Rapid Exploitation of CVE-2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-10271 | Unauthenticated Remote Code Execution in Oracle WebLogic Server Oracle WebLogic Server (CVE-2017-10271) contains a remote code execution flaw in its WLS Security component, where an XMLDecoder deserialization bug allows unauthenticated attackers to execute arbitrary code. The flaw is triggered by sending specially crafted XML requests to exposed WebLogic HTTP endpoints, so any instance whose WebLogic ports are reachable by untrusted users is at risk. Successful exploitation yields arbitrary code execution on the application server host, and the bug has been widely leveraged to install cryptominers and ransomware payloads. Organizations running Oracle WebLogic Server — particularly instances directly exposed to the internet — are affected, and the flaw has been on CISA's Known Exploited Vulnerabilities catalog since 2022-02-10 with confirmed ransomware use. Exploitation is assessed as essentially certain in the near term (EPSS 100.0%, 100th percentile), and defenders should treat it as an actively exploited, high-priority issue. Do: Apply Oracle's updates for CVE-2017-10271 per Oracle's instructions (the vendor's required action for this KEV entry). Until patched, restrict network access to WebLogic HTTP/admin ports from untrusted networks and limit or remove access to the XML/WSAT endpoints used for exploitation. Because ransomware operators are known to exploit this flaw, review internet-exposed WebLogic instances for signs of compromise, such as unexpected processes, new scheduled tasks, webshells, or ransomware artifacts. | 7.5 | 100% | KEV ransomware PoC ×3 |
| large≈tens of thousands of internet-exposed WebLogic Server instances (total deployed install base likely higher, including internal-only servers) | |
| CVE-2020-14882 | Remote Code Execution in Oracle WebLogic Server CVE-2020-14882 is a remote code execution vulnerability in Oracle WebLogic Server; its relationship to CVE-2020-14750 (a WebLogic administration console flaw) indicates it is reachable over the network, likely without authentication. An attacker who can reach a vulnerable WebLogic instance can trigger the flaw and execute arbitrary code in the context of the server. Successful exploitation can yield full control of the affected host, enabling data theft, lateral movement, and potentially ransomware deployment (ransomware use is currently unknown). Any organization running Oracle WebLogic Server is affected; WebLogic is widely deployed as a Java application server in large enterprises and government networks, and instances are frequently exposed to the internet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a maximum EPSS score of 100%, indicating confirmed in-the-wild exploitation. Do: Apply Oracle's WebLogic Server updates per vendor instructions immediately, as this is a required action under the CISA KEV listing. Inventory environments for WebLogic deployments (commonly listening on ports 7001/7002), prioritize patching internet-facing instances, and restrict or firewall access to the WebLogic administration console until patched. Review access logs for signs of exploitation, and treat unpatched, externally reachable WebLogic servers as high risk given the 100% EPSS score and confirmed in-the-wild exploitation. | 9.8 | 100% | KEV PoC ×3 |
| large≈50,000–100,000 internet-exposed WebLogic systems (public internet-wide scan counts around 2020); many more deployed internally in enterprise networks | |
| CVE-2020-2551 | Unauthenticated Remote Code Execution in Oracle WebLogic Server via IIOP CVE-2020-2551 is a critical flaw in the WLS Core Components of Oracle WebLogic Server that allows an unauthenticated attacker with network access to the IIOP protocol to remotely compromise the server. An attacker sends crafted IIOP requests directly to a listening WebLogic instance and gains takeover of the server, with high impact to confidentiality, integrity, and availability (CVSS 9.8). Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0 are affected, spanning widely deployed enterprise and government middleware environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), indicating active and likely broad targeting. Because exploitation requires only network reachability to the IIOP listener and no credentials or user interaction, internet-exposed WebLogic servers are the primary targets. Do: Apply the Oracle fixes for CVE-2020-2551 (October 2020 Critical Patch Update) to each affected WebLogic release, or move to a patched supported release per Oracle's instructions, consistent with CISA's KEV required action. Until patched, block or restrict IIOP traffic to WebLogic listeners (default port 7001) from untrusted networks and remove direct internet exposure of WebLogic admin and application servers. Review access logs for anomalous IIOP connections and check patched and unpatched hosts for signs of compromise. | 9.8 | 93% | KEV |
| largeorder of 10,000–50,000 internet-exposed WebLogic instances (public internet-wide scans have repeatedly shown tens of thousands of hosts exposing WebLogic… | |
| CVE-2026-21962 | Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply the fixes from Oracle's January 2026 quarterly update (advisory AV26-042) or later for Oracle HTTP Server and the WebLogic Server Proxy Plug-in on all affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 (IIS plug-in affected at 12.2.1.4.0 only). Prioritize internet-facing OHS, Apache and IIS front ends per CISA BOD 26-04 and the KEV required actions, and where patching is delayed, restrict HTTP access to trusted networks and review logs for signs of unauthorized data access or modification. | 10.0 | 42% | KEV |
| large~10,000-100,000 internet-exposed Oracle HTTP Server / WebLogic proxy front ends |
Full article389 words · extracted from infosecurity-magazine.com · click to collapse
A critical Oracle WebLogic vulnerability was weaponized almost immediately after public exploit code became available, according to a new honeypot-based analysis covering attack activity between January 22 and February 3, 2026.
The research focused on CVE-2026-21962, a remote code execution (RCE) flaw with a CVSS score of 10.0, and found that attackers began exploiting the vulnerability on the same day the exploit was released.
The CloudSEK study, published on March 25, used a high-interaction honeypot designed to replicate a real Oracle WebLogic Server environment.
Researchers recorded widespread automated scanning and exploitation attempts, confirming how quickly threat actors weaponize newly disclosed vulnerabilities.
Rapid Exploitation Observed
The most significant finding was the speed at which attackers adopted the CVE-2026-21962 exploit. Logs showed the first exploitation attempt occurred on January 22, the same day the exploit code was published. Additional scanning activity appeared days later as more attackers began probing internet-exposed servers.
Researchers also observed ongoing exploitation attempts targeting older but still widely abused WebLogic vulnerabilities, including:
-
CVE-2020-14882/14883 console remote code execution
-
CVE-2020-2551 IIOP deserialization remote code execution
-
CVE-2017-10271 WLS-WSAT deserialization remote code execution
This pattern shows attackers continue to rely on a small number of well-known vulnerabilities that remain effective against unpatched systems.
Automated Scanning and Broad Attacks
CloudSEK confirmed that most of the observed attacks originated from rented virtual private servers hosted by common cloud providers.
Activity was dominated by automated scanning tools, including libredtail-http and the Nmap Scripting Engine.
The honeypot also captured numerous non-WebLogic attacks, including command injection, path traversal attempts and reconnaissance activity. Generic web reconnaissance was the most frequent activity, accounting for 967 requests from 78 unique IP addresses over the 12-day period.
Mitigation and Security Recommendations
The report concluded that organizations running Oracle WebLogic servers should prioritize patching and defensive controls immediately. Key recommendations include:
-
Apply the latest Oracle security patches immediately
-
Restrict administrative console access from the internet
-
Disable unnecessary protocols and ports
-
Deploy web application firewall filtering
-
Monitor logs for suspicious activity
"The data underscores the critical and immediate need for organizations to prioritize the patching of CVE-2026-21962 and implement robust layered defenses," CloudSEK warned, "including strict access control for the administrative console and WAF filtering, to mitigate the severe RCE risk posed by these unauthenticated exploits."
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/critical-oracle-weblogic-rce/