The cybersecurity agency has added a high-severity Oracle WebLogic Server vulnerability to its Known Exploited Vulnerabilities catalog after detecting active exploitation.
Summary
- CISA has mandated federal agencies patch a high-severity Oracle WebLogic Server vulnerability that was originally fixed two years ago
- The flaw is now being actively exploited by threat actors in the wild
- Government agencies have a compliance deadline to secure their systems against this vulnerability
The US Cybersecurity and Infrastructure Security Agency has issued a binding operational directive requiring federal agencies to address a high-severity vulnerability in Oracle WebLogic Server that threat actors are now actively exploiting in attacks.
The vulnerability was originally patched by Oracle two years ago, yet CISA’s addition to the Known Exploited Vulnerabilities catalog indicates that unpatched systems remain widespread enough to warrant active exploitation campaigns.
CISA has set a compliance deadline for federal agencies to remediate this vulnerability, though the specific timeframe was not detailed in available sources. The agency’s directive applies only to federal civilian executive branch agencies, but serves as a strong indicator for private sector organisations about current threat activity.
Why it matters
This advisory highlights a critical gap between patch availability and deployment that threat actors are exploiting. When CISA adds vulnerabilities to its KEV catalog, it signals active, reliable exploitation techniques that put unpatched systems at immediate risk. The two-year gap between the original patch and active exploitation demonstrates how legacy vulnerabilities remain attractive targets for attackers.
What to do now
- Audit Oracle WebLogic Server deployments for this specific vulnerability
- Apply the Oracle security patch that was released two years ago
- Review patch management processes to prevent similar delays in critical security updates
