Urgent.News

What's breaking now, across thousands of outlets.

Science

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching deadline for an actively exploited, max-severity Oracle vulnerability. Tracked as CVE-2026-21962, the flaw affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in, allowing attackers to manipulate critical data and potentially gain full access to affected systems.

Initially disclosed in January 2026, Oracle released patches for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and CISA placed the vulnerability in its Known Exploited Vulnerability (KEV) catalog on August 24, the shortest deadline it can set. The timely addition to the KEV catalog comes despite reports suggesting threat actors had been targeting CVE-2026-21962 since January.

Cybersecurity analyst Vikas Kundu from CloudSEK found evidence of high-volume automated scans aimed at exploiting the bug, alongside attempts at other vulnerabilities. The findings underscore the urgency for organizations to prioritize patching this critical Oracle flaw.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Science

Bomb Fishing Is Wreaking Havoc on Indonesia's Coral Reefs

Fishers operating off the coast of Sulawesi, Indonesia, are detonating more than 8,000 underwater explosives each year, researchers estimate.

  • Over 8,000 underwater explosives detonated annually in Sulawesi region
  • Coral Triangle suffers significant damage from bomb fishing
  • Audio sensor network proposed to detect and combat illegal fishing

More from Tuesday 25 August →