Skip to main content
See every side of every news story
Published loading...Updated

CISA Slaps Its Tightest Three-Day Patching Deadline on Perfect-10 Oracle Flaw

Oracle’s flaw can give attackers complete access to affected systems, and private-sector telemetry found high-volume automated scanning before CISA’s deadline.

  • On Monday, CISA added the critical Oracle vulnerability CVE-2026-21962 to its Known Exploited Vulnerability catalog, mandating that FCEB agencies secure their systems against attacks within three days.
  • Tracked as CVE-2026-21962 , the max-severity bug affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in. Successful exploitation allows attackers to gain "complete access" to all data on affected systems.
  • Although CISA only recently added the flaw to the KEV Catalog, private sector reports suggest attackers targeted the vulnerability earlier this year. CloudSEK cyber intelligence analyst Vikas Kundu operated a honeypot for 12 days between January 22 and February 3, confirming early exploit attempts.
  • Kundu said findings demonstrated "the critical and immediate need for organizations to prioritize patching." Logs revealed a broad "spray and pray" approach by threat actors, including attempts to exploit Hikvision CVE and PHPUnit RCE.
  • This three-day deadline is CISA's most urgent enforcement window. Other bugs recently given this treatment include the critical RCE flaw affecting Python scaling framework Ray and N-able's "god mode" vulnerability, offering attackers "full administrative access to an N-central console.
Insights by Ground AI
Podcasts & Opinions

13 Articles

CISA has added a critical failure that affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to the known exploited vulnerabilities (KEV) catalog. Identified as CVE-2026-21962, vulnerability has received CVSS 10.0 score, maximum severity rating, and already has evidence of active exploitation. The alert puts infrastructure administrators, security teams and DevOps professionals in a situation that requires immediate attention. Fail…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

cisa.gov broke the news on Monday, August 24, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal