Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-2555 | Unauthenticated deserialization RCE in Oracle Coherence via T3 Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 contain a deserialization flaw (CWE-502) in the Caching, CacheStore and Invocation components, rated 9.8 (critical). An unauthenticated attacker with network access to the T3 protocol — the listener typically exposed by Oracle WebLogic Server, which bundles Coherence — can send a crafted serialized payload and take over Coherence, effectively achieving remote code execution in the hosting Java process with no credentials or user interaction required. Beyond standalone Coherence, the flaw affects the Oracle Fusion Middleware products that bundle it, including Access Manager, WebCenter Portal, Commerce Platform, Rapid Planning and others. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03, EPSS estimates a ~97% probability of exploitation within 30 days, public PoCs and exploit write-ups exist, and related reporting flags it among vulnerabilities heavily used by Chinese state-sponsored hackers. Do: Apply the Coherence fixes from Oracle's January 2020 Critical Patch Update (or later) for Coherence 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 and for every listed product that embeds Coherence, prioritizing WebLogic-based deployments given active exploitation and the 9.8 CVSS. Until patched, restrict T3/T3S access to trusted networks and remove direct internet exposure of WebLogic listener ports, and keep this in your KEV/EPSS-driven remediation queue; hunt for unexpected code execution or outbound connections originating from T3 listeners. | 9.8 | 97% | KEV PoC ×3 |
| largetens of thousands of internet-exposed Oracle WebLogic/Coherence T3 servers (public scans show on the order of 10,000–50,000); total enterprise install base… | |
| CVE-2020-2883 | Unauthenticated RCE in Oracle WebLogic Server via T3/IIOP CVE-2020-2883 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle WebLogic Server that is reachable over the network via the T3 and IIOP protocols. An attacker with network access to a WebLogic listener can trigger the flaw without credentials or user interaction, and successful exploitation results in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact. The supported affected releases are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Oracle rates the flaw CVSS 9.8 (Critical), and it carries a very high EPSS of 94.9% (100th percentile), indicating near-certain near-term exploitation likelihood. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 amid active exploitation, with reports of hackers targeting WebLogic servers and the flaw included in Oracle's January 2025 patch cycle. Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server — Oracle's January 2025 patch release includes WebLogic fixes, and the affected releases (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0) must be patched per vendor instructions. Until patched, restrict network access to the T3 and IIOP listeners (e.g., firewall them to trusted hosts only), prioritize internet-facing instances, and hunt for signs of exploitation. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable. | 9.8 | 95% | KEV |
| largetens of thousands of internet-exposed WebLogic instances | |
| CVE-2024-0012 +1 in the same advisory: …9474 | Authentication Bypass in Palo Alto Networks PAN-OS Management Interface CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474. Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device. | 9.3 group max | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised | |
| CVE-2024-41713 | Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days. Do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement). | 9.1 | 98% | KEV ransomware |
| largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed | |
| CVE-2024-55550 | Authenticated Path Traversal in Mitel MiCollab Enables Local File Reading Mitel MiCollab contains a path traversal vulnerability (CWE-22) caused by insufficient input sanitization of file-path input. It is triggered when an authenticated user with administrative privileges submits crafted paths that escape the intended directory, allowing the attacker to read local files on the MiCollab server. On its own the flaw requires admin credentials, but it can be chained with CVE-2024-41713, an unauthenticated remote arbitrary file-read flaw in the same product, enabling remote attackers to read files without valid credentials. Any organization running Mitel MiCollab is affected; the available data does not specify affected or fixed version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, although no public proof-of-concept is known. Do: Apply Mitel's updates or mitigations per the vendor advisory immediately, prioritizing internet-facing MiCollab servers, and address the chained CVE-2024-41713 issue in the same maintenance cycle; where mitigations are unavailable, restrict or discontinue use per CISA KEV guidance. Check the Mitel advisory for exact fixed versions (not provided here), limit administrative access to trusted users, and review server logs for evidence of arbitrary file reads or follow-on ransomware activity. | 2.7 | 38% | KEV ransomware |
| moderatethousands of internet-exposed MiCollab servers (roughly 1k-10k instances) |
Full article416 words · extracted from helpnetsecurity.com · click to collapse
CISA has added Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic Server (CVE-2020-2883) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

The Mitel MiCollab vulnerabilities exploited
Mitel MiCollab is a popular enterprise collaboration suite.
CVE-2024-41713 and CVE-2024-55550 are both path traversal vulnerabilities.
The former is exploitable without authentication, and may allow an attacker to gain access “to provisioning information including non-sensitive user and network information and perform unauthorized administrative actions on the MiCollab Server.”
The latter can only be exploited by an authenticated attacker with administrative privileges, to access specific resources and non-sensitive system information. The vulnerability does not allow file modification or privilege escalation, Mitel says.
Both vulnerabilities were reported to Mitel by watchTowr researcher Sonny Macdonald. Two months after the patch for CVE-2024-41713 had been made available, he shared details about them publicly, as well as a proof-of-concept exploit chaining them together.
CVE-2024-55550 did not have a CVE number at the time and still doesn’t have a fix, but it’s “substantially mitigated” in MiCollab 9.8 SP2 (9.8.2.12) and will be addressed by Mitel in future product updates. (Patches for older MiCollab versions are also available.)
The Oracle WebLogic Server vulnerability
CVE-2020-2883 is an “easily exploitable” vulnerability that may allow an unauthenticated attacker with network access via IIOP or T3 protocols to execute code in the context of the service account and thus to compromise / take over a vulnerable Oracle WebLogic Server.
The vulnerability, which was a bypass of a patch for a previous one (CVE-2020-2555), was fixed in April 2020.
CISA’s additional advice
By adding the three flaws to its KEV catalog, the Cybersecurity and Infrastructure Security Agency effectively confirms their in-the-wild exploitation and tells US federal civilian executive branch agencies that they have three weeks to remediate them. Details about the attacks are usually not shared.
The interesting thing about this latest KEV update is that CVE-2020-2883 was flagged as exploited by CISA back in May 2020, before the KEV catalog was created. It’s unknown why the agency decided to add the flaw to it now, but it’s possible they received more recent reports of attacks in the wild.
In this latest KEV update, CISA has also urged users and administrators to review threat briefs and security bulletins related to CVE-2024-0012 and CVE-2024-9474, two vulnerabilities in Palo Alto Networks firewalls that have been exploited (as zero-days) by attackers in November 2024.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/08/mitel-micollab-oracle-weblogic-server-vulnerabilities-exploited-by-attackers/