Threat reportVulnerabilityTL-2026-0283

CVE-2026-21962: Oracle WebLogic Server & HTTP Server Unauthenticated RCE via Proxy Plug-in Path Traversal (CVSS 10.0) — Active Exploitation

criticalACTIVE

CVE-2026-21962 (TL-2026-0283), also tracked as Ashwesker, is a critical-severity software vulnerability scored CVSS 10, first published 2026-03-25. It has no confirmed attribution, affects Oracle Oracle HTTP Server, references 1 CVE (CVE-2026-21962), maps to 11 MITRE ATT&CK techniques (T1027, T1059, T1071), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0283

Threat ID
TL-2026-0283
Also known as
Ashwesker
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, financial, government, healthcare, energy, telecommunications, manufacturing, education
Target regions
Global, North America, Europe, Middle East, Africa
Detection rules
9
Indicators of compromise
20

Malware and tooling in CVE-2026-21962

Malware and tooling: Ashwesker CVE-2026-21962 PoC, Nuclei

How CVE-2026-21962 works

Critical unauthenticated remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) exploitable via HTTP path traversal to the internal ProxyServlet endpoint. Public PoC released January 22, 2026 with same-day active exploitation confirmed. Widespread scanning observed across commodity threat actors leveraging automated tooling.

CVE-2026-21962 is a critical unauthenticated remote code execution vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in components within Oracle Fusion Middleware. The vulnerability carries the maximum CVSS 3.1 base score of 10.0 with a Changed scope, indicating compromise extends beyond the vulnerable component.

The flaw resides in the proxy plug-in's improper input validation of HTTP request paths. Attackers craft HTTP GET requests using path traversal sequences (specifically the '..;' notation) to reach internal WebLogic endpoints that should not be externally accessible. The primary attack vectors target:

- /_proxy//weblogic/..;/bea_wls_internal/ProxyServlet - /wl_proxy//weblogic/..;/bea_wls_internal/ProxyServlet

By accessing the internal ProxyServlet through these traversal paths, unauthenticated attackers gain the ability to execute arbitrary operating system commands on the underlying server. The vulnerability requires no authentication, no user interaction, and has low attack complexity — making it trivially exploitable at scale.

Affected products include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, as well as WebLogic Server Proxy Plug-in for Apache HTTP Server (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and WebLogic Server Proxy Plug-in for Microsoft IIS (version 12.2.1.4.0).

A proof-of-concept exploit was published on GitHub (boroeurnprach/Ashwesker-CVE-2026-21962) on January 22, 2026, providing both a Python exploitation script and a Nuclei scanning template. Active exploitation was observed within hours of PoC release — the first attack was recorded at 13:30:50 UTC on January 22, 2026 from IP 67.213.118.179 (Vultr Holdings LLC infrastructure).

CloudSEK deployed a high-interaction Oracle WebLogic honeypot running the vulnerable version 14.1.1.0.0 and observed a 12-day exploitation campaign from January 22 to February 3, 2026. Key findings:

- Scanning tools dominated traffic: libredtail-http (1,012 requests from 21 IPs), Nmap Scripting Engine (664 requests from 5 IPs), Go-http-client (253 requests from 64 IPs), and python-requests (43 requests from 24 IPs). - Infrastructure analysis revealed DigitalOcean (AS14061) as the most diverse source with 28 unique IPs and 461 requests, while HOSTGLOBAL.PLUS LTD (AS202306) generated the highest request volume (625 requests from 4 IPs). - The libredtail-http user agent pattern suggests persistent, large-scale botnet-driven scanning operations. - Attackers also exploited legacy WebLogic CVEs alongside CVE-2026-21962, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT Deserialization).

Oracle addressed this vulnerability in the January 2026 Critical Patch Update. The CWE classification is CWE-284 (Improper Access Control). Despite the CVSS 10.0 score, the EPSS probability remains relatively low at 0.00031, though real-world exploitation data clearly contradicts this assessment given confirmed active exploitation.

MITRE ATT&CK techniques used in TL-2026-0283

defense-evasion

T1027 Obfuscated Files or Information

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

command-and-control

T1071 Application Layer Protocol

discovery

T1082 System Information Discovery

initial-access

T1190 Exploit Public-Facing Application

persistence

T1505 Server Software Component

impact

T1531 Account Access Removal

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

reconnaissance

T1595 Active Scanning

Affected products and versions in CVE-2026-21962

  • Oracle — Oracle HTTP Server
    Vulnerable versions: 12.2.1.4.0; 14.1.1.0.0; 14.1.2.0.0
    Fixed in: January 2026 CPU patched versions
  • Oracle — WebLogic Server Proxy Plug-in for Apache HTTP Server
    Vulnerable versions: 12.2.1.4.0; 14.1.1.0.0; 14.1.2.0.0
    Fixed in: January 2026 CPU patched versions
  • Oracle — WebLogic Server Proxy Plug-in for Microsoft IIS
    Vulnerable versions: 12.2.1.4.0
    Fixed in: January 2026 CPU patched versions

Remediation for CVE-2026-21962

Patches

  • Oracle Critical Patch Update January 2026 — addresses CVE-2026-21962
  • Upgrade Oracle HTTP Server to patched version per CPU advisory
  • Upgrade WebLogic Server Proxy Plug-in for Apache to patched version
  • Upgrade WebLogic Server Proxy Plug-in for IIS to patched version

Immediate actions

  • Apply Oracle January 2026 Critical Patch Update immediately
  • Block path traversal patterns (..;) at WAF/reverse proxy layer
  • Restrict external access to WebLogic administrative endpoints and internal servlets
  • Monitor for HTTP GET requests to /_proxy/ and /wl_proxy/ paths
  • Block known attacker IPs at perimeter firewall

Workarounds

  • Disable or restrict access to ProxyServlet if not required
  • Configure reverse proxy rules to block requests containing '..;' traversal sequences
  • Place WebLogic Server behind a WAF with path traversal detection rules
  • Remove or restrict access to bea_wls_internal endpoints

Longer-term hardening

  • Implement network segmentation to isolate WebLogic servers from direct internet exposure
  • Deploy web application firewall with virtual patching capabilities
  • Establish continuous vulnerability scanning for Oracle Fusion Middleware components
  • Implement egress filtering to detect and block unauthorized command execution callbacks
  • Subscribe to Oracle Security Alert notifications for proactive patching

CVEs associated with CVE-2026-21962

CVE-2026-21962

Weaknesses (CWE) in CVE-2026-21962

CWE-284

Timeline of CVE-2026-21962

  • Oracle publishes Security Alert for CVE-2026-21962; NVD entry created with CVSS 10.0 base score
  • Oracle releases January 2026 Critical Patch Update addressing CVE-2026-21962 with CVSS 10.0 rating
  • Tenable releases detection plugins 296603 and 296604 for CVE-2026-21962
  • First active exploitation observed at 13:30:50 UTC from IP 67.213.118.179 (Vultr Holdings LLC) targeting WebLogic honeypot
  • Public PoC exploit (Ashwesker) released on GitHub by boroeurnprach with Python script and Nuclei template
  • Widespread scanning wave commences with multiple new attacker IPs from TE Data Egypt (41.251.179.181) and DigitalOcean Germany (149.28.149.165)
  • CloudSEK completes 12-day honeypot observation period documenting exploitation patterns across multiple ASNs and scanning tools
  • CloudSEK publishes comprehensive honeypot analysis detailing attacker infrastructure, scanning tools, and exploitation patterns
  • As of 2026-05-29, CVE-2026-21962 (Ashwesker) remains a live threat: Oracle patched it in the Jan 2026 CPU, but the CVSS 10.0 unauthenticated WebLogic RCE has 17+ public PoCs, same-day weaponization, and ongoing commodity/botnet scanning still hitting unpatched internet-facing servers. Active exploitation continues despite patch availability.

Sources cited for CVE-2026-21962

Detection coverage for TL-2026-0283

As of 2026-03-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0283 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats