CVE-2024-20953Active Exploitation(oracle / agile_product_lifecycle_management)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch oracle agile_product_lifecycle_management systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-17. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agile_product_lifecycle_management

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 3 mentions (2026-05-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
agile_product_lifecycle_management

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-03: 3Mentions · 2026-06-02: 1Active Exploitation · 2026-05-03: 3Active Exploitation · 2026-06-02: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-06-02: 105-0306-02
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-033
Active Exploitation3
2026-06-021
Active Exploitation1
Full discourse4 posts
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    Two years on the shelf. Now it has CISA's name on it. CVE-2024-21216, Oracle WebLogic Server, CVSS 9.8. Oracle patched it in the October 2024 CPU. CISA just KEV-listed it — meaning active exploitation is confirmed, federal agencies are on the clock, and the "should patch" conversation is over. The BleepingComputer headline frames this as a "two-year-old flaw," which is technically true and completely misses the point. The flaw isn't the story. The story is that unpatched WebLogic instances are still sitting in federal and critical infrastructure networks in mid-2026, and someone is actively walking through the door Oracle left open eighteen months ago. The vector is as clean as it gets for an attacker: AV:N/AC:L/PR:N/UI:N. No authentication. No user interaction. No complexity. WebLogic's T3 and IIOP protocols exposed to the internet, and a missing authorization check (CWE-862) between an unauthenticated request and complete server takeover. Affected versions are 12.2.1.4.0 and 14.1.1.0.0. If you applied the October 2024 CPU, you're covered. If your change management queue has been sitting on it — the queue loses. The attack chain maps cleanly to what we've seen in prior WebLogic exploitation campaigns — CVE-2023-21839, CVE-2020-14882, same playbook. T1190 for initial access via the exposed endpoint, T1059 for post-exploitation RCE, T1505.003 for persistence via web shell. Threat actors scanning for exposed WebLogic don't need novel techniques here. They never did. Worth cross-referencing: CVE-2024-20953, Oracle Agile PLM 9.3.6, CVSS 8.8, KEV-listed February 2025 with a federal remediation deadline that already passed in March. A deserialization flaw (CWE-502) in the HTTP Export component, exploitable by a low-privileged attacker. The exploit lifecycle model puts it at roughly 54% mass exploitation probability with an expected days-to-mass-exploitation of zero — the window isn't approaching, it's open. Two Oracle products. Same pattern: patched, forgotten, quietly weaponized. CISA's decision to add a two-year-old Oracle flaw to the KEV catalog is an editorial statement every time it happens. Someone, somewhere, still hasn't patched. The attackers know exactly who. We are nothing if not consistent. Three things worth doing right now if you're running WebLogic: audit any instance of 12.2.1.4.0 or 14.1.1.0.0 accessible via T3 or IIOP from the internet or untrusted segments, apply the October 2024 CPU if you haven't, and block T3/IIOP at the perimeter as a compensating control — those protocols have no business being internet-routable for most deployments. Check your Oracle PLM exposure separately while you're at it; the federal deadline on CVE-2024-20953 is already overdue. Federal agencies are operating under mandatory remediation timelines per CISA BOD 22-01. For everyone else, the KEV listing is the operational trigger it's designed to be. Treat it that way.

    Post summary

    CVE‑2024‑21216 is confirmed to be actively exploited in the wild by CISA, with unpatched Oracle WebLogic Server instances exposed to the internet; immediate patching or network mitigation is urgently required.

    1000030
    16 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2024-20953 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-02-24, with a remediation due date of 2025-03-17, signaling confirmed exp

    Post summary

    CISA has confirmed that CVE-2024-20953 is actively exploited, with a remediation deadline, underscoring an ongoing security incident.

    1000032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-20953. What happened CISA added CVE-2024-20953 to the Known Exploited Vulnerabilities (KEV) catalog on 2025-02-24, with a remediation due date of 2025-03-17, signaling confirmed exploitation in the wild CISA KEV.

    Post summary

    CISA has added CVE-2024‑20953 to its KEV catalog, confirming active exploitation in the wild and providing a remediation due date.

    1000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-20953-agile-product-lifecycle-management-plm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to a discussion about CVE‑2024‑20953, indicating active exploitation, but provides no further technical, PoC, or remediation details.

    0000023
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleagile_product_lifecycle_management9.3.6--

Explore more