CISA warns of active exploitation of Oracle WebLogic Server vulnerability
By
Dirk Knop
Toasted just enough. A reliable bake, gently seasoned.
Summary
A vulnerability in Oracle's WebLogic Server (part of Oracle Fusion Middleware) is being actively exploited by attackers. The flaw has been known since mid-2024, with a patch available since Oracle's Critical Patch Update in July 2024. The US cybersecurity authority CISA has added it to the "Known Exploited Vulnerabilities" catalog and has given US federal agencies until June 4th to remediate the issue. The vulnerability allows attackers to fully compromise the affected instance.
Key quotes
· 3 pulledThe US cybersecurity authority CISA is currently warning about this.
The vulnerability has thus entered the 'Known Exploited Vulnerabilities' catalog, and US authorities have until June 4th to contain the vulnerability.
Attackers are targeting a vulnerability in Oracle's WebLogic Server. It allows for full compromise of the instance.
You might also wanna read
Cisco discloses actively exploited zero-day affecting up to 2 million IOS and IOS XE devices
Cisco disclosed an actively exploited zero-day vulnerability (CVE-2025-20352) affecting all supported versions of Cisco IOS and IOS XE, pote
arstechnica.com·8mo agoOpenSSL Vulnerability CVE-2025-15467: Stack Overflow with Remote Code Execution Risk
JFrog Security Research team reports on a newly disclosed OpenSSL vulnerability, CVE-2025-15467, which is a stack overflow issue that could
CVE-2026-10520: Critical Ivanti Sentry OS Command Injection Vulnerability Actively Exploited
Ivanti Sentry (formerly MobileIron Sentry) has a critical pre-authentication OS command injection vulnerability (CVE-2026-10520, CVSS 10.0)
Critical cPanel vulnerability under active attack allows full server hijacking
Security researchers have discovered a critical vulnerability in cPanel and WebHost Manager (WHM), widely used web server management softwar
Early Exploitation of React2Shell Vulnerability (CVE-2025-55182) Targets Critical Infrastructure
The article details early exploitation activity following the public disclosure of the critical React2Shell vulnerability (CVE-2025-55182).
X.Org Security Advisory: Multiple Vulnerabilities Fixed in X Server 21.1.19 and Xwayland 24.1.9
X.Org has released security advisories for multiple vulnerabilities in X.Org X server (prior to version 21.1.18) and Xwayland (prior to vers
