Skip to content

CISA spots Oracle bug exploitation seven months after patch

Government security teams given just three days to patch the CVSS 10 vulnerability.

CISA spots Oracle bug exploitation seven months after patch
Image credit: https://unsplash.com/@jokostudios

Hackers have started exploiting a CVSS 10-rated Oracle bug patched in January, according to the US government’s cybersecurity agency, which added CVE-2026-21962 to its exploited bug database this week.

The Cybersecurity and Infrastructure Security Agency (CISA) gave security teams its tightest three-day deadline to patch the improper access bug in Oracle’s HTTP Server and Weblogic Server Proxy Plug-in, after adding it to its Known Exploited Vulnerabilities Catalog.

A notice on 24 August said the vulnerability could “result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.”

The trivially exploitable bug affects Oracle’s Fusion Middleware and was patched in January 2026, but neither Oracle nor security researchers flagged exploitation in the wild at the time.

Honeypot exploitation

This content is for members only

Subscribe
Add The Stack on Google