The Patch Was Seven Months Old. The Deadline Is Three Days.
WHEN THE VENDOR PATCHES AND THE EXPLOIT DROPS ON THE SAME DAY
CVE-2026-21962. CVSS 10.0 – the maximum. An improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. Unauthenticated network access via HTTP. Successful exploitation: unauthorized access or modification of critical data, potential remote code execution, full compromise of backend WebLogic Server instances.
Oracle patched it in January 2026.
According to CISA, the first exploitation attempt occurred January 22, 2026 – the same day exploit code was published.
That's not a long-dormant vulnerability that sat in code for years before surfacing. That's a patch race the attackers won on day one.
Path traversal. Header manipulation. Bypassed proxy access controls. An unauthenticated attacker with network access gets in, and if they're fast enough – if they move before the patch window closes – they have standing access to backend systems nobody can see from outside.
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24, 2026. Federal deadline: August 27, 2026. That's three days for every federal civilian agency to identify affected Oracle HTTP Server and WebLogic instances, schedule the patch, test it, deploy it, and verify remediation across production environments.
Three days is not a deadline. It's a countdown to the agencies that didn't patch in January.
Oracle released the fix seven months ago. If you're patching this weekend, you weren't waiting for CISA to tell you it mattered. You were waiting for someone to tell you that you'd be held accountable for not doing it.
The math:
- January 2026: Oracle patches CVE-2026-21962
- January 22, 2026: Exploit code published; first exploitation attempt the same day
- August 24, 2026: CISA adds to KEV catalog, 215 days after the patch
- August 27, 2026: Federal deadline
215 days between patch and enforcement. Zero days between exploit publication and first attack.
Federal agencies had seven months to patch a maximum-severity flaw affecting critical infrastructure. The deadline isn't "when can you get to this?" The deadline is "prove you already did."
CISA doesn't add a vulnerability to the KEV catalog as a courtesy reminder. It adds it because exploitation is confirmed, federal agencies are confirmed targets, and the risk to critical infrastructure is no longer hypothetical.
A CVSS 10.0 doesn't sit dormant. It gets exploited the moment the researcher publishes the details, because every attacker with network access and a working HTTP client just got handed a skeleton key.
If your remediation plan for a maximum-severity enterprise vulnerability is "wait for CISA to make it mandatory," you don't have a security posture. You have a compliance checklist, and the attackers are already inside.
The vendor did its part. The researchers did their part. CISA did its part. The agencies that patch this over the weekend are fixing a seven-month-old problem the rest of the internet already knows about.
Three days to close a door that's been open since January.