Circuit Wire — a daily news update from the Circuit.
The US Cybersecurity and Infrastructure Security Agency added a maximum-severity Oracle vulnerability to its Known Exploited Vulnerabilities catalog on August 24 and gave federal civilian agencies three days to fix it. The flaw, tracked as CVE-2026-21962, carries a perfect severity score of 10 out of 10. It affects Oracle HTTP Server and the WebLogic Server Proxy Plug-in, software that sits in front of many corporate web applications.
An attacker needs no login and only network access over HTTP to exploit it, The Register reported. A successful attack lets an intruder create, delete, or change access to critical data, and in some cases gain complete access to everything stored on the affected system. Oracle listed versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 as vulnerable.
Oracle disclosed the bug and shipped a fix in its January 20 update, describing the attack as low in complexity. Public exploit code appeared soon after. The three-day window is the shortest remediation timeline CISA is authorized to set, a level it reserves for flaws under real and immediate attack. The agency has issued that same deadline only rarely this month, including for a critical flaw in the Python framework Ray and an administrative bug in N-able software.
Evidence of exploitation reaches back to the start of the year. Vikas Kundu, a cyber intelligence analyst at CloudSEK, ran a honeypot for twelve days between January 22 and February 3 and logged repeated attempts to hit the vulnerability, alongside older WebLogic exploits from 2020 and 2017. Kundu described high-volume, automated scanning, with tools such as the Nmap Scripting Engine dominating the malicious traffic. Much of it came from bots searching the internet for exposed servers.
Seven months passed between Oracle's patch and the catalog entry, a gap that left unpatched systems exposed while attackers refined their tools. The directive binds federal agencies, but the catalog is widely used across private industry as a patching priority list. Oracle web infrastructure runs behind many business portals and internal tools.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

