CISA imposes 3-day patch window for critical Oracle vulnerability

1 min read
Source: The Register
CISA imposes 3-day patch window for critical Oracle vulnerability
Photo: The Register
TL;DR Summary

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog, giving federal agencies a three‑day deadline to patch a critical Oracle flaw in Oracle HTTP Server and WebLogic Proxy Plug‑in on Windows VMs that can grant full data access. Oracle released patches in January 2026 for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); private-sector researchers reported active exploitation attempts, underscoring the urgency of patching.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

21 min

vs 22 min read

Condensed

99%

4,21361 words

Want the full story? Read the original article

Read on The Register