CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
- ID
- 17650
- Status
- summarized
- Published
- 25 Aug 2026, 6:43 PM
- Fetched
- 25 Aug 2026, 10:42 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 25 Aug 2026, 10:44 PM
- Tags
- Audience
- developersdatabase_learners
What happened
CISA added CVE-2026-21962, a CVSS 10.0 improper access control flaw in Oracle's HTTP Server and WebLogic Server Proxy Plug-in (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) on Windows VMs, to its Known Exploited Vulnerability catalog with a three-day patching deadline. Oracle patched the bug in January 2026, but CISA only catalogued it seven months later despite honeypot evidence from CloudSEK showing active exploitation within days of disclosure.
Why it matters
If you run Oracle WebLogic or HTTP Server on Windows in production, patch immediately—attackers were already probing this within days of the January disclosure, and successful exploitation grants complete data access. For everyone else not on the Oracle stack, this is a reminder that KEV catalog lag (seven months here) means you cannot wait for government mandates to drive patching timelines.
Discussion angle
The seven-month gap between Oracle's patch and CISA's KEV listing, plus honeypot evidence of immediate exploitation, is a useful case study on why patching cadence should be driven by exploit availability, not government catalogues.