Loading sources...
CISA demands urgent patching for critical Oracle vulnerability
In the US, CISA has issued a three-day deadline for federal agencies to patch a critical Oracle vulnerability. Disclosed in January 2026, CVE-2026-21962 affects Oracle's HTTP Server and WebLogic Server Proxy Plug-in, allowing unauthorized access to sensitive data. Despite Oracle's earlier patches, attackers had begun exploiting the flaw, highlighting the urgent need for organizations to prioritize security measures.

Published Aug 25, 2026