Security & Risk5 minNewsroom

CISA Gives 72 Hours to Fix Oracle's 10.0 Vulnerability Exploited Since January by China-linked Group

Corredor de data center federal na madrugada com relógio de contagem regressiva vermelho de 72 horas e administrador de sistemas trabalhando sozinho em um laptop apoiado sobre rack aberto.

CVE-2026-21962 allows unauthenticated access to Oracle HTTP Server and WebLogic. U.S. federal agencies have until August 27 to apply the patch. The vulnerability has been actively exploited for eight months.

The Cybersecurity and Infrastructure Security Agency (CISA) of the United States included a high-severity Oracle vulnerability in its catalog of actively exploited vulnerabilities on Monday, August 24. Civil federal agencies have until this Wednesday, August 27, to apply the patch. The CVE-2026-21962, with a CVSS score of 10.0, allows an unauthenticated attacker with network access via HTTP to compromise the Oracle HTTP Server and Oracle WebLogic Server's Proxy Plug-in, resulting in access to or modification of critical data.


This vulnerability is not new. CloudSEK detected exploitation attempts in its honeypots on January 22, immediately after the public release of a proof-of-concept exploit. In July, SOCRadar reported that CVE-2026-21962 was one of the vulnerabilities used by a China-linked threat group in attacks against government infrastructure. What changes now is the regulatory deadline.


What KEV Really Means


For U.S. federal civil agencies, inclusion in the Known Exploited Vulnerabilities (KEV) catalog is binding under CISA’s Binding Operational Directive 22-01. Seventy-two hours is the standard in this cycle. For the rest of the market, KEV serves as a risk signal: devices that remain vulnerable become part of the preferred target map for criminal operators, who replicate what they see being used by state actors.


This case is rare. A score of 10.0 is the ceiling of the CVSS and usually comes with public detection, an exploit written, and presence in threat intelligence reports. CVE-2026-21962 has marked all three boxes for eight months. The question CISOs need to answer this week is not whether they are vulnerable. It is why they have not patched yet.


Who Still Runs Oracle WebLogic in Production


The product has an installed base in banks, insurance companies, governments, and telecommunications operators. In the U.S., WebLogic supports layers of integration and portals in legacy stacks that have resisted migrations to microservices in Kubernetes. In Europe, particularly in Germany and Spain, it is common to find WebLogic in payment and core banking stacks that underwent consolidations in the 2010s. In shared service centers in India and the Philippines, outsourced teams operate these instances on behalf of global clients.


The exposure pattern, therefore, is known. It is precisely the fragmentation of responsibility among the customer, integrator, and managed provider that stretches the interval between available patches and applied patches. Eight months after the publication of the PoC, there are still public instances of WebLogic without patches. Independent surveys of internet-wide scans place the number in the hundreds.


What CISA Is Signaling


The choice of a 72-hour deadline for a vulnerability disclosed in January carries a message. CISA no longer treats CVE-2026-21962 as something pending. It treats it as something that has been used in campaigns attributable to a state actor and continues to be exploited by opportunistic operators who copy the tactic. The short deadline reflects the real urgency of the moment, not the original disclosure calendar.


Oracle had not publicly commented on specific cases of exploitation by the time this article was published. The company included the fix in its Critical Patch Update cycle and made the patch available for affected versions. The operational burden now lies with the client.


BOD 22-01 is the most assertive mechanism in the regulatory security arsenal of the U.S. federal government. It waives internal risk assessments: if the CVE enters KEV, the patch is mandatory within the deadline, with no room for exceptions based on maintenance windows. Agencies that fail to comply are included in quarterly reports sent to the White House. The institutional weight is what makes the mechanism work in environments where the patch queue has historically stretched for months.


What This Reprices for Consultancies and Security Operations


For MDR and SOC teams serving multinational clients, CVE-2026-21962 means immediate scanning across the entire managed base and documented evidence of patched application by the deadline. For consultancies offering GRC, this case reinforces an old thesis: KEV needs to be included in the patch SLA by default, not as an exception. For the European bank that inherited WebLogic in an acquisition made a decade ago and never migrated, the week starts complicated.


Each CVE 10.0 that remains unpatched in production for eight months is a data point about the operational model. Not about the bug.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk