Patch this Oracle vulnerability within 72 hours, CISA demands.NurPhoto via Getty ImagesWhile the July security patch roundup from Oracle included 1,449 bug fixes, addressing 1434 distinct Common Vulnerabilities and Exposures, which was a new record in terms of numbers, the U.S. Cybersecurity and Infrastructure Security Agency has now issued a new alert for an old “improper access control” CVE. What’s more, it has given Federal Civilian Executive Branch agencies just 72 hours from the August 24 alert to install the fix. The reason that CISA is so concerned about a vulnerability impacting Oracle’s HTTP server and WebLogic server proxy plugin that was actually disclosed in January along with the highest possible Common Vulnerability Scoring System severity rating of 10, and a patch to address it, is that it’s now known to be under active exploit in the wild.CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, which is reason enough for all organizations to take heed of the issues which it described as involving a “frequent attack vector for malicious cyber actors,” but it also took the unusual step of giving FCEB agencies the shortest possible deadline it is able to under Binding Operational Directive 26-04 of just three days to remedy the threat by patching it.BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to “prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation,“ CISA said. FCEB agencies must also check whether threat actors had already compromised their systems before the patch was applied.Of course, while the directive itself applies only to these agencies, CISA is quite clear, as are other security professionals, that all organizations must adopt what is known as risk-based vulnerability management; and that means prioritizing KEV catalog-listed vulnerabilities when it comes to patching.“The ebb and flow of the ‘Patch Apocalypse’ continues with no sign of slowing yet,” Todd Schell, principal product manager at Ivanti, told me. The problem is that not all Common Vulnerabilities and Exposures are created equal. “The patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities,” Schell warned, but you need to remain disciplined and remember even CVEs with high CVSS scores which are not exploited or are not internet-facing can be handled in a second round of patching. And, in case you need any further reminders, this means that the Oracle CVE-2026-21962 vulnerability has to be on your priority patching list. What are you waiting for?