CISA adds a CVSS 10.0 Oracle WebLogic flaw to its exploited list and gives federal agencies a three-day patch window.