Skip to content
CISA gives admins three days to patch actively exploited Oracle flaw

CISA gives admins three days to patch actively exploited Oracle flaw

Feeds.4Sysops IT News August 25, 2026

CISA has given U.S. federal agencies only three days to patch CVE-2026-21962, a maximum-severity Oracle vulnerability that attackers were already probing months before it entered the agency’s Known Exploited Vulnerabilities catalog. The flaw affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in on Windows virtual machines and carries a CVSS score of 10.0. Source

Extracted Entities