{
  "id": 3277893,
  "title": "CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw",
  "url": "https://urgent.news/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-3277893",
  "topic": "science",
  "section": "Science",
  "published": "2026-08-25T10:43:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107"
  },
  "original_language": "en",
  "account": "The Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching deadline for an actively exploited, max-severity Oracle vulnerability. Tracked as CVE-2026-21962, the flaw affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in, allowing attackers to manipulate critical data and potentially gain full access to affected systems. Initially disclosed in January 2026, Oracle released patches for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and CISA placed the vulnerability in its Known Exploited Vulnerability (KEV) catalog on August 24, the shortest deadline it can set. The timely addition to the KEV catalog comes despite reports suggesting threat actors had been targeting CVE-2026-21962 since January. Cybersecurity analyst Vikas Kundu from CloudSEK found evidence of high-volume automated scans aimed at exploiting the bug, alongside attempts at other vulnerabilities. The findings underscore the urgency for organizations to prioritize patching this critical Oracle flaw.",
  "summary": "Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}