Security
Government security teams given just three days to patch the CVSS 10 vulnerability.
Hackers have started exploiting a CVSS 10-rated Oracle bug patched in January, according to the US government’s cybersecurity agency, which added CVE-2026-21962 to its exploited bug database this week.
The Cybersecurity and Infrastructure Security Agency (CISA) gave security teams its tightest three-day deadline to patch the improper access bug in Oracle’s HTTP Server and Weblogic Server Proxy Plug-in, after adding it to its Known Exploited Vulnerabilities Catalogue.
A notice on 24 August said the vulnerability could “result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.”
The trivially exploitable bug affects Oracle’s Fusion Middleware and was patched in January 2026, but neither Oracle nor security researchers flagged exploitation in the wild at the time.
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
Already a member? Sign in