By The Hacker News
Publication Date: 2026-06-02 18:14:00
The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity vulnerability affecting the known exploited vulnerabilities in Oracle WebLogic Server (KEV) catalog based on evidence of active exploitation.
The vulnerability, CVE-2024-21182 (CVSS score: 7.5) allows an unauthenticated attacker with network access to take control of vulnerable servers. It was patched from Oracle in July 2024.
“Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server,” CISA said.
“Successful attacks on this vulnerability could result in unauthorized access to critical data or complete access to all accessible data on Oracle WebLogic Server.”
There are currently no public reports of the vulnerability being exploited in the wild. However, there were already previous errors in the software…




