CISA, the US cyber defense agency, flagged CVE 2026 21962, a maximum severity flaw in Oracle's WebLogic application server plug in, as actively exploited and gave federal civilian agencies 72 hours to patch.
CISA put federal civilian agencies on a 72-hour clock on August 24 to patch a maximum-severity flaw in Oracle's WebLogic Server Proxy Plug-in. It is the tightest patching deadline the agency has ever set for a known-exploited bug.
The agency added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24, citing evidence of active exploitation. The flaw scores 10.0 on the CVSS severity scale, the maximum, and lets an unauthenticated attacker compromise Oracle HTTP Server and the WebLogic Proxy Plug-in over HTTP without credentials.
The bug is not new. Oracle patched it in its January 2026 Critical Patch Update; what changed is that attackers are now using it in the wild. Under Binding Operational Directive 26-04, the 72-hour window replaces the two-week to one-month deadlines CISA has historically set for KEV entries and forces agencies to run a 2-hour scoping triage and a 2-to-24-hour containment cycle before remediation.
The federal clock does not bind private companies, state and local governments, or critical-infrastructure operators, even when they run the same Oracle software. The Register, which first reported the deadline, reads the August 24 escalation as a tempo signal: a January-patched bug is now treated as urgent infrastructure risk.
For organizations running Oracle HTTP Server or the WebLogic Server Proxy Plug-in, the practical read is direct: patch now, because exploitation is attested rather than theoretical.