A maximum-severity Oracle flaw is under active exploitation, with the U.S. Cybersecurity and Infrastructure Security Agency giving federal agencies no more than three days to implement a patch. See ...