← All CVEs NewScan detects
criticalKEV

CVE-2026-21962

WebLogic Server Proxy Plug-in for Apache HTTP Server: unauthenticated remote access to critical data (CVSS 10.0, exploited in the wild)

Severity
critical
Affected product
Oracle WebLogic Server
Affected versions
Oracle WebLogic Server all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
43% chance of exploitation in the next 30 days
Added to NewScan
2026-08-25
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Oracle WebLogic Server appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-25 - the day's only KEV entry, CVSS 10.0, EPSS 43%, and the subject of two independent feed stories the same morning (The Hacker News and BleepingComputer both led on an actively exploited Oracle WebLogic flaw). The vulnerable component is the Weblogic Server Proxy Plug-in for Apache HTTP Server, the mod_wl front end that Oracle HTTP Server and the Oracle E-Business Suite web tier both sit behind, so the reachable surface is the HTTP front door rather than WebLogic's own listener. NO VERSION GATE, and that is deliberate rather than lazy: this follows the Oracle E-Business Suite CVE-2025-61882 stance in this same pack - neither the plug-in nor the OHS front door publishes its Fusion Middleware release anonymously, so the honest output is an advisory observation on a fingerprinted product and the operator confirms the patch level. WHAT THIS ROW DOES AND DOES NOT CLAIM: it fires where the appliances.json Oracle WebLogic Server fingerprint fires (the x-oracle-dms-ecid header or a `WebLogic Server` body marker), which an install that exposes the console or an error page does emit; it will NOT fire on a hardened deployment whose Apache front end reveals nothing, because we do not fingerprint Oracle HTTP Server at all - `Server: Oracle-HTTP-Server/12.x` is absent from tech_signatures header.server. That gap is the higher-value follow-up and is written up in docs/backlog.md rather than guessed at here: the OHS banner could not be measured today (no public image, and the vulhub corpus has no OHS or proxy-plug-in env - its weblogic envs are the WLS listener itself), and an unmeasured banner regex is exactly the aspirational row that passes a synthetic test and finds nothing in the field.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →