[URGENT] Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962: Apply the January 2026 CPU Now — Unauthenticated Data Tampering
CISA added this flaw to the KEV catalog on August 24, 2026 with a remediation deadline of August 27. Exploitable over the network without authentication and scored 10.0 under CVSS 3.1, here are the affected versions, the patch to apply, and Oracle's own stance on workarounds.
