CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

← Back to the feed

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Register · 8 hours ago

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued its tightest possible three-day patching deadline for a maximum-severity Oracle vulnerability, warning that it is already being actively exploited. The flaw affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in running on Windows virtual machines, and could let attackers gain complete control over data stored on affected systems, making it a serious risk for any organisation still running unpatched versions.

The vulnerability, CVE-2026-21962, carries the maximum CVSS score of 10.0 and stems from improper access control, allowing low-complexity attacks that can create, delete or modify critical data. Oracle disclosed the flaw and released patches back on 20 January 2026, affecting versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, but CISA only added it to its Known Exploited Vulnerabilities catalogue on 24 August, seven months later, giving federal agencies just three days to secure their systems. Security researchers say attackers were targeting the bug far earlier than CISA's action suggests: CloudSEK ran a honeypot in late January and early February that captured high-volume automated scanning exploiting the flaw alongside older WebLogic bugs, part of a broader "spray and pray" campaign by opportunistic threat actors.

  • CISA gives US agencies just three days to patch a critical Oracle flaw.
  • CVE-2026-21962 scores a perfect 10.0 severity rating.
  • Attackers were exploiting the bug months before CISA's official deadline.

Software

Read the full article at the source →