Web_Logo
Remote Support
Security Alert: Oracle WebLogic Flaw Actively Exploited
Home » Security Alerts  »  Security Alert: Oracle WebLogic Flaw Actively Exploited

Security Alert: Oracle WebLogic Flaw Actively Exploited

A maximum severity flaw in Oracle HTTP Server and WebLogic Server is being actively exploited by attackers, and the US government's cyber security agency has told its own agencies to patch it today.

  • What it is: CVE-2026-21962 is a flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in that lets an attacker access, create, delete or modify data without logging in. It carries the maximum possible severity score of 10 out of 10.
  • Who is affected: Any business running Oracle HTTP Server or Oracle WebLogic Server, particularly if the affected proxy plug-in is exposed to the internet.
  • What the risk is: The flaw has reportedly been exploited since January 2026, including by a state-linked group targeting organisations worldwide. Successful attacks can hand over complete access to server data with no login required.
  • What action is needed: Oracle released a fix for this issue in its January 2026 security updates. If you run Oracle HTTP Server or WebLogic, confirm that update has been applied. If not, treat it as an immediate priority.

We recommend checking your Oracle patch level today rather than waiting for your next scheduled review.