability of exploitation activity in the next 30 days at roughly 43 percent before this listing. What changed on August 24 is CISA's assessment, based on evidence of active exploitation, that somebody is now using it.

Patch it, then find the plug-ins you forgot

Apply Oracle's update for the affected versions. The harder half of the job is inventory, because a proxy plug-in lives on the Apache or IIS box in front of WebLogic, is often owned by a different team, and so tends not to appear on the WebLogic asset list at all. Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of KEV entries on publicly exposed assets, and to check whether attackers compromised the system before the patch went on. That second step is the one everybody else should copy: a bug this old and this exposed may already have been used against you.

Oracle middleware is a repeat visitor to this catalog. IntelFusions covered the last set of Oracle flaws to come under active attack in July, and the 943 fix quarterly update that landed this month. CISA published the listing in its August 24 catalog update.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions