CISA added Oracle WebLogic Server vulnerability CVE-2024-21182 to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and ordered U.S. federal civilian agencies to patch affected systems by June 4 under Binding Operational Directive 22-01. The flaw affects WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0, carries a CVSS 7.5 rating, and can be exploited remotely by an unauthenticated attacker with network access using T3 or IIOP protocols.
Successful exploitation could expose sensitive information or give attackers full access to data reachable by the server, raising concern for both government and enterprise environments. Oracle issued fixes in July 2024, but CISA warned that WebLogic bugs are frequently used as initial access vectors, and reporting indicated more than 1,592 internet-exposed WebLogic servers may be vulnerable; private-sector organizations were also urged to patch quickly as attackers have historically leveraged WebLogic flaws for botnets, cryptomining, and ransomware activity.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-08, CISA added CVE-2026-42271 in BerriAI LiteLLM and CVE-2026-50751 in Check Point Security Gateway to its Known Exploited Vulnerabilities catalog after obtaining evidence of active exploitation in the wild. CISA said the flaws pose risk to the federal enterprise and require remediation under Binding Operational Directive 22-01.
Under Binding Operational Directive 22-01, CISA directed Federal Civilian Executive Branch agencies to patch or remediate CVE-2024-21182 by 2026-06-04. CISA also urged private-sector organizations to patch quickly due to the risk posed by the actively exploited flaw.
CISA added Oracle WebLogic Server vulnerability CVE-2024-21182 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The agency said the flaw could enable unauthorized access to sensitive or otherwise accessible server data.
Oracle released a patch for CVE-2024-21182 in Oracle WebLogic Server. The vulnerability affects versions 12.2.1.4.0 and 14.1.1.0.0 and can be exploited remotely by unauthenticated attackers with network access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.