INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Oracle WebLogic CVE-2024-21182 Exploit Added to Catalog
| 2026-06-02 18:14 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The vulnerability, CVE-2024-21182 (CVSS score 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. This high-severity security flaw impacts Oracle WebLogic Server versions [IOC HIDDEN • LOGIN REQUIRED].0 and [IOC HIDDEN • LOGIN REQUIRED].0, making it a critical issue for organizations relying on this software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, recommending immediate patching by June 4, 2026, to secure networks.
Technical Mitigations AI-generated
• Patch Oracle WebLogic Server versions <a href="/auth/login?next=/detail/XbMDjJ4BHUyMcQl65m7U" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.0 and <a href="/auth/login?next=/detail/XbMDjJ4BHUyMcQl65m7U" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.0 to CVE-2024-21182 (CVSS score: 7.5) as soon as possible.
• Implement network access controls, such as firewalls or intrusion detection systems, to prevent unauthenticated attackers from exploiting the vulnerability remotely over T3 or IIOP protocols.
• Regularly review and update Oracle WebLogic Server configurations and applications to ensure they are patched against known vulnerabilities like CVE-2024-21182.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
12.2.•••.•••
14.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-21182CVE-2024-21182
CVE-2026-21962CVE-2026-21962
CVE-2020-2883CVE-2020-2883
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
July 2024
Threat actors used automated exploitation attempts to target Oracle WebLogic CVE-2026-21962.
Click on any entity below to view its context and source!
organisation
Oracle
It was
patched
by Oracle in July 2024.
organisation
CVE-2026-21962
Earlier this March, CloudSEK also
disclosed
that another maximum-severity security flaw in WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts shortly after exploit code became publicly available.
organisation
CloudSEK
Earlier this March, CloudSEK also
disclosed
that another maximum-severity security flaw in WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts shortly after exploit code became publicly available.
organisation
WebLogic
Earlier this March, CloudSEK also
disclosed
that another maximum-severity security flaw in WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts shortly after exploit code became publicly available.
organisation
CVSS
Earlier this March, CloudSEK also
disclosed
that another maximum-severity security flaw in WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts shortly after exploit code became publicly available.
organisation
Oracle WebLogic
"Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
January 2025
Threat actors used a previously disclosed vulnerability in Oracle WebLogic Server to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Click on any entity below to view its context and source!
organisation
CVSS
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1584.004 - Server
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1588.006 - Vulnerabilities
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
vulnerability
CVE-2020-2883
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
vulnerability
CVSS score 9.8
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
Known Exploited
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
KEV
In January 2025, the U.S. Cybersecurity and Infrastructure Security Agency
added
another Oracle WebLogic Server flaw, tracked as
CVE-2020-2883
(CVSS score 9.8),to its
Known Exploited Vulnerabilities (KEV) catalog
.
Jun 02, 2026
Threat actors exploited a known vulnerability in Oracle WebLogic, CVE-2024-21182.
2026/06/02
U.S. CISA added the Oracle WebLogic CVE-2024-21182 flaw to its Known Exploited Vulnerabilities catalog after successful exploitation of an unauthenticated vulnerability allowing attackers to access sensitive information on affected servers via T3 or IIOP protocols.
Click on any entity below to view its context and source!
organisation
Oracle WebLogic CVE-2024-21182
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation.
organisation
KEV Catalog After Active Exploitation
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation.
organisation
Oracle WebLogic
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
infrastructure
12.2.1
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
infrastructure
4.0
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
infrastructure
14.1.1
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
infrastructure
0.0
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
organisation
WebLogic
Successful exploitation could allow attackers to access critical data or potentially obtain full access to all data available through the compromised WebLogic Server instance.
organisation
IIOP
An unauthenticated attacker with network access via IIOP, T3 can exploit the issue to compromise Oracle WebLogic Server.
organisation
T3
An unauthenticated attacker can exploit the issue remotely over the T3 or IIOP protocols to gain unauthorized access to sensitive information stored on affected servers.
June 4, 2026
Threat actors exploited the Oracle WebLogic CVE-2024-21182 vulnerability and recommended affected Federal Civilian Executive Branch agencies apply necessary fixes by June 4, 2026.
Click on any entity below to view its context and source!
attribution
Federal Civilian Executive Branch
In light of active exploitation of the flaw, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by June 4, 2026, to secure their networks.
attribution
FCEB
In light of active exploitation of the flaw, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by June 4, 2026, to secure their networks.
Tactical Metrics
Metrics
infrastructure
12.2.1
Software Version
Click for context!
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
Metrics
infrastructure
4.0
Software Version
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
Metrics
infrastructure
14.1.1
Software Version
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
Metrics
infrastructure
0.0
Software Version
The
CVE-2024-21182
flaw is an easily exploitable vulnerability affecting Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0.
Intelligence Sources
The Hacker News
2026-06-02
Security Affairs
2026-06-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Oracle WebLogic CVE-2024-21182
entity
11x
attribution
Attributing Entity
Vulnerability / Network Security
authority
6x
timeline
Temporal Reference
Jun 02, 2026
date
4x
infrastructure
Software Version
12.2.1
version
3x
vulnerability
Exploited CVE
CVE-2024-21182
cve
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
vulnerability
CVSS Score
8
score
Contextual Telemetry
Context Block
3 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
general metric
Vulnerability
8
vulnerability
general metric
Jun
2
jun
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.