A critical vulnerability, CVE-2026-21962, has been identified in Oracle Fusion Middleware components including Oracle HTTP Server and the WebLogic Server Proxy Plug-in for Apache and IIS. The issue is an authentication bypass that can be exploited remotely without user interaction, allowing an unauthenticated attacker to bypass access controls and cause significant confidentiality and integrity impact. Published advisories list the WebLogic Server Proxy Plug-in for IIS 12.2.1.4.0 as affected; Oracle included fixes for this and related issues in its January 2026 Critical Patch Update. The vulnerability carries a CVSS v3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N) per published details.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

