CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
ID: 483f4c7e-a05a-5ebd-9536-bef2da12e8ef
STIX ID: report--483f4c7e-a05a-5ebd-9536-bef2da12e8ef
Feed Name: The Register (Security)
Threat Score
CISA has issued a three-day remediation deadline for CVE-2026-21962, a critical (CVSS 10.0) improper access control flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in that can allow attackers full access to affected Windows VMs; Oracle released patches in January, but private-sector honeypots captured exploitation attempts and automated scanning, prompting CISA to add the bug to its Known Exploited Vulnerability catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
