Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Urges Immediate Action: Oracle Flaw Raises Concerns Over System Security




The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching deadline for a critical vulnerability in Oracle's HTTP Server and WebLogic Server Proxy Plug-in, CVE-2026-21962. This flaw allows attackers to create, delete, or modify access to critical data and gain complete access to all data stored on affected systems. The CISA has added the vulnerability to its Known Exploited Vulnerability (KEV) catalog, giving federal agencies three days to patch the vulnerability before it is considered exploited. This is the tightest deadline set by CISA, indicating the severity of the vulnerability.

  • Oracle's HTTP Server and WebLogic Server Proxy Plug-in are vulnerable to a critical exploit (CVE-2026-21962) rated as a perfect 10 by the Common Vulnerability Scoring System (CVSS).
  • CISA has added CVE-2026-21962 to its Known Exploited Vulnerability (KEV) catalog, giving federal agencies a three-day deadline to patch the vulnerability before it is considered exploited.
  • Attacks using CVE-2026-21962 have been actively exploited, allowing attackers to gain unauthorized access to systems and create, delete, or modify access to critical data.
  • The CISA has added two new vulnerabilities to the KEV catalog: a Python scaling framework vulnerability and a "god mode" vulnerability.
  • Experts emphasize the critical need for organizations to prioritize patching CVE-2026-21962 immediately.



  • The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching deadline for a critical vulnerability in Oracle's HTTP Server and WebLogic Server Proxy Plug-in, CVE-2026-21962. This flaw, rated as a perfect 10 by the Common Vulnerability Scoring System (CVSS), allows attackers to create, delete, or modify access to critical data and gain complete access to all data stored on affected systems. The vulnerability has been actively exploited, with attackers using it to gain unauthorized access to systems.

    The CISA has added CVE-2026-21962 to its Known Exploited Vulnerability (KEV) catalog, giving federal civilian executive branch (FCEB) agencies three days to patch the vulnerability before it is considered exploited. This is the tightest deadline set by CISA, indicating the severity of the vulnerability. The deadline was set on August 24, 2026, allowing agencies to take immediate action to protect themselves against attacks.

    The vulnerability was first disclosed in January 2026, and since then, honeypot activity has indicated that attackers have been scanning for the vulnerability, as well as other WebLogic RCE bugs dating back to 2020 and 2017. The logs from the honeypot operation revealed significant background noise, including attempts to exploit non-WebLogic-specific vulnerabilities, indicating a broad "spray and pray" approach by threat actors.

    Experts emphasize the critical need for organizations to prioritize patching the vulnerability at the time of its disclosure. The findings from the honeypot operation demonstrate the urgent need for immediate action. The CISA's decision to set a tight deadline for patching the vulnerability highlights the agency's commitment to protecting the nation's critical infrastructure.

    The Oracle patch for CVE-2026-21962 was released on January 20, 2026, and it addressed versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. However, the CISA's addition of the vulnerability to the KEV catalog has raised concerns about the effectiveness of the patch. The fact that attackers have been actively exploiting the vulnerability suggests that the patch may not be as effective as initially thought.

    The addition of CVE-2026-21962 to the KEV catalog is also significant, as it highlights the agency's focus on high-priority vulnerabilities. The KEV catalog is used to track and prioritize known exploited vulnerabilities, and its addition to the catalog indicates that the CISA considers CVE-2026-21962 a high-priority vulnerability.

    In addition to CVE-2026-21962, CISA has also added another vulnerability, the critical remote code execution (RCE) flaw affecting Python scaling framework Ray, to the KEV catalog. This vulnerability was disclosed in 2025 but was not added to the catalog until last week. The CISA has also added a "god mode" vulnerability, which offered attackers "full administrative access to an N-central console," to the KEV catalog, giving federal agencies a three-day deadline to patch the vulnerability.

    The CISA's actions are a reminder that cybersecurity is a constant evolving landscape, and organizations must stay vigilant to protect themselves against new and emerging threats. The CISA's decision to set a tight deadline for patching CVE-2026-21962 highlights the agency's commitment to protecting the nation's critical infrastructure and emphasizes the critical need for immediate action.

    In conclusion, the CISA's decision to add CVE-2026-21962 to the KEV catalog and set a tight deadline for patching the vulnerability is a clear indication of the agency's commitment to protecting the nation's critical infrastructure. The findings from the honeypot operation demonstrate the urgent need for immediate action, and experts emphasize the critical need for organizations to prioritize patching the vulnerability at the time of its disclosure.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Urges-Immediate-Action-Oracle-Flaw-Raises-Concerns-Over-System-Security-ehn.shtml

  • https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107


  • Published: Tue Aug 25 06:45:38 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us