CVE-2026-21962: Oracle WebLogic Server & HTTP Server Unauthenticated RCE via Proxy Plug-in Path Traversal (CVSS 10.0) — Active Exploitation — Threadlinqs Intelligence
As of 2026-05-30, CVE-2026-21962: Oracle WebLogic Server & HTTP Server Unauthenticated RCE via Proxy Plug-in Path Traversal (CVSS 10.0) — Active Exploitation is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0283 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical unauthenticated remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) exploitable via HTTP path traversal to the internal
CVE-2026-21962 is a critical unauthenticated remote code execution vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in components within Oracle Fusion Middleware. The vulnerability carries the maximum CVSS 3.1 base score of 10.0 with a Changed scope, indicating compromise extends beyond the vulnerable component.
The flaw resides in the proxy plug-in's improper input validation of HTTP request paths. Attackers craft HTTP GET requests using path traversal sequences (specifically the '..;' notation) to reach internal WebLogic endpoints that should not be externally accessible. The primary attack vectors target:
- /_proxy//weblogic/..;/bea_wls_internal/ProxyServlet
- /wl_proxy//weblogic/..;/bea_wls_internal/ProxyServlet
By accessing the internal ProxyServlet through these traversal paths, unauthenticated attackers gain the ability to execute arbitrary operating system commands on the underlying server. The vulnerability requires no authentication, no user interaction, and has low attack complexity — making it trivially exploitable at scale.
Affected products include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, as well as WebLogic Server Proxy Plug-in for Apache HTTP Server (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and WebLogic Server Proxy Plug-in for Microsoft IIS (version 12.2.1.4.0).
A proof-of-concept exploit was published on GitHub (boroeurnprach/Ashwesker-CVE-2026-21962) on January 22, 2026, providing both a Python exploitation script and a Nuclei scanning template. Active exploitation was observed within hours of PoC release — the first attack was recorded at 13:30:50 UTC on January 22, 2026 from IP 67.213.118.179 (Vultr Holdings LLC infrastructure).
CloudSEK deployed a high-interaction Oracle WebLogic honeypot running the vulnerable version 14.1.1.0.0 and observed a 12-day exploitation campaign from January 22 to February 3, 2026. Key findings:
- Scanning tools dominated traffic: libredtail-http (1,012 requests from 21 IPs), Nmap Scripting Engine (664 requests from 5 IPs), Go-http-client (253 requests from 64 IPs), and python-requests (43 requests from 24 IPs).
- Infrastructure analysis revealed DigitalOcean (AS14061) as the most diverse source with 28 unique IPs and 461 requests, while HOSTGLOBAL.PLUS LTD (AS202306) generated the highest request volume (625 requests from 4 IPs).
- The libredtail-http user agent pattern suggests persistent, large-scale botnet-driven scanning operations.
- Attackers also exploited legacy WebLogic CVEs alongside CVE-2026-21962, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT Deserialization).
Oracle addressed this vulnerability in the January 2026 Critical Patch Update. The CWE classification is CWE-284 (Improper Access Control). Despite the CVSS 10.0 score, the EPSS probability remains relatively low at 0.00031, though real-world exploitation data clearly contradicts this assessment given confirmed active exploitation.
Target sectors: technology, financial, government, healthcare, energy, telecommunications, manufacturing, education
Target regions: Global, North America, Europe, Middle East, Africa
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21962, T1595, T1595, T1588, T1583, T1190, T1059, T1059, T1203, T1505, T1027