CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
CISA has imposed a three-day patching deadline for a critical Oracle WebLogic Server vulnerability. The flaw carries a perfect-10 severity score and allows unauthenticated attackers to access critical data or achieve full server takeover via T3 and IIOP protocols. The vulnerability is currently being exploited in the wild. Oracle has released August 2026 updates to the EBS Java Critical Patch Update Checker to help administrators manage the remediation process.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ CISA set a three-day patching deadline for an Oracle flaw with a perfect-10 severity score.
- ✓ The Oracle WebLogic vulnerability is being actively exploited.
- ✓ Unauthenticated attackers can use the flaw to access critical data.
- ✓ Oracle released August 2026 updates to the EBS Java Critical Patch Update Checker.
What changed
CISA issued a three-day remediation window for an actively exploited Oracle WebLogic vulnerability.
Live updates
-
CISA mandates three-day patch for critical Oracle WebLogic flaw
CISA has imposed a three-day patching deadline for a critical Oracle WebLogic Server vulnerability. The flaw carries a perfect-10 severity score and allows unauthenticated attackers to access critical data or achieve full server takeover via T3 and IIOP protocols. The vulnerability is currently being exploited in the wild. Oracle has released August 2026 updates to the EBS Java Critical Patch Update Checker to help administrators manage the remediation process.
Why it matters
WebLogic Server is a widely used enterprise Java platform. A perfect-10 score indicates the highest possible risk level. Rapid patching is required because the flaw enables remote attackers to bypass authentication.
What is confirmed
- CISA set a three-day patching deadline for an Oracle flaw with a perfect-10 severity score.
- The Oracle WebLogic vulnerability is being actively exploited.
- Unauthenticated attackers can use the flaw to access critical data.
- Oracle released August 2026 updates to the EBS Java Critical Patch Update Checker.
Still unconfirmed
- The flaw enables server takeover via T3 and IIOP protocols.
What to watch next
- Confirmation of widespread server takeovers
- CISA updates on exploitation trends
- Oracle release of additional mitigation guides
confidence 90%Sources used for this update (5)
- The Register — CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
- SecurityWeek — CISA Warns of Exploited Oracle WebLogic Vulnerability
- The Hacker News — Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
- Oracle Blogs — August 2026 Updates to EBS Java Critical Patch Update Checker (EJCPUC)
- Field Effect — Oracle WebLogic Server flaw enables server takeover via T3 and IIOP
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community