CVE-2017-10271Active Exploitation(oracle / weblogic_server)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for oracle weblogic_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblogic_server

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Peaked 3d ago at 1 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
weblogic_server

4 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-01: 1Mentions · 2026-04-08: 1Mentions · 2026-06-04: 1Mentions · 2026-07-22: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-07-22: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-08: 1Technical Details · 2026-06-04: 1Technical Details · 2026-07-22: 104-0104-0806-0407-22
Signal classification2 categories
Active Exploitation
375.0%
Exploit
125.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-011
Active Exploitation1
2026-04-081
Active Exploitation1
2026-06-041
Active Exploitation1
2026-07-221
Exploit1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Active Exploitation

    Oracle WebLogic 脆弱性 CVE-2026-21962 (CVSS 10.0):実環境での継続的な悪用を確認 https://iototsecnews.jp/2026/04/01/hackers-actively-exploit-critical-weblogic-rce-vulnerabilities-in-ongoing-attacks/ Oracle WebLogic Server の脆弱性である CVE-2026-21962 が、実環境で積極的に悪用され続けています。この脆弱性を悪用する攻撃者は、認証を必要とせずに外部から OS コマンドを実行できます。攻撃者はパス・トラバーサルという手法を悪用し、本来アクセスできない領域を操作することで、システムの制御権を奪おうとします。また、過去に報告された CVE-2020-14882 や CVE-2017-10271 といった既知の脆弱性も、依然として攻撃の入り口として狙われています。これらは、設定の不備や修正プログラムの未適用を突くものであり、自動化されたツールにより日々スキャンされています。ご利用のチームは、ご注意ください。 #CVE202621962 #Exploit #Oracle #Vulnerability #WebLogic

    Post summary

    Oracle WebLogic Server’s CVE-2026-21962, rated CVSS 10.0, is confirmed to be actively exploited in production, enabling unauthenticated attackers to execute OS commands via path‑traversal techniques.

    02011161
    483 followersView on X
  • RST Cloud@rst_cloud
    Exploit

    #threatreport #HighCompleteness Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries | 20-07-2026 Source: https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve Key details below ↓ 💀Threats: Adaptixc2_tool, Supershell, Nginx_rift_vuln, Clickfix_technique, Impacket_tool, Goby_tool, 🎯Victims: Government, Universities, Healthcare, Financial services, Academic, Private sector 🏭Industry: Government, Financial, Education, Healthcare 🌐Geo: Italy, Brazil, France, Vietnam, Singapore, Australia, Chinese, South korea, United states, Indonesia, United kingdom, Ireland, New zealand 🔓CVEs: CVE-2023-27350 \[[Vulners](https://vulners.com/cve/CVE-2023-27350)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - papercut papercut_mf (<20.1.7, <21.2.11, <22.0.9) - papercut papercut_ng (<20.1.7, <21.2.11, <22.0.9) CVE-2026-4480 \[[Vulners](https://vulners.com/cve/CVE-2026-4480)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - redhat openshift_container_platform (4.0) - samba (<4.2.1) - redhat enterprise_linux (7.0, 8.0, 9.0, 10.0) CVE-2026-26980 \[[Vulners](https://vulners.com/cve/CVE-2026-26980)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True Soft: - ghost (<6.19.1) CVE-2024-3273 \[[Vulners](https://vulners.com/cve/CVE-2024-3273)] - CVSS V3.1: *7.3*, - Vulners: Exploitation: True Soft: - dlink dns-320l_firmware (1.01.0702.2013, 1.03.0904.2013, 1.11) CVE-2026-20253 \[[Vulners](https://vulners.com/cve/CVE-2026-20253)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - splunk (<10.0.7, <10.2.4) CVE-2026-42945 \[[Vulners](https://vulners.com/cve/CVE-2026-42945)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - f5 dos (le4.7.0, 4.8.0) - f5 nginx_gateway_fabric (le1.6.2, le2.5.1) - f5 nginx_ingress_controller (le3.7.2, le4.0.1, le5.4.1) - f5 nginx_instance_manager (le2.21.1) ... CVE-2017-10271 \[[Vulners](https://vulners.com/cve/CVE-2017-10271)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - oracle weblogic_server (10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0) 📚TTPs: ⚔️Tactics: 2 🛠️Technics: 0 🤖LLM extracted TTPs:` T1190, T1583.001, T1583.003, T1588.002, T1588.005, T1595.002 🧨IOCs: - IP: 2 - File: 4 - Hash: 1 - Domain: 4 💽Software: NGINX, PaperCut, WebLogic, mysql, GoDaddy 🔢Algorithms: sha256 🔠Functions: system ⚙️Win Services: print-spooler 📜Programming Languages: golang, javascript, python #threatreport: In mid-2026, significant vulnerabilities were discovered in NGINX and Ghost CMS, leading to potential cyber exploits targeting governmental and financial institutions across eleven countries. The two primary vulnerabilities included NGINX Rift (CVE-2026-42945), a heap overflow in the NGINX rewrite module, and a blind SQL injection in the Ghost CMS Content API (CVE-2026-26980). Public exploit code for both was released shortly after their discovery, prompting attackers to develop and deploy creative methods to leverage these vulnerabilities. An exposed directory on an active Singapore-based VPS revealed the operational details of a cyber threat actor leveraging these vulnerabilities. The directory, housing a variety of exploits, contained tools for multiple attack techniques, including reverse shell setup and out-of-band (OOB) DNS callbacks to confirm malware execution. The target sectors indicated a strategic approach, primarily focusing on high-value entities like federal governments, educational institutions, healthcare providers, and financial services. The NGINX Rift vulnerability was used in targeted attempts to exploit live infrastructure. An exploitation script (http://poc.py) relied on specific memory addresses and settings that necessitated a low-security environment, indicating a phase of development rather than direct application on active targets. The actor’s exploration revealed little success during these attempts. On the other hand, the Ghost CMS exploit allowed the attacker to interact with the database without authentication, making it easier to extract sensitive information. By running a public exploit script, the actor conducted checks to identify vulnerable hosts and subsequently attempted data extraction. The implications of CVE-2026-26980 extend beyond this singular event, as it had been previously associated with larger campaigns aimed at mass exploitation. Additional exploits in the toolkit included those targeting well-known vulnerabilities in systems such as PaperCut, Oracle WebLogic, and D-Link NAS devices. The operator's use of OOB verification methods, like directing DNS queries to uniquely generated subdomains, offered a means to validate successful exploit execution despite potential network response filtering. Command and control infrastructure included the presence of widely recognized exploitation frameworks like AdaptixC2 and Supershell, although these tools were not directly linked to any specific intrusion captured in the analysis. The operational artifacts uncovered indicated a systematic approach to database exploitation, along with diligent targeting across nations including Brazil, France, South Korea, and others, primarily within sectors that handle sensitive data. While specific compromise outcomes were not confirmed in the gathered evidence, this activity exemplified a competent cyber threat actor exploiting newly discovered vulnerabilities and old, effective techniques with awareness and precision. The existence of these exploits and their deliberate targeting underscores the need for heightened vigilance and proactive defense measures within the cybersecurity landscape to mitigate similar attacks.

    Post summary

    The report documents the release of public exploit code for NGINX Rift (CVE-2026-42945) and Ghost CMS blind SQL injection (CVE-2026-26980), including detailed technical info and evidence of active exploitation attempts across multiple high-value sectors, underscoring an increased threat landscape.

    00010302
    721 followersView on X
  • Alias Robotics@AliasRobotics
    Active Exploitation

    🚨 Myth busted: AI-augmented hackers aren't hunting sci-fi zero-days. The top bug in 26M prompts is a Kubernetes flaw from 2019 (CVE-2019-11248) &amp; an Oracle RCE from 2017 (CVE-2017-10271). AI is mass-automating the exploitation of old technical debt. https://t.co/697p56ZNqN

    Post summary

    The tweet asserts that AI is automating attacks against older Kubernetes and Oracle vulnerabilities, implying active exploitation of known flaws.

    10000105
    1.4K followersView on X
  • ZeitTrender@ZeitTrender
    Active Exploitation

    🚨 Hackers are actively exploiting a new critical (CVSS 10.0) unauthenticated RCE in Oracle WebLogic Server — CVE-2026-21962 — along with several older high-severity flaws (CVE-2020-14882/83, CVE-2020-2551, CVE-2017-10271). Exploitation of the new flaw began the same day public PoC dropped. Honeypots saw immediate automated attacks. Full details: https://gbhackers.com/hackers-exploit-critical-weblogic-rce-vulnerabilities/

    Post summary

    A critical unauthenticated RCE in Oracle WebLogic Server (CVE-2026-21962) is being actively exploited, with a public PoC released the same day and automated attacks observed in honeypots.

    00000100
    59 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.1.0--
Apporacleweblogic_server12.2.1.2.0--

Explore more