CVE-2026-21962Critical· 10.0▾ Hadal⚠ Exploited in the wildPoC availableVulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 8.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Federal remediation due Aug 27, 2026
43%
10 GitHub repos
Added to the CISA catalog on Aug 24, 2026. Federal remediation due Aug 27, 2026. View catalog ↗
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
http_server = 12.2.1.4.0http_server = 14.1.1.0.0http_server = 14.1.2.0.0weblogic_server_proxy_plug-in = 12.2.1.4.0weblogic_server_proxy_plug-in = 14.1.1.0.0weblogic_server_proxy_plug-in = 14.1.2.0.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2012-4681Critical· 9.8Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) usi…
CVE-2012-1723Critical· 9.8Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidential…
CVE-2026-60438Critical· 9.1Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl)
CVE-2026-60363Critical· 9.8Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin)
CVE-2026-42536High· 7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…
CVE-2026-87250High· 7.6Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)