CISA Gives Federal Agencies 72 Hours To Patch Actively Exploited Oracle Bug
Updated August 37: This article, originally published August 25, has been updated with comments and guidance from cybersecurity experts following the CISA advisory giving Federal agencies just 72 hours to patch a critical and now actively exploited Oracle vulnerability.
While the July security patch roundup from Oracle included 1,449 bug fixes, addressing 1434 distinct Common Vulnerabilities and Exposures, which was a new record in terms of numbers, the U.S. Cybersecurity and Infrastructure Security Agency has now issued a new alert for an old “improper access control” CVE. What’s more, it has given Federal Civilian Executive Branch agencies just 72 hours from the August 24 alert to install the fix. The reason that CISA is so concerned about a vulnerability impacting Oracle’s HTTP server and WebLogic server proxy plugin that was actually disclosed in January along with the highest possible Common Vulnerability Scoring System severity rating of 10, and a patch to address it, is that it’s now known to be under active exploit in the wild.
CISA Adds Oracle CVE-2026-21962 Vulnerability To KEV Catalog
CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, which is reason enough for all organizations to take heed of the issues which it described as involving a “frequent attack vector for malicious cyber actors,” but it also took the unusual step of giving FCEB agencies the shortest possible deadline it is able to under Binding Operational Directive 26-04 of just three days to remedy the threat by patching it.
BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to “prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation,“ CISA said. FCEB agencies must also check whether threat actors had already compromised their systems before the patch was applied.
“CISA added CVE-2026-21962 to the KEV catalog on August 24, 216 days after the patch,” Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs,pointed out, adding that, in January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. “Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math,” Krell said, “BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.”
Of course, while the directive itself applies only to these agencies, CISA is quite clear, as are other security professionals, that all organizations must adopt what is known as risk-based vulnerability management; and that means prioritizing KEV catalog-listed vulnerabilities when it comes to patching.
Oracle Users Should Take Note Of The Patch Apocalypse
“The ebb and flow of the ‘ Patch Apocalypse ’ continues with no sign of slowing yet,” Todd Schell, principal product manager at Ivanti, told me . The problem is that not all Common Vulnerabilities and Exposures are created equal. “The patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities,” Schell warned, but you need to remain disciplined and remember even CVEs with high CVSS scores which are not exploited or are not internet-facing can be handled in a second round of patching.
“The KEV catalog is one of the most important resources defenders have for prioritizing vulnerability remediation,” Robert Coles, senior manager of threat intelligence security at Black Duck, said, adding that “there are thousands of critical vulnerabilities published every year, but only a small subset is added to KEV.” Security teams should, therefore, use this KEV status as a beacon that a vulnerability has moved from a theoretical risk to a very real and operational one. “In the case of CVE-2026-21962,” Coles warned, “there have been public reports of exploitation activity dating back to shortly after Oracle released its January patch, including observations from security researchers, honeypot operators, and threat intelligence providers.”And, in case you need any further reminders, this means that the Oracle CVE-2026-21962 vulnerability has to be on your priority patching list no matter your organisation. What are you waiting for?
Loading article...