CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
The US Cybersecurity and Infrastructure Security Agency (CISA) has imposed an extremely tight three-day deadline for organizations to patch a highly critical Oracle flaw. This vulnerability, identified as CVE-2026-21962, is of perfect severity (10.0) and is categorized as an improper access control (CWE-284) flaw affecting Oracle's HTTP Server and WebLogic Server Proxy Plug-in.
Successful exploitation of this vulnerability can enable attackers to create, delete, or modify access to critical data, and even grant them complete access to all stored data on affected systems.
The patch for CVE-2026-21962 was made available by Oracle as part of its January 20, 2026 updates, and it was disclosed for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. CISA added this flaw to the Known Exploited Vulnerability (KEV) catalog on August 24, 2023, which is the agency's tightest deadline for patching. Other recent flaws given the three-day treatment include a critical remote code execution (RCE) flaw in the Python scaling framework Ray, and N-able's "god mode" vulnerability which provided attackers full administrative access to an N-central console.
Despite being disclosed in 2025, CISA added CVE-2026-21962 to the KEV catalog seven months after its initial disclosure. However, according to private sector reports, attackers had already been targeting the vulnerability earlier in the year. Cyber intelligence analyst Vikas Kundu from CloudSEK ran a honeypot for 12 days between January 22 and February 3, shortly after the disclosure and release of public exploit code.
The honeypot captured automated scanning attempts and malicious traffic using tools like libredtail-http and the Nmap Scripting Engine, as well as background noise from attacks targeting other non-WebLogic vulnerabilities. This underscores the urgent need for organizations to prioritize patching such critical flaws.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.