CISA imposes 3-day patch window for critical Oracle vulnerability

TL;DR
CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog, giving federal agencies a three‑day deadline to patch a critical Oracle flaw in Oracle HTTP Server and WebLogic Proxy Plug‑in on Windows VMs that can grant full data access. Oracle released patches in January 2026 for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); private-sector researchers reported active exploitation attempts, underscoring the urgency of patching.
- CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw The Register
- CISA Warns of Exploited Oracle WebLogic Vulnerability SecurityWeek
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data The Hacker News
- August 2026 Updates to EBS Java Critical Patch Update Checker (EJCPUC) Oracle Blogs
- Oracle WebLogic Server flaw enables server takeover via T3 and IIOP Field Effect
Want the full story? Read the original reporting
Read on The Register