A maximum-severity flaw in Oracle WebLogic Server's proxy plug-in, tracked as CVE-2026-21962, has a CISA-mandated patch deadline of August 27, 2026 for U.S. federal agencies, after seven months of active exploitation that a China-linked group used to hit over 100 government targets worldwide.

Read the full story: Oracle WebLogic's CVE-2026-21962: The 3-Day Deadline Is Today →

Transcript

Oracle patched this bug in January. Attackers started exploiting it four days later, and they never stopped. It's called CVE-2026-21962, a maximum severity flaw in Oracle WebLogic's proxy plug-in, and it lets anyone with no login at all reach straight into the backend server. CISA only added it to its exploited vulnerabilities list on August 24th. But because this flaw checked every risk box, unauthenticated, internet facing, actively exploited, and catastrophic if it hits, agencies got the shortest deadline CISA hands out: three calendar days. That's today. And there's a new twist. Agencies don't just have to patch, they have to prove they weren't already breached. A China linked group has reportedly used this exact flaw against more than a hundred governments. If you run WebLogic, patching isn't the finish line anymore.