CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching deadline for an actively exploited, max-severity Oracle vulnerability. Tracked as CVE-2026-21962, the flaw affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in, allowing attackers to manipulate critical data and potentially gain full access to affected systems.
Initially disclosed in January 2026, Oracle released patches for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and CISA placed the vulnerability in its Known Exploited Vulnerability (KEV) catalog on August 24, the shortest deadline it can set. The timely addition to the KEV catalog comes despite reports suggesting threat actors had been targeting CVE-2026-21962 since January.
Cybersecurity analyst Vikas Kundu from CloudSEK found evidence of high-volume automated scans aimed at exploiting the bug, alongside attempts at other vulnerabilities. The findings underscore the urgency for organizations to prioritize patching this critical Oracle flaw.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.