The images in this article were generated with artificial intelligence. How we publish
The US Agency for Infrastructure and Cybersecurity. US (CISA) has given a clear and urgent order: federal agencies must secure their systems against a critical failure in Oracle WebLogic Server (traced as CVE-2024-21182) which, although Oracle patched it in July 2024, is now being actively exploited on the network.
This is a remote execution vulnerability that can be exploited without credentials and with low complexity through the T3 and IIOP application protocols in WebLogic facilities (versions 12.2.1.4.0 and 14.1.1.0.0), and Oracle warned from his safety bulletin that a successful explosion can give full access to the data accessible by the affected server. For technical details and Oracle's notice, see the July 2024 official patch bulletin: Oracle CPU Jul 2024.

The urgency of CISA is not anecdotal: public scans show that there are still hundreds of WebLogic instances exposed on the Internet that match vulnerable versions - Shodan detects around 1,592 servers between the two versions concerned - which offers attackers a wide area for automated operation. You can check those searches in Shodan here: instances 12.2.1.4.0 and instances 14.1.1.0.0.
That a parched vulnerability two years ago resurrects in active attacks illustrates a known pattern: the product cycle → patch → slow deployment. Many organizations maintain inherited servers, lack reliable inventory or expose critical middleware to the Internet for operational convenience, making WebLogic a lucrative target for actors seeking initial access for data theft or ransomware deployment. CISA has added the entry to the catalogue of vulnerabilities exploited in practice and has ordered corrections under the BOD 22-01 regulations that require federal authorities to mitigate certain vulnerabilities within limited time limits: CISA alert of 1 June 2026 and the binding directive: BOD 22-01.
For managers and risk managers this means making concrete decisions immediately: patch to corrected versions or apply official mitigation, isolate or disconnect from the perimeter WebLogic servers accessible from the Internet, and block or filter T3 / IIOP traffic at firewall / ACL level where possible. If there are no applicable mitigation, CISA recommends that the product be discontinued.
In addition to the patch, organizations should prioritize detection and response actions: review access records and JVM in search of unusual connections on the typical WebLogic ports (e.g. 7001 / 7002), search for user creation or suspicious web shells, deploy detection rules in EDR / SIEM for WebLogic operating patterns and conduct threat hunting focused on side movements from exposed instances. Making verifiable backup and recovery plans restores resilience to commitments that evolve to mass extortion or encryption.

The strategic lesson is clear: patches are necessary but not sufficient. It is essential to maintain a reliable inventory of software and exposures, apply network segmentation that prevents critical middleware from being accessible from the Internet and have accelerated patching processes for products that are historically the frequent target of malicious actors. CISA has already listed multiple Oracle vulnerabilities exploited in the past, which emphasizes that the Oracle surface deserves continuous governance and monitoring processes: Oracle's exploited vulnerability catalogue.
If you manage cloud environments or tercerized services, review the cloud contracts and guides on shared responsibility and apply the BOD 22-01 guide for cloud services; mitigation may vary according to whether the instance is self-managed or provided by a supplier. Finally, communicate and coordinate with business teams before taking disruptive actions: a patch or poorly coordinated isolation may affect critical applications, but keeping vulnerable servers in production is a higher risk.
In short, the emergence of exploits for CVE-2024-21182 two years after the patch reminds us that effective safety requires inventory, rapid patches, network mitigation and preparation for detection and incidents. Acting now reduces the likelihood of becoming the next victim of a holding that is, according to the category of CISA, known and active.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...