Back to News
Vulnerabilities

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

Cyber RTJune 2, 20263 min read
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in Oracle WebLogic Server, CVE-2024-21182, to its Known Exploited Vulnerabilities Catalog due to active exploitation. This flaw allows unauthenticated attackers to control vulnerable servers. Although Oracle patched it in July 2024, agencies are urged to apply fixes by June 4, 2026. Previous WebLogic flaws have been exploited for botnets and ransomware.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a significant security vulnerability in Oracle WebLogic Server, adding it to its Known Exploited Vulnerabilities (KEV) Catalog. This decision is based on evidence of the flaw being actively exploited. The vulnerability, labeled CVE-2024-21182, carries a CVSS score of 7.5, indicating its high severity. It allows an unauthenticated attacker with network access to potentially take over affected servers, posing a substantial risk to systems using Oracle WebLogic Server. Oracle addressed this vulnerability with a patch released in July 2024. The flaw is described as an unspecified vulnerability that can be exploited via network access through T3 and IIOP protocols. If successfully exploited, attackers could gain unauthorized access to critical data or even complete access to all data accessible through the Oracle WebLogic Server. This makes the vulnerability particularly dangerous for organizations relying on this software for their operations. Despite the lack of public reports detailing how this vulnerability is being exploited in the wild, there is a history of similar flaws in Oracle WebLogic being used by threat actors. These actors have previously weaponized such vulnerabilities to create botnets, mine cryptocurrency, and deploy ransomware. This history underscores the potential for significant harm if the current vulnerability is not addressed promptly. In March, another severe security flaw in WebLogic, identified as CVE-2026-21962 with a maximum CVSS score of 10.0, was disclosed by CloudSEK. This flaw saw automated exploitation attempts soon after the exploit code was made publicly available. The rapid exploitation of these vulnerabilities highlights the urgent need for organizations to apply security patches as soon as they are released to protect their systems. Given the active exploitation of the CVE-2024-21182 vulnerability, CISA has recommended that Federal Civilian Executive Branch (FCEB) agencies implement the necessary fixes by June 4, 2026. This deadline is set to ensure that these agencies secure their networks against potential attacks that could exploit this vulnerability. Adhering to this recommendation is crucial for maintaining the integrity and security of federal systems. The article concludes by encouraging readers to stay informed about cybersecurity issues by following CISA on platforms like Google News, Twitter, and LinkedIn. This suggests a broader strategy of raising awareness and disseminating information to help organizations and individuals protect themselves against cybersecurity threats. By staying updated, stakeholders can take proactive measures to mitigate risks associated with newly discovered vulnerabilities. Overall, the addition of the Oracle WebLogic Server vulnerability to CISA's KEV Catalog serves as a critical reminder of the ever-evolving cybersecurity landscape. Organizations must remain vigilant and responsive to emerging threats by applying timely patches and updates to their systems. This proactive approach is essential to safeguarding sensitive data and maintaining the operational integrity of critical infrastructure.