CISA flags two-year-old Oracle flaw as actively exploited in attacks
CISA added a two-year-old Oracle WebLogic flaw to its exploited-in-the-wild list and told federal agencies to patch by June 4.
Intelligence analysis by GPT-5.4 Mini

CISA says CVE-2024-21182 in Oracle WebLogic Server is being actively exploited and has ordered federal agencies to patch by June 4 under BOD 22-01. Oracle fixed the bug in July 2024, but Shodan still shows more than 1,592 exposed servers online.
A broken lock on a popular office computer program is being used by attackers. CISA told government offices to fix it fast, like changing a lock after seeing burglars use it.
Analysis
What happened
CISA added CVE-2024-21182 to its catalog of vulnerabilities exploited in attacks and ordered U.S. federal agencies to patch Oracle WebLogic Server systems by midnight on Thursday, June 4 under Binding Operational Directive 22-01. The agency also urged private-sector defenders to patch as soon as possible.
The vulnerability
Oracle says the flaw can be exploited remotely with no privileges and low complexity on WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. In Oracle’s own wording when it patched the issue in July 2024, a successful attack could lead to unauthorized access to critical data or to all data accessible to the WebLogic Server instance.
Exposure and response
The article cites Shodan data showing more than 1,592 WebLogic servers exposed online and vulnerable to exploitation, including 961 running version 12.2.1.4.0 and 631 running version 14.1.1.0.0. CISA warned that this kind of flaw is a frequent attack path for malicious actors and said defenders should apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or stop using the product if no mitigation is available.
Broader pattern
The story also places this advisory alongside earlier Oracle-related CISA action, including an October order to patch an exploited Oracle E-Business Suite SSRF flaw and a March Oracle out-of-band fix for a critical Identity Manager and Web Services Manager issue. CISA has now flagged 43 Oracle vulnerabilities as exploited in the wild over several years, 12 of them tied to ransomware attacks.
Key points
- CISA says CVE-2024-21182 is being actively exploited in attacks.
- Federal agencies must patch Oracle WebLogic Server by June 4 under BOD 22-01.
- Oracle patched the flaw in July 2024, but many exposed servers still appear online.
- Shodan data in the article shows more than 1,592 vulnerable WebLogic servers exposed to the internet.
- CISA urged all defenders to patch, mitigate, or discontinue use if mitigations are unavailable.
If agencies and other operators patch quickly, the active attack window can narrow fast. The advisory also gives defenders clear guidance: patch, apply vendor mitigations, or retire the product where mitigations are not available.
If exposed WebLogic servers stay unpatched, attackers may keep using the flaw to reach sensitive data or broader internal systems. The large number of internet-facing instances suggests many organizations may still be sitting on reachable targets.



