The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago but is now being actively exploited in attacks.

Oracle WebLogic Server is an enterprise Java application server commonly used as middleware for large, distributed business applications.

The vulnerability, tracked as CVE-2024-21182, can be exploited remotely by attackers without any privileges. It affects Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 and can be targeted through low-complexity attacks.

Oracle said when it released patches in July 2024 that the flaw was easily exploitable by an unauthenticated attacker with network access through T3 or IIOP. A successful attack could allow unauthorized access to critical data or complete access to all data available through the affected Oracle WebLogic Server.

According to Shodan data, more than 1,592 Oracle WebLogic servers exposed online are currently vulnerable to CVE-2024-21182 exploits. This includes 961 servers running version 12.2.1.4.0 and 631 servers running version 14.1.1.0.0.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Thursday and ordered federal agencies to patch affected WebLogic servers by midnight on Thursday, June 4, under Binding Operational Directive 22-01.

Although the directive applies only to federal agencies, CISA also urged all network defenders, including private-sector organizations, to patch their systems as quickly as possible because the vulnerability is already being exploited.

CISA warned that this type of flaw is a common attack path for malicious cyber actors and creates serious risks for federal networks. The agency advised organizations to apply Oracle’s recommended mitigations, follow BOD 22-01 guidance for cloud services where applicable, or stop using the product if no mitigation is available.

READ
Germany, U.S. Shut Down Kratos Phishing Platform, Arrest Developer in Indonesia

This is not the first time CISA has warned agencies about exploited Oracle vulnerabilities. In October, the agency ordered federal agencies to patch an unauthenticated server-side request forgery flaw in Oracle E-Business Suite, tracked as CVE-2025-61884, after confirming it was being exploited in the wild.

More recently, Oracle released an emergency security update in March to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager, tracked as CVE-2026-21992. Oracle did not comment when asked whether that flaw had been exploited.

Over the past several years, CISA has flagged 43 vulnerabilities across Oracle products as exploited in real-world attacks, including 12 that have been used in ransomware campaigns.


Buy ExpressVPN with PayPal or Credit Card

Advertisement