CISA Gives Agencies Three Days to Patch Actively Exploited Oracle Enterprise Flaw
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog and set an August 27 remediation deadline for affected federal systems.
Why it matters: Active exploitation of an unauthenticated Oracle enterprise flaw creates immediate patching risk for internet-facing middleware.
A vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited, prompting U.S. cybersecurity officials to impose an unusually short federal remediation deadline.
CVE-2026-21962 can be exploited remotely without authentication by an attacker who can reach an affected server over HTTP. Successful exploitation can allow unauthorized access to critical information as well as modification or deletion of data accessible through the affected Oracle components.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 24 and ordered affected federal civilian systems to apply vendor mitigations by August 27.
The three-day patch window reflects the potential severity of the threat. CISA classifies exploitation as active, the attack as automatable and the possible technical impact as total.
For enterprises running Oracle middleware, the incident is another reminder that externally reachable infrastructure can move from disclosed vulnerability to confirmed exploitation faster than conventional patch cycles are designed to handle.