Active Exploitation
Two years on the shelf. Now it has CISA's name on it.
CVE-2024-21216, Oracle WebLogic Server, CVSS 9.8. Oracle patched it in the October 2024 CPU. CISA just KEV-listed it — meaning active exploitation is confirmed, federal agencies are on the clock, and the "should patch" conversation is over.
The BleepingComputer headline frames this as a "two-year-old flaw," which is technically true and completely misses the point. The flaw isn't the story. The story is that unpatched WebLogic instances are still sitting in federal and critical infrastructure networks in mid-2026, and someone is actively walking through the door Oracle left open eighteen months ago.
The vector is as clean as it gets for an attacker: AV:N/AC:L/PR:N/UI:N. No authentication. No user interaction. No complexity. WebLogic's T3 and IIOP protocols exposed to the internet, and a missing authorization check (CWE-862) between an unauthenticated request and complete server takeover. Affected versions are 12.2.1.4.0 and 14.1.1.0.0. If you applied the October 2024 CPU, you're covered. If your change management queue has been sitting on it — the queue loses.
The attack chain maps cleanly to what we've seen in prior WebLogic exploitation campaigns — CVE-2023-21839, CVE-2020-14882, same playbook. T1190 for initial access via the exposed endpoint, T1059 for post-exploitation RCE, T1505.003 for persistence via web shell. Threat actors scanning for exposed WebLogic don't need novel techniques here. They never did.
Worth cross-referencing: CVE-2024-20953, Oracle Agile PLM 9.3.6, CVSS 8.8, KEV-listed February 2025 with a federal remediation deadline that already passed in March. A deserialization flaw (CWE-502) in the HTTP Export component, exploitable by a low-privileged attacker. The exploit lifecycle model puts it at roughly 54% mass exploitation probability with an expected days-to-mass-exploitation of zero — the window isn't approaching, it's open. Two Oracle products. Same pattern: patched, forgotten, quietly weaponized.
CISA's decision to add a two-year-old Oracle flaw to the KEV catalog is an editorial statement every time it happens. Someone, somewhere, still hasn't patched. The attackers know exactly who. We are nothing if not consistent.
Three things worth doing right now if you're running WebLogic: audit any instance of 12.2.1.4.0 or 14.1.1.0.0 accessible via T3 or IIOP from the internet or untrusted segments, apply the October 2024 CPU if you haven't, and block T3/IIOP at the perimeter as a compensating control — those protocols have no business being internet-routable for most deployments. Check your Oracle PLM exposure separately while you're at it; the federal deadline on CVE-2024-20953 is already overdue.
Federal agencies are operating under mandatory remediation timelines per CISA BOD 22-01. For everyone else, the KEV listing is the operational trigger it's designed to be. Treat it that way.
Post summary
The post highlights that CVE‑2024‑21216 is actively exploited, stresses the need to apply the October 2024 CPU patch and block exposed protocols, and warns of similar patterns in other Oracle products.