Threat reportVulnerabilityTL-2026-0283
CVE-2026-21962: Oracle WebLogic Server & HTTP Server Unauthenticated RCE via Proxy Plug-in Path Traversal (CVSS 10.0) — Active Exploitation
CVE-2026-21962 (TL-2026-0283), also tracked as Ashwesker, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-25. It has no confirmed attribution, affects Oracle Oracle HTTP Server, references 1 CVE (CVE-2026-21962), maps to 11 MITRE ATT&CK techniques (T1027, T1059, T1071), and is covered by 9 detection rules and 20 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0283
- Threat ID
- TL-2026-0283
- Also known as
- Ashwesker
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, financial, government, healthcare, energy, telecommunications, manufacturing, education
- Target regions
- Global, North America, Europe, Middle East, Africa
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in CVE-2026-21962
Malware and tooling: Ashwesker CVE-2026-21962 PoC, Nuclei
How CVE-2026-21962 works
Critical unauthenticated remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) exploitable via HTTP path traversal to the internal ProxyServlet endpoint. Public PoC released January 22, 2026 with same-day active exploitation confirmed. Widespread scanning observed across commodity threat actors leveraging automated tooling.
CVE-2026-21962 is a critical unauthenticated remote code execution vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in components within Oracle Fusion Middleware. The vulnerability carries the maximum CVSS 3.1 base score of 10.0 with a Changed scope, indicating compromise extends beyond the vulnerable component.
The flaw resides in the proxy plug-in's improper input validation of HTTP request paths. Attackers craft HTTP GET requests using path traversal sequences (specifically the '..;' notation) to reach internal WebLogic endpoints that should not be externally accessible. The primary attack vectors target:
- /_proxy//weblogic/..;/bea_wls_internal/ProxyServlet - /wl_proxy//weblogic/..;/bea_wls_internal/ProxyServlet
By accessing the internal ProxyServlet through these traversal paths, unauthenticated attackers gain the ability to execute arbitrary operating system commands on the underlying server. The vulnerability requires no authentication, no user interaction, and has low attack complexity — making it trivially exploitable at scale.
Affected products include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, as well as WebLogic Server Proxy Plug-in for Apache HTTP Server (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and WebLogic Server Proxy Plug-in for Microsoft IIS (version 12.2.1.4.0).
A proof-of-concept exploit was published on GitHub (boroeurnprach/Ashwesker-CVE-2026-21962) on January 22, 2026, providing both a Python exploitation script and a Nuclei scanning template. Active exploitation was observed within hours of PoC release — the first attack was recorded at 13:30:50 UTC on January 22, 2026 from IP 67.213.118.179 (Vultr Holdings LLC infrastructure).
CloudSEK deployed a high-interaction Oracle WebLogic honeypot running the vulnerable version 14.1.1.0.0 and observed a 12-day exploitation campaign from January 22 to February 3, 2026. Key findings:
- Scanning tools dominated traffic: libredtail-http (1,012 requests from 21 IPs), Nmap Scripting Engine (664 requests from 5 IPs), Go-http-client (253 requests from 64 IPs), and python-requests (43 requests from 24 IPs). - Infrastructure analysis revealed DigitalOcean (AS14061) as the most diverse source with 28 unique IPs and 461 requests, while HOSTGLOBAL.PLUS LTD (AS202306) generated the highest request volume (625 requests from 4 IPs). - The libredtail-http user agent pattern suggests persistent, large-scale botnet-driven scanning operations. - Attackers also exploited legacy WebLogic CVEs alongside CVE-2026-21962, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT Deserialization).
Oracle addressed this vulnerability in the January 2026 Critical Patch Update. The CWE classification is CWE-284 (Improper Access Control). Despite the CVSS 10.0 score, the EPSS probability remains relatively low at 0.00031, though real-world exploitation data clearly contradicts this assessment given confirmed active exploitation.
MITRE ATT&CK techniques used in TL-2026-0283
defense-evasion
T1027 Obfuscated Files or Information
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
command-and-control
T1071 Application Layer Protocol
discovery
T1082 System Information Discovery
initial-access
T1190 Exploit Public-Facing Application
persistence
T1505 Server Software Component
impact
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
reconnaissance
Affected products and versions in CVE-2026-21962
- Oracle — Oracle HTTP Server
Vulnerable versions: 12.2.1.4.0; 14.1.1.0.0; 14.1.2.0.0
Fixed in: January 2026 CPU patched versions - Oracle — WebLogic Server Proxy Plug-in for Apache HTTP Server
Vulnerable versions: 12.2.1.4.0; 14.1.1.0.0; 14.1.2.0.0
Fixed in: January 2026 CPU patched versions - Oracle — WebLogic Server Proxy Plug-in for Microsoft IIS
Vulnerable versions: 12.2.1.4.0
Fixed in: January 2026 CPU patched versions
Remediation for CVE-2026-21962
Patches
- Oracle Critical Patch Update January 2026 — addresses CVE-2026-21962
- Upgrade Oracle HTTP Server to patched version per CPU advisory
- Upgrade WebLogic Server Proxy Plug-in for Apache to patched version
- Upgrade WebLogic Server Proxy Plug-in for IIS to patched version
Immediate actions
- Apply Oracle January 2026 Critical Patch Update immediately
- Block path traversal patterns (..;) at WAF/reverse proxy layer
- Restrict external access to WebLogic administrative endpoints and internal servlets
- Monitor for HTTP GET requests to /_proxy/ and /wl_proxy/ paths
- Block known attacker IPs at perimeter firewall
Workarounds
- Disable or restrict access to ProxyServlet if not required
- Configure reverse proxy rules to block requests containing '..;' traversal sequences
- Place WebLogic Server behind a WAF with path traversal detection rules
- Remove or restrict access to bea_wls_internal endpoints
Longer-term hardening
- Implement network segmentation to isolate WebLogic servers from direct internet exposure
- Deploy web application firewall with virtual patching capabilities
- Establish continuous vulnerability scanning for Oracle Fusion Middleware components
- Implement egress filtering to detect and block unauthorized command execution callbacks
- Subscribe to Oracle Security Alert notifications for proactive patching
CVEs associated with CVE-2026-21962
Weaknesses (CWE) in CVE-2026-21962
Timeline of CVE-2026-21962
- Oracle publishes Security Alert for CVE-2026-21962; NVD entry created with CVSS 10.0 base score
- Oracle releases January 2026 Critical Patch Update addressing CVE-2026-21962 with CVSS 10.0 rating
- Tenable releases detection plugins 296603 and 296604 for CVE-2026-21962
- First active exploitation observed at 13:30:50 UTC from IP 67.213.118.179 (Vultr Holdings LLC) targeting WebLogic honeypot
- Public PoC exploit (Ashwesker) released on GitHub by boroeurnprach with Python script and Nuclei template
- Widespread scanning wave commences with multiple new attacker IPs from TE Data Egypt (41.251.179.181) and DigitalOcean Germany (149.28.149.165)
- CloudSEK completes 12-day honeypot observation period documenting exploitation patterns across multiple ASNs and scanning tools
- CloudSEK publishes comprehensive honeypot analysis detailing attacker infrastructure, scanning tools, and exploitation patterns
- As of 2026-05-29, CVE-2026-21962 (Ashwesker) remains a live threat: Oracle patched it in the Jan 2026 CPU, but the CVSS 10.0 unauthenticated WebLogic RCE has 17+ public PoCs, same-day weaponization, and ongoing commodity/botnet scanning still hitting unpatched internet-facing servers. Active exploitation continues despite patch availability.
Sources cited for CVE-2026-21962
Detection coverage for TL-2026-0283
As of 2026-03-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0283 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.