What is CVE-2024-21182?
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Timeline
- 2024-07-16Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-01Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-03First covered in a defend.network daily briefing
- 2026-06-04CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Affected product
Oracle WebLogic Server
Remediation Steps
- Apply the vendor security update for Oracle Weblogic Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
- Vulnerability Priority Report – Week 1 of June 2026 (June 1 – 7)
- Android, WinRAR, WordPress Kirki: Three critical zero-days under active exploitation (2026-06-03)
Browse all tracked CVEs in the defend.network CVE database →