Exploited Known exploited (KEV) CVE-2026-21962

Oracle HTTP Server and WebLogic proxy plug-in access control flaw (CVE-2026-21962) — listed the year it was found, three days to fix

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Added to KEV Aug 24, 2026 Federal remediation due 2026-08-27

A component that hands web requests through to a business application platform is recorded as not applying access control properly. Numbering and listing fell in the same year, three days were allowed, and the required action goes beyond applying updates to naming a prioritization directive and requirements for preserving records.

Key facts

  • CVE IDCVE-2026-21962
  • Affected (vendor / product)Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
  • CWECWE-284
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-27 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A proxy component handing web requests to a business application platform is recorded as not applying access control properly (CWE-284).
  • Important data may be created, deleted or altered without authorization, and everything reachable through the component may become reachable.
  • Added 24 August 2026 and due 27 August 2026, an allowance of three days, with numbering and listing in the same year.
  • The required action covers not only updates but observance of a prioritization directive, requirements for preserving records, and responsibility for judging exposure.
  • Only 101 of the 1,694 records this site holds as of 2026-09-04 (6.0%) allow three days or less, and 85.1% of those were numbered and listed in the same year.

1A component that hands things through

A web server takes requests from users and passes some of them back to the business application platform behind it. What is affected here is the component that does the handing through. It is invisible from the front and its name rarely comes up. Yet because it touches both sides, access control failing there opens a path to whatever sits behind.

The catalog describes important data being created, deleted or altered without authorization, and everything reachable through the component becoming reachable.

2Not finished at apply the update

The aspectWhat most catalog entries sayWhat this entry says
The measureApply updates according to vendor instructionsApply mitigations, and observe a prioritization directive and requirements for preserving records
The assumptionApplying the fix is enoughAssessing exposure and preparing to keep records are included
Where responsibility sitsUsually unstatedStakeholders are explicitly responsible for judging each asset's exposure

Most entries end with a single line about applying vendor updates. This one does not. A directive for ordering work by risk is named, requirements for preserving records are set alongside it, and responsibility for judging exposure is written down.

The same phrasing turns up again in the eighteen-year-old entry at the end of this series. How the required action is written reflects both the weight of an entry and what is happening now.

3Three days

From listing to deadline for this entry3 daysAdded 24 August 2026, due 27 August 2026
Entries allowing three days or less among the 1,694 this site holds as of 2026-09-041016.0% of the total
Of those, entries numbered and listed in the same year8685.1% of the three-day group

The median allowance is 21 days, a value shared by 1,025 entries. Three days or less is rare, and most of that group reached the catalog within the year the identifier was issued. A short deadline, in other words, usually attaches to something happening now. As later articles show, there are exceptions.

4What it means to be listed in the year it was found

Of the 1,694 records this site holds as of 2026-09-04, 731 (43.2%) reached the catalog in the same year their identifier was issued, the largest group. Little time passed between disclosure and confirmed exploitation. Attackers read the same publications, so publication and exploitation converge. The articles that follow walk out along that interval as it widens to one year, three, seven, and eighteen.

Why it matters

The components that hand things through are invisible from the front and touch both sides at once. Access control failing there opens the path to whatever sits behind. When a required action runs past a single line into directives, record preservation and responsibility for judging exposure, it signals preparation for something that may already have happened, not merely the availability of a fix.

FAQ

What is a proxy plug-in?
A component that passes requests received by a web server back to the business application platform behind it. It sits where little of it is visible from the front.
Why only three days?
The catalog sets a deadline per entry. Allowances of three days or less cover 6.0% of entries, most of them listed within the year the identifier was issued.
Is applying an update enough?
For this entry the action includes observing a directive and requirements for preserving records alongside mitigations. Applicability should be confirmed with vendor sources and against your own environment.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Application platforms#Access control
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.