---
schema: 1
kind: vulnerability
title: "CVE-2024-21182 — Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation"
headline: "CVE-2024-21182 — Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation"
summary: "Oracle WebLogic CVE-2024-21182 (CVSS 7.5) added to CISA KEV on evidence of active exploitation — an unauthenticated attacker reaching the T3 or IIOP listeners (default ports 7001/7002) gains unauthorized access to WebLogic-accessible data. Patched in Oracle's July 2024 CPU; the in-window signal is the fresh exploitation, not the 23-month-old fix. WebLogic remains common middleware in EU finance and public-sector estates (The Hacker News, 2026-06-02)."
discovered_at: "2026-06-03T05:00:02Z"
event_date: 2026-06-02
run_id: 2026-06-03-ee0eae61
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - info-disclosure
  - cisa-kev
  - patch-available
regions:
  - global
  - europe
sectors:
  - finance
  - public-sector
entities: []
cves:
  - id: CVE-2024-21182
    cvss: "7.5"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.oracle.com/security-alerts/cpujul2024.html"
    publisher: Oracle CPU July 2024
    role: primary
  - url: "https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html"
    publisher: The Hacker News
    role: corroborating
  - url: "https://securityaffairs.com/193027/security/u-s-cisa-adds-oracle-weblogic-flaw-to-its-known-exploited-vulnerabilities-catalog.html"
    publisher: Security Affairs
    role: corroborating
closed_sources: []
evidence:
  - quote: "CISA added CVE-2024-21182 to the Known Exploited Vulnerabilities catalog on 2026-06-01 \"based on evidence of active exploitation\" (The Hacker News, 2026-06-02)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Close internet exposure of Oracle WebLogic T3/IIOP and confirm the July 2024 CPU is applied** (§ 2, CVE-2024-21182). It is actively exploited unauthenticated; block T3/IIOP at the perimeter, restrict to internal admin subnets via connection filters, and alert on external initiators to ports 7001/7002."
migrated_from: briefs/2026-06-03.md
---

CISA added CVE-2024-21182 to the Known Exploited Vulnerabilities catalog on 2026-06-01 "based on evidence of active exploitation" ([The Hacker News, 2026-06-02](https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html)). The flaw (CVSS 7.5) lets an unauthenticated, network-positioned attacker abuse the T3 or IIOP protocol listeners — exposed by default on ports 7001/7002 — to obtain unauthorized access to WebLogic-accessible data, and on some configurations a more complete server compromise. It affects Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 and was fixed in Oracle's July 2024 Critical Patch Update ([Oracle CPU, 2024-07-16](https://www.oracle.com/security-alerts/cpujul2024.html)). The operationally relevant fact is the *fresh* exploitation against a patch that has been available for 23 months, not the FCEB remediation date attached to the KEV entry; WebLogic is heavily deployed J2EE middleware in EU financial-services and public-sector estates ([Security Affairs, 2026-06-02](https://securityaffairs.com/193027/security/u-s-cisa-adds-oracle-weblogic-flaw-to-its-known-exploited-vulnerabilities-catalog.html)). Defenders: apply the July 2024 (or later) CPU; block T3/IIOP at the perimeter and restrict it to internal admin subnets via WebLogic connection filters; alert on unauthenticated T3/IIOP initiators reaching 7001/7002 from external sources.
