A maximum-severity Oracle WebLogic vulnerability is under attack right now. The US government’s cyber agency has given federal systems just three days to fix it. Does your business run Oracle HTTP Server or WebLogic behind a customer portal, an ERP system or an online shop? If so, this is the kind of flaw that lands on a pen-tester’s report marked “critical”.

The bug is tracked as CVE-2026-21962. It scores a full 10.0 out of 10 on the CVSS severity scale, the highest mark possible. It sits in the WebLogic Server Proxy Plug-in, used with both Apache HTTP Server and Microsoft IIS, and in Oracle HTTP Server itself. Oracle fixed it in its January 2026 Critical Patch Update. Seven months on, many firms still haven’t applied that fix. That’s why it’s back in the news.
Table of Contents
What the Oracle WebLogic vulnerability actually does
This is an access control flaw. An attacker needs no password. They need no valid session. They need no help from anyone inside your firm. All they need is a network path over HTTP. The US cyber agency, CISA, puts it plainly. A successful attack “can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data.”
In plain terms, an attacker who finds an exposed, unpatched system can read data they shouldn’t see. They can also change or delete it. The affected versions cover Apache HTTP Server builds 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, plus IIS build 12.2.1.4.0. So this Oracle WebLogic vulnerability touches a wide slice of the Oracle Fusion Middleware installed base.
Why attackers moved so fast
Researchers at CloudSEK ran a 12-day honeypot study. It started on 22 January 2026. That’s the same day exploit code for the bug went up on GitHub. Their fake WebLogic server, built to look real, logged its first attack that same day. Within days, attackers using rented virtual servers from providers including HOSTGLOBAL.PLUS and DigitalOcean were probing it non-stop. Most used off-the-shelf scanning tools, not custom-built malware.
CloudSEK’s researchers put it simply: attackers “continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.” The same traffic also hit older, well-known WebLogic holes, including CVE-2020-14882, CVE-2020-2551 and CVE-2017-10271. It hit unrelated flaws in other products too. This wasn’t one skilled attacker picking a single target. It was broad, automated scanning for any unlocked door.
Not every attacker here is acting at random, though. Threat intelligence firm SOCRadar reported in July that a China-linked group had used this same flaw against government targets. That was months after the patch shipped, and long before this week’s headlines.
The CISA deadline that isn’t really about you
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue on 24 August. It gave US federal agencies until 27 August, one of its tightest windows, to fix it. If you’re not a US federal agency, that deadline doesn’t bind you. But treat it as a warning sign, not paperwork. CISA saves its shortest deadlines for flaws it has strong proof are under live, wide attack. It doesn’t use them for theoretical risks.
For a UK business, the US compliance clock isn’t the point. The point is this: the flaw has been open to anyone, with no login needed, for seven months. Scans for it haven’t stopped since day one.
What this means for UK businesses
Start by checking whether this Oracle WebLogic vulnerability touches your business. Don’t assume it doesn’t. Oracle HTTP Server and WebLogic often sit behind other software you didn’t pick yourself. That could be an ERP system, a portal a supplier installed, or systems you inherited from a company you bought. An external attack surface review shows you what’s actually facing the internet. That’s the same thing a real attacker would check first.
If you find an affected version, apply Oracle’s January 2026 Critical Patch Update right away. While you wait for a maintenance window, lock admin access down to internal networks only. Put a web application firewall in front of anything you can’t patch today. Then check your web server, proxy and application logs back to January. Look for the kind of scanning CloudSEK found: odd requests to Oracle server paths, and repeated traffic from IP ranges you don’t know.
None of this needs exotic tools. It needs someone who knows what your business runs, checks it against the patch list, and is honest about how long “we’ll get to it” has already lasted. An unpatched Oracle WebLogic vulnerability rarely stays quiet for long once exploit code goes public. This one has had a very public seven months.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.