CVE-2024-21182 entered CISA's KEV catalog after active exploitation evidence, requiring federal patching by June 4, 2026.

CISA is warning organizations that an Oracle WebLogic vulnerability patched nearly two years ago is being exploited in the wild.

CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively…