CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. The action requires Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in operators in the federal civilian branch to apply fixes by August 27, 2026. The directive reduces the window for further abuse of a CVSS 10.0 access-control bug that can expose or alter critical data.
Related Happenings
CISA BOD 26-04 Oracle EBS patch order
Public Sector Action
H score38
First: 16.07.2026 13:56
Last: 16.07.2026 13:56
Sources 1
About this happening:
CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...
CISA BOD 26-04 Oracle EBS patch order
Public Sector ActionAbout this happening: CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch Release
H score53
First: 29.06.2026 16:46
Last: 29.06.2026 16:46
Sources 1
About this happening:
Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)
Security Patch ReleaseAbout this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...
Latest development: 16.07.2026 13:56
CISA ordered U.S. federal agencies to secure Oracle E-Business Suite systems by Saturday, July 18, after confirming ongoing attacks against CVE-2026-46817 in Oracle Payments. Defused said it observed exploitation on Oracle E-Business honeypots over the weekend, and Oracle had already released the May 2026 Critical Security Patch Update for the flaw.
Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)
Vulnerability
H score52
First: 29.06.2026 16:46
Last: 29.06.2026 16:46
Sources 1
About this happening:
Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...
Oracle E-Business Suite unauth HTTP takeover security flaw (CVE-2026-46817)
VulnerabilityAbout this happening: Oracle E-Business Suite CVE-2026-46817 is under active exploitation, putting Oracle Payments deployments at takeover risk. The flaw allows unauthenticated HTTP a...
Latest development: 16.07.2026 13:56
CISA ordered U.S. federal agencies to secure Oracle E-Business Suite systems by Saturday, July 18, after confirming active exploitation of CVE-2026-46817 and adding it to its known exploited security flaws list. Oracle E-Business Suite's Oracle Payments File Transmission component allows an unauthenticated attacker with HTTP access to compromise Oracle Payments.
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector Action
H score53
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
CISA orders federal patching of Oracle WebLogic CVE-2024-21182
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch Oracle WebLogic Server against CVE-2024-21182 by June 4, creating an immediate remediation deadline for affected government...
Oracle WebLogic Server unauthenticated remote compromise flaw (CVE-2024-21182)
Vulnerability
H score59
First: 02.06.2026 15:40
Last: 02.06.2026 15:40
Sources 1
About this happening:
CVE-2024-21182 in Oracle WebLogic Server is actively exploited and can let a network-access attacker achieve unauthenticated remote compromise. The flaw affect...
Oracle WebLogic Server unauthenticated remote compromise flaw (CVE-2024-21182)
VulnerabilityAbout this happening: CVE-2024-21182 in Oracle WebLogic Server is actively exploited and can let a network-access attacker achieve unauthenticated remote compromise. The flaw affect...
Timeline
-
25.08.2026 09:12 2 articles · 2h ago
CISA adds CVE-2026-21962 to KEV catalog and sets federal fix deadline
Legal Policy Action UpdateCISA added CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The maximum-severity flaw, CVSS 10.0, is an unauthenticated HTTP access-control issue that can allow unauthorized access to instances or modification of critical data, and Federal Civilian Executive Branch agencies were recommended under BOD 26-04 to apply necessary fixes by August 27, 2026.
Show sources
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — thehackernews.com — 25.08.2026 09:12
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — thehackernews.com — 25.08.2026 09:12