CISA has added a critical Oracle WebLogic Server vulnerability to its Known Exploited Vulnerabilities catalogue, confirming it is actively being used to deliver ransomware and remote access tools to unpatched servers. The federal agency remediation deadline is today, 4 June 2026.
- What it is: CVE-2024-21182 is a flaw in Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0) that allows an attacker to access data without needing a username or password. Exploitation requires only network access via standard WebLogic ports — no credentials needed.
- Who is affected: Organisations running Oracle WebLogic Server that have not applied Oracle's Critical Patch Update from July 2024. WebLogic is commonly used in enterprise Java application environments. This patch has been available for almost two years.
- What the risk is: Active attacks are delivering Sodinokibi ransomware, Cobalt Strike remote access beacons, and cryptocurrency miners to compromised servers. The vulnerability carries a CVSS score of 7.5. Attackers have been scanning for exposed WebLogic instances since mid-May 2026.
- What to do: Confirm whether your environment includes Oracle WebLogic Server and verify the July 2024 patch has been applied. If you are unsure, contact your IT provider immediately.
If your environment includes Oracle WebLogic Server, patching should be treated as urgent. We recommend confirming your exposure and patching status with your IT provider today.
Sources: CISA Known Exploited Vulnerabilities Catalog | Bleeping Computer | The Hacker News