# CISA added CVE-2024-21182, an actively exploited Oracle WebLogic Server vulnerability, to…

Published: 2026-06-01 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/7ef0fff3-b01e-4c1b-b2f7-badc98508724/cisa-added-cve-2024-21182-an-actively-exploited-oracle-weblogic-server

> CISA added CVE-2024-21182, an actively exploited Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities Catalog.

CISA has updated its Known Exploited Vulnerabilities Catalog to include CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server. The addition is based on evidence of active exploitation in the wild. Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies are required to remediate this vulnerability by the specified due date.

The vulnerability represents a frequent attack vector used by malicious cyber actors and poses significant risk to federal networks. While BOD 22-01 mandates remediation for federal agencies, CISA strongly recommends all organizations prioritize patching this vulnerability as part of their vulnerability management programs.

Oracle WebLogic Server is a widely deployed Java-based application server platform commonly used in enterprise environments. Active exploitation of this vulnerability indicates threat actors are already leveraging it in campaigns, making timely remediation critical for organizations running affected versions.

## Mentioned in this report

- Vulnerabilities: CVE-2024-21182 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7ef0fff3-b01e-4c1b-b2f7-badc98508724/cisa-added-cve-2024-21182-an-actively-exploited-oracle-weblogic-server.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
