app.cubelet.ai← cubelet.ai
GRID42INTELLIGENCE TRACKERAI governance · compliance · regulatory signals
← All digests

VulnOps

2026-09-18
Today · VULNOPS

CISA issued urgent directives today on two critical vulnerabilities requiring immediate patching: a critical Oracle flaw with a three-day remediation mandate and an active exploitation warning for Trimble Cityworks deserialization vulnerability (CVE-2025-0994) targeting critical infrastructure. Vulnops practitioners must treat both as priority incidents given CISA's enforcement authority and confirmed active exploitation.

  • CISA Three-Day Patch Mandate for Critical Oracle Flaw: Federal agencies face binding compliance deadlines under CISA directives, and vulnops teams must align patch schedules with government-mandated timelines or face regulatory consequences.
  • Active Exploitation of Trimble Cityworks Deserialization Vulnerability (CVE-2025-0994): Confirmed active exploitation in critical infrastructure software elevates this from theoretical risk to immediate threat, requiring vulnops teams to prioritize assessment and patching for any Cityworks deployments in their environment.
  • Dual-Vector Vulnerability Pressure on Compliance Calendars: Simultaneous critical advisories force vulnops practitioners to triage competing patching demands and may require escalation of change management timelines to meet regulatory expectations.

Immediately inventory Oracle and Trimble Cityworks instances, confirm patch availability, and initiate emergency change requests to meet CISA's three-day deadline and address active exploitation risks.

Signals in this digest
CISA Gives Agencies Just Three Days to Patch Critical Oracle Flaw

Because attackers are actively exploiting the vulnerability, CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog and given US federal civilian agencies just three days to secure affected systems. That is the shortest remediation deadline CISA is authorised to impose. What Is CVE-2026-21962? CVE-2026-21962 is classified as an improper access-control vulnerability. [...] For internet-facing enterprise software, waiting until the next routine monthly maintenance window may no

CISA warns of hackers targeting vulnerability in Trimble Cityworks to conduct RCE

The Cybersecurity and Infrastructure Security Agency warned hackers are targeting a vulnerability in Trimble Cityworks that could allow an attacker to conduct remote code execution. The deserialization vulnerability, tracked as CVE-2025-0994, can enable an attacker to conduct remote code execution against a user's Microsoft Internet Information Services web server, according to the CISA advisory. [...] 2. Types of car insurance 3. Find life insurance 6. Taxes 1. How to file