CVE-2026-21962 is an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The vulnerability allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible by the affected components. It was disclosed as part of Oracle's January 2026 Critical Patch Update. CISA has included this vulnerability under BOD 26-04, which prioritizes security updates based on risk. Federal agencies and organizations using Oracle HTTP Server or WebLogic Server Proxy Plug-in are advised to apply patches immediately. The vulnerability is rated High criticality and poses significant risk to enterprise environments relying on Oracle middleware. Forensic triage requirements have also been outlined by CISA as part of the BOD 26-04 implementation guidance.