As cited
Copy frozen at (site build).
vulnerabilities
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
The Cybersecurity and Infrastructure Security Agency (CISA) placed CVE-2026-21962, a perfect-score Oracle vulnerability affecting Windows virtual machines, on its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in allows attackers to read, alter, or remove data through low-complexity attacks and was disclosed in January 2026, yet exploitation attempts occurred within weeks of public details becoming available. Honeypot data from January and February captured automated scanning campaigns targeting this and related older bugs alongside generic vulnerabilities, underscoring early adversary interest in the issue.
Why it matters: Federal civilian agencies must patch Oracle systems running vulnerable versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 within three days; private sector organizations should prioritize patches immediately as threat actors have actively scanned for and exploited this remote code execution vector since shortly after disclosure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
The Cybersecurity and Infrastructure Security Agency (CISA) placed CVE-2026-21962, a perfect-score Oracle vulnerability affecting Windows virtual machines, on its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in allows attackers to read, alter, or remove data through low-complexity attacks and was disclosed in January 2026, yet exploitation attempts occurred within weeks of public details becoming available. Honeypot data from January and February captured automated scanning campaigns targeting this and related older bugs alongside generic vulnerabilities, underscoring early adversary interest in the issue.
Why it matters: Federal civilian agencies must patch Oracle systems running vulnerable versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 within three days; private sector organizations should prioritize patches immediately as threat actors have actively scanned for and exploited this remote code execution vector since shortly after disclosure.
- Source published
- First seen by Cybersecurity Tracker