
CVE-2024-21287 lets attackers bypass auth in Oracle's WebLogic Server. Zero-click RCE through deserialization flaws. ShinyHunters already weaponized it — scanning for unpatched .edu domains since last week. How many student SSNs before CISOs wake up?
Post summary
CVE‑2024‑21287 is a zero‑click RCE that allows authentication bypass in Oracle WebLogic. ShinyHunters have weaponized it and are actively scanning unpatched .edu domains.

