# CVE-2026-21962: Oracle WebLogic Server & HTTP Server Unauthenticated RCE via Proxy Plug-in Path Traversal (CVSS 10.0) — Active Exploitation

> Critical unauthenticated remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) exploitable via HTTP path traversal to the internal ProxyServlet endpoint. Public PoC released January 22, 2026 with same-day active exploitation confirmed. Widespread scanning observed across commodity threat actors leveraging automated tooling.

- **Published:** 2026-03-25T12:00:00Z
- **Last reviewed:** 2026-03-25T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0283
- **ID:** TL-2026-0283
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-21962

## Description

CVE-2026-21962 is a critical unauthenticated remote code execution vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in components within Oracle Fusion Middleware. The vulnerability carries the maximum CVSS 3.1 base score of 10.0 with a Changed scope, indicating compromise extends beyond the vulnerable component.

The flaw resides in the proxy plug-in's improper input validation of HTTP request paths. Attackers craft HTTP GET requests using path traversal sequences (specifically the '..;' notation) to reach internal WebLogic endpoints that should not be externally accessible. The primary attack vectors target:

- /_proxy//weblogic/..;/bea_wls_internal/ProxyServlet
- /wl_proxy//weblogic/..;/bea_wls_internal/ProxyServlet

By accessing the internal ProxyServlet through these traversal paths, unauthenticated attackers gain the ability to execute arbitrary operating system commands on the underlying server. The vulnerability requires no authentication, no user interaction, and has low attack complexity — making it trivially exploitable at scale.

Affected products include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, as well as WebLogic Server Proxy Plug-in for Apache HTTP Server (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and WebLogic Server Proxy Plug-in for Microsoft IIS (version 12.2.1.4.0).

A proof-of-concept exploit was published on GitHub (boroeurnprach/Ashwesker-CVE-2026-21962) on January 22, 2026, providing both a Python exploitation script and a Nuclei scanning template. Active exploitation was observed within hours of PoC release — the first attack was recorded at 13:30:50 UTC on January 22, 2026 from IP 67.213.118.179 (Vultr Holdings LLC infrastructure).

CloudSEK deployed a high-interaction Oracle WebLogic honeypot running the vulnerable version 14.1.1.0.0 and observed a 12-day exploitation campaign from January 22 to February 3, 2026. Key findings:

- Scanning tools dominated traffic: libredtail-http (1,012 requests from 21 IPs), Nmap Scripting Engine (664 requests from 5 IPs), Go-http-client (253 requests from 64 IPs), and python-requests (43 requests from 24 IPs).
- Infrastructure analysis revealed DigitalOcean (AS14061) as the most diverse source with 28 unique IPs and 461 requests, while HOSTGLOBAL.PLUS LTD (AS202306) generated the highest request volume (625 requests from 4 IPs).
- The libredtail-http user agent pattern suggests persistent, large-scale botnet-driven scanning operations.
- Attackers also exploited legacy WebLogic CVEs alongside CVE-2026-21962, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT Deserialization).

Oracle addressed this vulnerability in the January 2026 Critical Patch Update. The CWE classification is CWE-284 (Improper Access Control). Despite the CVSS 10.0 score, the EPSS probability remains relatively low at 0.00031, though real-world exploitation data clearly contradicts this assessment given confirmed active exploitation.

## MITRE ATT&CK

- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1071 Application Layer Protocol
- T1531 Account Access Removal

## Sources

- [CloudSEK Honeypot Analysis: Attacks Targeting CVE-2026-21962 and Critical WebLogic Vulnerabilities](https://www.cloudsek.com/blog/honey-for-hackers-a-study-of-attacks-targeting-the-recent-cve-2026-21962-and-other-critical-weblogic-vulnerabilities-on-a-high-interactive-oracle-honeypot)
- [NVD - CVE-2026-21962](https://nvd.nist.gov/vuln/detail/CVE-2026-21962)
- [Oracle Security Alert - CVE-2026-21962](https://www.oracle.com/security-alerts/alert-cve-2026-21962.html)
- [Oracle Critical Patch Update January 2026](https://www.oracle.com/security-alerts/cpujan2026.html)
- [Ashwesker CVE-2026-21962 PoC Exploit](https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962)
- [Tenable CVE-2026-21962 Detection Plugins (296603-296604)](https://www.tenable.com/cve/CVE-2026-21962)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0283
