VORANT. Threat Intelligence Sign in Get the full feed

CISA added CVE-2024-21182, an actively exploited Oracle WebLogic Server vulnerability, to…

high vulnerability government-national

CISA added CVE-2024-21182, an actively exploited Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities Catalog.

CISA has updated its Known Exploited Vulnerabilities Catalog to include CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server. The addition is based on evidence of active exploitation in the wild. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies are required to remediate this vulnerability by the specified due date.

The vulnerability represents a frequent attack vector used by malicious cyber actors and poses significant risk to federal networks. While BOD 22-01 mandates remediation for federal agencies, CISA strongly recommends all organizations prioritize patching this vulnerability as part of their vulnerability management programs.

Oracle WebLogic Server is a widely deployed Java-based application server platform commonly used in enterprise environments. Active exploitation of this vulnerability indicates threat actors are already leveraging it in campaigns, making timely remediation critical for organizations running affected versions.

Mentioned in this report

Vulnerabilities CVE-2024-21182KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free