CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

https://image.theregister.com/1682641.jpg?imageId=1682641&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs.

Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s HTTP Server and WebLogic Server Proxy Plug-in.

Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain “complete access” to all data stored on the affected systems.

Oracle disclosed and provided patches for CVE-2026-21962 as part of its January 20, 2026, updates. At the time, it said versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 were affected, and that the vulnerability could be exploited in low-complexity attacks.

CISA added CVE-2026-21962 to its Known Exploited Vulnerability (KEV)...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more