CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5901

As cited

Copy frozen at (site build).

vulnerabilities

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Cybersecurity and Infrastructure Security Agency (CISA) placed CVE-2026-21962, a perfect-score Oracle vulnerability affecting Windows virtual machines, on its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in allows attackers to read, alter, or remove data through low-complexity attacks and was disclosed in January 2026, yet exploitation attempts occurred within weeks of public details becoming available. Honeypot data from January and February captured automated scanning campaigns targeting this and related older bugs alongside generic vulnerabilities, underscoring early adversary interest in the issue.

Why it matters: Federal civilian agencies must patch Oracle systems running vulnerable versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 within three days; private sector organizations should prioritize patches immediately as threat actors have actively scanned for and exploited this remote code execution vector since shortly after disclosure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The Cybersecurity and Infrastructure Security Agency (CISA) placed CVE-2026-21962, a perfect-score Oracle vulnerability affecting Windows virtual machines, on its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in allows attackers to read, alter, or remove data through low-complexity attacks and was disclosed in January 2026, yet exploitation attempts occurred within weeks of public details becoming available. Honeypot data from January and February captured automated scanning campaigns targeting this and related older bugs alongside generic vulnerabilities, underscoring early adversary interest in the issue.

Why it matters: Federal civilian agencies must patch Oracle systems running vulnerable versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 within three days; private sector organizations should prioritize patches immediately as threat actors have actively scanned for and exploited this remote code execution vector since shortly after disclosure.

VendorsMicrosoftOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary