Critical Unauthenticated RCE in Oracle HTTP Server & WebLogic Proxy Plug‑in (CVE‑2026‑21962) Added to CISA KEV Catalog
What It Is – Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in contain an unauthenticated remote code execution flaw (CVE‑2026‑21962) with a CVSS 10.0 score. An attacker can send crafted HTTP requests to compromise the server without any credentials.
Exploitability – Actively exploited in the wild; CloudSEK’s honeypot captured attacks within weeks of disclosure. No proof‑of‑concept is required beyond a network‑reachable HTTP request.
Affected Products – Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in for Apache HTTP Server and IIS, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0.
Why It Matters for Compliance & Audit Readiness
- Continuous control monitoring must capture patch status for high‑severity vulnerabilities to satisfy SOC 2 Change Management (CC6.1) and System Operations (CC7.2) requirements.
- Evidence of timely remediation is a core audit artifact; a failure to patch a CVSS 10 flaw can be cited as a control breach during a SOC 2 audit.
- Enterprise buyers now demand proof that critical vendor components are continuously assessed and that remediation evidence is stored in a tamper‑evident repository.
Recommended Actions
- Deploy Oracle’s security patch for the listed versions immediately.
- Update your asset inventory to flag any servers running the vulnerable components.
- Integrate automated vulnerability scanning with continuous evidence collection to map remediation to SOC 2 controls.
- Verify network segmentation to limit external access to the proxy plug‑in.
Source: Security Affairs