Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2
CISA added actively exploited Oracle flaw CVE-2026-21962 to the KEV catalog; it allows remote unauthorized access to Oracle HTTP Server and WebLogic Proxy Plug-in.
Canada's Cyber Centre updated advisory AV26-042 on Oracle's January 2026 quarterly rollup, reporting that CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 24, 2026. The flaw affects the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in in Oracle Fusion Middleware and may allow a remote attacker to obtain unauthorized access. A public proof of concept has been available since January 21, 2026, and fixes shipped in Oracle's January 20, 2026 advisory covering multiple products.