2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Oracle WebLogic Flaw CVE-2024-21182 Placed in CISA’s KEV Catalog Following Active Exploitation


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed a serious vulnerability affecting Oracle WebLogic Server into its Known Exploited Vulnerabilities (KEV) Catalog after detecting signs of active use by attackers. The flaw, tracked as CVE-2024-21182 and scored 7.5 on the CVSS scale, can be abused by an unauthenticated actor with network access to seize control of vulnerable WebLogic instances.

Oracle released a security update addressing the bug in July 2024. According to CISA, the weakness involves an unspecified defect in Oracle WebLogic that could be exploited over the network using protocols such as T3 and IIOP, enabling an unauthenticated attacker to compromise Oracle WebLogic Server.

CISA warned that successful exploitation may lead to unauthorized exposure of sensitive information or full access to any data reachable via the affected Oracle WebLogic Server deployments. While the agency’s listing is based on evidence of exploitation, there are currently no public technical write-ups detailing how attackers are leveraging the defect in the wild.

Historically, vulnerabilities in WebLogic have been rapidly weaponized by adversaries for purposes including adding compromised hosts to botnets, running cryptocurrency miners, and deploying ransomware. In a related incident earlier this year, security firm CloudSEK reported that a different, maximum-severity WebLogic vulnerability (CVE-2026-21962, CVSS 10.0) experienced automated exploitation attempts soon after proof-of-concept exploit code became available publicly.

Because CISA has determined this issue is being actively exploited, Federal Civilian Executive Branch (FCEB) agencies are urged to implement the available patches and mitigations no later than June 4, 2026, to protect their networks. For additional context and the official KEV listing, see CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

First published on June 3, 2026.
Last updated on July 15, 2026.