Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962

Public Sector Action
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. The action requires Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in operators in the federal civilian branch to apply fixes by August 27, 2026. The directive reduces the window for further abuse of a CVSS 10.0 access-control bug that can expose or alter critical data.

Related Happenings

CISA BOD 26-04 Oracle EBS patch order

Public Sector Action
H score38 First: 16.07.2026 13:56 Last: 16.07.2026 13:56 Sources 1

About this happening: CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...

Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)

Security Patch Release
H score53 First: 29.06.2026 16:46 Last: 29.06.2026 16:46 Sources 1

About this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...

Latest development: 16.07.2026 13:56

CISA ordered U.S. federal agencies to secure Oracle E-Business Suite systems by Saturday, July 18, after confirming ongoing attacks against CVE-2026-46817 in Oracle Payments. Defused said it observed exploitation on Oracle E-Business honeypots over the weekend, and Oracle had already released the May 2026 Critical Security Patch Update for the flaw.

Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)

Vulnerability
H score52 First: 29.06.2026 16:46 Last: 29.06.2026 16:46 Sources 1

About this happening: Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...

Latest development: 16.07.2026 13:56

CISA ordered U.S. federal agencies to secure Oracle E-Business Suite systems by Saturday, July 18, after confirming active exploitation of CVE-2026-46817 and adding it to its known exploited security flaws list. Oracle E-Business Suite's Oracle Payments File Transmission component allows an unauthenticated attacker with HTTP access to compromise Oracle Payments.

CISA orders federal patching of Oracle WebLogic CVE-2024-21182

Public Sector Action
H score53 First: 02.06.2026 15:40 Last: 02.06.2026 15:40 Sources 1

About this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...

Oracle WebLogic Server unauthenticated remote compromise flaw (CVE-2024-21182)

Vulnerability
H score59 First: 02.06.2026 15:40 Last: 02.06.2026 15:40 Sources 1

About this happening: CVE-2024-21182 in Oracle WebLogic Server is actively exploited and can let a network-access attacker achieve unauthenticated remote compromise. The flaw affect...

Timeline

  1. 25.08.2026 09:12 2 articles · 2h ago

    CISA adds CVE-2026-21962 to KEV catalog and sets federal fix deadline

    Legal Policy Action Update

    CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The maximum-severity flaw, CVSS 10.0, is an unauthenticated HTTP access-control issue that can allow unauthorized access to instances or modification of critical data, and Federal Civilian Executive Branch agencies were recommended under BOD 26-04 to apply necessary fixes by August 27, 2026.

    Show sources