CISA Slaps Its Tightest Three-Day Patching Deadline on Perfect-10 Oracle Flaw
Oracle’s flaw can give attackers complete access to affected systems, and private-sector telemetry found high-volume automated scanning before CISA’s deadline.
- On Monday, CISA added the critical Oracle vulnerability CVE-2026-21962 to its Known Exploited Vulnerability catalog, mandating that FCEB agencies secure their systems against attacks within three days.
- Tracked as CVE-2026-21962 , the max-severity bug affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in. Successful exploitation allows attackers to gain "complete access" to all data on affected systems.
- Although CISA only recently added the flaw to the KEV Catalog, private sector reports suggest attackers targeted the vulnerability earlier this year. CloudSEK cyber intelligence analyst Vikas Kundu operated a honeypot for 12 days between January 22 and February 3, confirming early exploit attempts.
- Kundu said findings demonstrated "the critical and immediate need for organizations to prioritize patching." Logs revealed a broad "spray and pray" approach by threat actors, including attempts to exploit Hikvision CVE and PHPUnit RCE.
- This three-day deadline is CISA's most urgent enforcement window. Other bugs recently given this treatment include the critical RCE flaw affecting Python scaling framework Ray and N-able's "god mode" vulnerability, offering attackers "full administrative access to an N-central console.
13 Articles
13 Articles
Oracle WebLogic CVE-2025-20989: Critical RCE Flaw Bypasses All 2025 Patches
Oracle has disclosed a high-severity vulnerability in its WebLogic Server that allows unauthenticated remote code execution through a sophisticated deserialization attack. The flaw, tracked as CVE-2025-20989, affects multiple supported versions of the enterprise application server even when organizations have applied every available security patch released during 2025. Security researchers first identified the issue during a routine penetration …
CISA Gives Federal Agencies 72 Hours To Patch Old 10/10 Oracle Bug
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s HTTP Server and WebLogic Server Proxy Plug-in. Successful attacks targeting CVE-2026-21962 can allow m…
CISA has added a critical failure that affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to the known exploited vulnerabilities (KEV) catalog. Identified as CVE-2026-21962, vulnerability has received CVSS 10.0 score, maximum severity rating, and already has evidence of active exploitation. The alert puts infrastructure administrators, security teams and DevOps professionals in a situation that requires immediate attention. Fail…
CISA orders federal agencies to patch actively exploited Oracle flaw by August 27– Expert Comments
CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modif…
CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition confirms that attackers are actively exploiting the vulnerability in real-world attacks. Organizations with affected Oracle infrastructure should identify exposed systems and apply available …
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









