ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-21182CVE-2026-21962

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21182
Unauthenticated Data Exposure in Oracle WebLogic Server via T3/IIOP

CVE-2024-21182 is a vulnerability in the Core component of Oracle WebLogic Server (part of Oracle Fusion Middleware) affecting supported releases 12.2.1.4.0 and 14.1.1.0.0. It is easily exploited by an unauthenticated attacker who has network reachability to the server over the T3 or IIOP protocols, with no credentials or user interaction required. A successful attack grants unauthorized access to critical data, potentially complete access to all data accessible to Oracle WebLogic Server, which is reflected in the confidentiality-only CVSS 3.1 base score of 7.5 (C:H/I:N/A:N). Any organization running an affected WebLogic version, especially where T3/IIOP listeners are reachable from the internet or from less-trusted network zones, is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-01, and its EPSS score of 74.2% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known.

Do: Apply the Oracle WebLogic security patch that fixes CVE-2024-21182 (delivered in Oracle's July 2024 Critical Patch Update) on versions 12.2.1.4.0 and 14.1.1.0.0, or upgrade to a patched release; as an interim mitigation, restrict T3/IIOP listener access to trusted hosts and networks. US federal agencies must follow BOD 22-01 timelines, and all defenders should hunt for exploitation activity given the KEV listing on 2026-06-01.

7.574% KEV
  • Oracle WebLogic Server (Core component, Oracle Fusion Middleware) 12.2.1.4.0 and 14.1.1.0.0
largetens of thousands of internet-exposed WebLogic servers (≈40,000–70,000 in public scans), with a far larger internal installed base
CVE-2026-21962
Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in

CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the fixes from Oracle's January 2026 quarterly update (advisory AV26-042) or later for Oracle HTTP Server and the WebLogic Server Proxy Plug-in on all affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 (IIS plug-in affected at 12.2.1.4.0 only). Prioritize internet-facing OHS, Apache and IIS front ends per CISA BOD 26-04 and the KEV required actions, and where patching is delayed, restrict HTTP access to trusted networks and review logs for signs of unauthorized data access or modification.

10.042% KEV
  • Oracle HTTP Server (Oracle Fusion Middleware) 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
  • Oracle WebLogic Server Proxy Plug-in for IIS 12.2.1.4.0
large~10,000-100,000 internet-exposed Oracle HTTP Server / WebLogic proxy front ends
Full article241 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 02, 2026Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was patched by Oracle in July 2024.

"Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server," CISA said.

"Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data."

There are currently no public reports about how the vulnerability is being exploited in the wild. That said, prior flaws in the software have been repeatedly weaponized by various threat actors to enlist them into botnets, mine cryptocurrency, and deploy ransomware.

Earlier this March, CloudSEK also disclosed that another maximum-severity security flaw in WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts shortly after exploit code became publicly available.

In light of active exploitation of the flaw, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by June 4, 2026, to secure their networks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html