GCS Threat Briefing
Vulnerability Governance

The Patch Nobody Scheduled

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
August 2026 · 9 min read
GCS Threat Briefing cover: The Patch Nobody Scheduled. A dark brand panel stating that a CVSS 10.0 Oracle flaw went 216 days from vendor fix to confirmed exploitation, with three statistics: 10.0 CVSS on the Oracle proxy plug-in, 216 days from fix to confirmed exploitation, and four public exploits for the Palo Alto GlobalProtect agent with one flaw still unpatched. Garzon Cyber Solutions red and white on near-black.

The delay between a patch being published and a patch being applied is normally treated as a resourcing problem: too few engineers, too many systems, a change window that is always full. Two vulnerabilities that moved this week suggest a less comfortable explanation. In both cases the fix already existed. In both cases the software sits inside almost every large enterprise estate. And in both cases the patch was not late so much as unscheduled, because the asset it belongs to does not appear cleanly on any single team's list.

What happened

Two items, one day apart, in software most organisations would describe as trusted infrastructure rather than as attack surface.

On 24 August, CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue. The flaw carries a CVSS base score of 10.0, the maximum the scale allows. It is an improper access control weakness in the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS. The plug-in does not properly verify identity and permissions when it forwards requests from a front-end web server, which allows an unauthenticated remote attacker to craft HTTP requests that inherit the plug-in's own access rights. Affected versions run to 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Oracle disclosed the flaw and shipped the fix in its Critical Patch Update on 20 January 2026. These proxy components typically sit in a DMZ, in front of the application server they protect.

On 25 August, security researcher Martijn van Ramesdonk published five vulnerabilities in the Palo Alto Networks GlobalProtect app. He reported them to the vendor in early April 2026. Two became CVE-2026-0251, a set of local privilege escalation issues arising from an untrusted search path. A low-privileged user with access to an endpoint can reach NT AUTHORITY\SYSTEM on Windows, or root on macOS and Linux. Palo Alto's advisory confirms branches 6.0.x, 6.2.x and 6.3.x are affected across all three operating systems, with fixed builds at 6.3.3-h11, 6.2.8-h10 and 6.0.13, and 6.3.3-h2 and 6.0.11 on Linux. Mobile and UWP builds are unaffected. The CVSS base score is 8.5. The researcher additionally documented a technique for recovering Active Directory passwords by abusing privileged GlobalProtect components. Four proof-of-concept exploits are now public. A fifth issue remains unpatched and undisclosed. Palo Alto states it has no evidence of exploitation in the wild.

One distinction matters here and is easily missed. This is the GlobalProtect app, the client agent installed on the endpoint. It is not CVE-2026-0257, the PAN-OS portal authentication bypass that Qilin has been using for initial access. Different component, different patch, different owner. That distinction is the entire subject of this briefing.

The dated sequence

  • 20 January 2026Oracle discloses CVE-2026-21962 and ships the fix in its January Critical Patch Update. CVSS 10.0.
  • 22 January 2026NHS England Digital issues cyber alert CC-4739 covering the flaw. The alert records that a proof-of-concept exploit is already publicly available and that the National CSOC assesses exploitation as highly likely.
  • Early April 2026Van Ramesdonk reports five GlobalProtect app vulnerabilities to Palo Alto Networks under coordinated disclosure.
  • 24 August 2026CISA confirms active exploitation of CVE-2026-21962 and adds it to the KEV catalogue. 216 days after the fix was available.
  • 25 August 2026Van Ramesdonk publishes. Four working proof-of-concept exploits enter the public domain. One flaw remains unfixed.
10.0CVSS on the Oracle proxy plug-in, the maximum score
216days from vendor fix to confirmed exploitation
4public exploits for the VPN agent, with a fifth flaw unpatched

Why this pair is different

Neither vulnerability is exotic. Neither required a novel technique to find. What connects them is not the flaw class. It is where the software lives.

Vulnerability management programmes are organised around asset classes: servers, endpoints, network devices, applications, cloud services. Each class has an owner, a patch window and a compliance percentage. Mean time to patch is measured against the inventory, and the inventory is assembled from those classes. The model works well, right up to the point where a piece of software refuses to belong to one of them.

Both of these do exactly that.

The Oracle proxy plug-in is a module loaded into a web server that fronts an application server. Infrastructure owns the web server. The applications team owns WebLogic. Networks owns what sits in the DMZ. The plug-in is the connective tissue between all three, and connective tissue rarely has a name written against it.

The GlobalProtect app is a security agent, selected and deployed by the security or network function, running on endpoints managed by IT. The firewall team patches PAN-OS, because that is their appliance. The endpoint team patches the operating system and the productivity stack, because that is their build. The agent that security pushed onto every laptop in the business belongs, in operational practice, to neither.

The failure mode is not slow patching. It is absence from the list. A patch cycle cannot be late for an asset it never enumerated.

Infographic titled The Ownership Gap. Two columns compare the Oracle HTTP Server and WebLogic Proxy Plug-in against the Palo Alto GlobalProtect app. The Oracle column lists three candidate owners, infrastructure, applications and networks, and shows none accountable. The GlobalProtect column lists two candidate owners, the firewall team and the endpoint team, and shows none accountable. A red footer states that the patch cycle cannot be late for an asset it never enumerated. Garzon Cyber Solutions dark and red brand styling.
Both components run with elevated privilege. Neither belongs to a single function. That is the finding, not the CVE.

216 days is the number that matters

Oracle published the fix on 20 January. CISA confirmed exploitation on 24 August. Across those seven months nothing about the vulnerability changed. What changed is that an attacker got round to it.

That inverts the usual urgency argument. Security teams are conditioned to fear the zero day, the flaw with no available fix and no defensive option. The commercially expensive case is the opposite, and it is the one in front of us: a maximum-severity flaw, patched and publicly documented for over half a year, still live on an internet-facing component because nobody's remit quite covered it. The organisation was not outpaced. It was unaware.

For UK healthcare the sequence is sharper still. NHS England Digital published CC-4739 on 22 January, two days after the fix, and recorded at that point that a working exploit was already public and that its own CSOC judged exploitation highly likely. The warning was correct, specific, addressed to the right sector, and issued seven months before the outcome it predicted. Notification was never the constraint.

The GlobalProtect disclosure is the same shape at an earlier stage. Reported in April, patched by the vendor, and as of this week accompanied by four working exploits in public circulation. The window is open now, against an asset that most endpoint inventories record under installed software rather than under attack surface, and against a component that on a compromised laptop is the difference between a standard user and full administrative control of the device.

The commercial exposure for UK organisations

Regulatory

NIS2 reaches its national compliance milestone across Member States in October 2026, and vulnerability handling sits explicitly inside the risk management measures in-scope entities must be able to evidence. Cyber Resilience Act reporting duties, including the manufacturer obligation to notify actively exploited vulnerabilities, apply from 11 September 2026. For financial entities, DORA has entered its first genuine supervisory enforcement cycle, and ICT risk management under DORA covers patch management and third-party component tracking directly. A regulator asking how you manage vulnerabilities will not be satisfied by an inventory that happens to omit the component that was exploited.

Financial

The material exposure sits less in the incident itself than in what follows it. Cyber insurance is increasingly written with conditions tied to demonstrable remediation discipline against KEV-listed vulnerabilities. A maximum-severity flaw, with a vendor fix available since January and a national health service alert issued in the same week, is a difficult thing to characterise afterwards as unforeseeable.

Contractual

Enterprise buyers now audit supplier vulnerability management as a condition of contract, not as a courtesy. The question in a serious security assessment has quietly shifted from whether you patch to how you know what you have. An answer that rests on an inventory built by asset class will not survive a competent assessor, and losing that assessment costs revenue rather than merely reputation.

Governance

This is the one that belongs on a board agenda. Both vulnerabilities are governance findings wearing technical clothing. The question is not whether the organisation patches quickly. It is whether anyone can produce a named owner for every piece of software in the estate that runs with elevated privilege.

Infographic titled Seven Months Of Warning. A vertical timeline in Garzon Cyber Solutions red and white on a near-black background. Twentieth of January 2026, Oracle ships the fix, CVSS ten point zero. Twenty-second of January, NHS England alert CC-4739 records that a public exploit exists and assesses exploitation as highly likely. April, five GlobalProtect flaws reported to Palo Alto. Twenty-fourth of August, CISA confirms exploitation, 216 days after the fix. Twenty-fifth of August, four proof-of-concept exploits published, one flaw still unpatched.
Every warning in this sequence arrived on time. The gap was never information.

What leaders should do now

These are decisions rather than tasks, and they are deliberately not a complete programme.

1. Ask for the exception list, not the compliance rate. A patch dashboard reports on what is in scope. Ask instead for the list of installed software that no team has formally claimed. The length of that list is the actual finding, and in most organisations nobody has ever been asked to produce it.

2. Re-inventory by privilege, not by asset class. Anything running as SYSTEM or root, or capable of inheriting a service account's rights, belongs on one register with one owner regardless of which box it runs on. Security agents, proxy modules, backup clients and management agents all qualify. Most estates have never been mapped this way, which is precisely why this keeps happening.

3. Treat the KEV catalogue as a contractual clock rather than a technical feed. The moment a component in your estate is listed, an insurer, an enterprise customer and potentially a regulator all start counting. Decide now who is accountable for that clock, and what evidence you will hold to show when it stopped.

4. Make vendor disclosure practice part of due diligence. Coordinated disclosure timelines, credit conventions and how a vendor handles researcher reports are legitimate procurement questions. They tell you how quickly you will learn about the next one, which is a supply chain characteristic, not a matter of etiquette.

5. Assign the gap before the next disclosure, in writing. The category of software that sits between functions will not shrink. Cloud agents, identity connectors, observability collectors and AI tooling are all being deployed into the same structural blind spot right now. Naming an owner is a governance decision that costs nothing and can only be made once, in advance.

Where this stops being a patching problem

Nothing above is a tooling gap. Most organisations that missed CVE-2026-21962 already own a scanner capable of finding it. The gap is structural: an inventory built around the organisation chart rather than around privilege, and no single role accountable for the software that falls between functions. Buying another platform to sit on top of that arrangement adds cost without resolving the cause.

We built Garzon Cyber Solutions around that specific sequence. A security assessment establishes what is genuinely present and where privilege actually sits. Compliance work then translates it into evidence a regulator, an insurer or an enterprise buyer will accept, mapped to the frameworks they are already asking about. Specialist recruitment puts a named owner behind the result, so the capability survives the audit rather than decaying in the months after it. Delivered in that order, three things most companies buy separately stop behaving like three cost lines.

We are a young firm, the founder runs the work personally, and the technical delivery is done with established partners. What we will not tell you is that the answer is another product.

Three questions for leadership

Which piece of software in our estate runs at the highest privilege and has no named owner? If nobody can answer inside a working day, that delay is itself the answer.

How many days passed between the last KEV listing that affected us and our remediation, and who measured it? A number, from a person, not a percentage from a dashboard.

If an enterprise buyer asked us to evidence vulnerability ownership for components that sit between teams, what exactly would we send them? If the honest answer is a policy document, the assessment is already lost.

Infographic titled Five Decisions For This Week. A numbered branded action list in Garzon Cyber Solutions red and white on a near-black background. One, ask for the exception list, not the compliance rate. Two, re-inventory by privilege, not by asset class. Three, treat the KEV catalogue as a contractual clock. Four, make vendor disclosure practice part of due diligence. Five, assign the gap in writing before the next disclosure. Footer reads: the patch was not late, it was never scheduled.
Five decisions an executive can make without a technical briefing. Screenshot this one.

The strategic takeaway

Security spending is overwhelmingly organised around finding things faster. This pair of disclosures is a reminder that speed of detection is irrelevant when the object in question was never on the list to begin with. A maximum-severity flaw sat patched and publicly warned about for 216 days. A privilege escalation path now sits, with public exploit code, inside the security agent an organisation deployed specifically to reduce its risk.

The differentiating capability is not another platform, another feed, or another dashboard. It is an inventory organised around privilege, a named owner for every entry in it, and a leadership team willing to keep asking the first of the three questions above until the answer arrives with a name attached.

The tools you bought to reduce your attack surface are part of your attack surface. Someone has to own them.

Who owns the software that sits between your teams?

A focused review of privilege ownership across your estate: which components run elevated, who is formally accountable for each, how your remediation clock is measured against the KEV catalogue, and what evidence you could put in front of a regulator, an insurer or an enterprise buyer tomorrow morning.

Start the Conversation →

Confidence note: CVE-2026-21962 details, affected versions and the 20 January 2026 Critical Patch Update date are taken from Oracle's advisory and corroborated by NHS England Digital cyber alert CC-4739, published 22 January 2026, which is also the source for the publicly available proof-of-concept and the National CSOC assessment that exploitation was highly likely. The 24 August 2026 KEV addition is confirmed by CISA. CVE-2026-0251 affected branches, fixed builds and the CVSS base score of 8.5 are taken from the Palo Alto Networks security advisory. The count of five reported issues, four published proof-of-concept exploits, one unpatched issue, the Active Directory password recovery technique and the April 2026 report date are the researcher's own account as reported in trade press, and have not been independently verified by GCS. Palo Alto Networks states it is not aware of exploitation in the wild. The 216 day figure is calculated from 20 January to 24 August 2026 inclusive of the fix date.

Sources: Oracle Critical Patch Update Advisory, January 2026. Palo Alto Networks Security Advisory, CVE-2026-0251, GlobalProtect App Local Privilege Escalation Vulnerabilities. NHS England Digital, cyber alert CC-4739, 22 January 2026. CISA Known Exploited Vulnerabilities Catalog, addition dated 24 August 2026. GitHub Advisory Database, GHSA-h94g-f37w-qxpj. Reporting on the van Ramesdonk disclosure via Cybersecurity News and GBHackers, 25 August 2026. Regulation referenced: Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act). GCS Threat Briefings translate live incidents into the governance and commercial decisions boards and security leaders need to make.

#VulnerabilityManagement #Governance #AssetOwnership #NIS2 #CyberSecurity #CISO #ThirdPartyRisk #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent selling cybersecurity, compliance and technology to security and technology buyers, working alongside marketing and technical colleagues.