CISA orders federal agencies to patch critical Oracle bug within three days
CISA has given U.S. federal civilian agencies a three-day window to apply patches for Oracle’s high-severity CVE-2026-21962 flaw, the agency’s shortest deadline.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Oracle’s CVE-2026-21962, a max-severity improper-access-control defect in Oracle HTTP Server and WebLogic Proxy Plug-in, to its Known Exploited Vulnerabilities catalog and imposed a three-day remediation deadline for all federal civilian executive branch agencies, the shortest timeline the agency can set. Oracle originally disclosed the flaw and released patches on January 20 for versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, warning that it could be exploited with low complexity.
This directive follows similar three-day mandates for a critical Ray RCE bug and an N-able “god mode” vulnerability. CloudSEK analyst Vikas Kundu reported that a honeypot captured high-volume automated scans and exploit attempts against the Oracle bug within days of its public release. CISA’s action highlights the urgency of securing government systems against actively exploited software flaws.
Why it matters
Unpatched Oracle servers could let attackers seize or destroy critical data on U.S. government systems.
In this story
