“Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain ‘complete access’ to all data stored on the affected systems.”
CVSS 10.0, disclosed back in January, and CISA only now gives federal agencies three days. Honeypots caught automated scanning for it within weeks of disclosure, so attackers have had a seven-month head start. The deadline is the shortest CISA has ever issued, which tells you how bad the exposure got while everyone sat on it.