CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch

CVE-2024-21182 sat quietly at CVSS 7.3 for two years before threat actors noticed the unpatched stragglers. Now federal agencies have until Thursday.

ThreatVectr Newsdesk· 2 min read
CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch
Share

Federal agencies got a four-day deadline this week to patch CVE-2024-21182, an unauthenticated data-access vulnerability in Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0. CISA dropped it into the Known Exploited Vulnerabilities catalog on Monday, confirming active exploitation in the wild.

The flaw scored 7.3 on the CVSS scale — not the kind of number that triggers emergency all-hands calls. Oracle patched it in the July 2024 Critical Patch Update. So why is it surfacing now?

The answer is probably selection pressure. Fortra associate director of security R&D Tyler Reguly put it plainly: organizations that haven't patched a two-year-old hole are likely running looser shops overall, which makes them more attractive targets than the diligent ones. WebLogic already had a dozen entries in the KEV before this addition. Admins who missed this one may have missed others.

Reguly also ran a quick audit of KEV timing. Only about 41% of catalog entries were added in the same calendar year the CVE was published. Stretch to release-year-plus-one and you reach roughly 58%. That leaves more than 40% of KEV additions arriving two or more years after disclosure — a data point that reframes the catalog as less of a real-time alert feed and more of a slow-motion archaeology project.

WebLogic is critical middleware. It hosts enterprise Java applications on-premises and in Kubernetes environments, and it sits close to sensitive data. Attackers have targeted it repeatedly: scanning campaigns in 2019, honeypot studies showing immediate exploit attempts after proof-of-concept release, attackers probing 2017-era bugs on unpatched test servers.

Oracle recently moved from a quarterly to a monthly patch cadence, which should help at the margins. The first monthly release dropped the same day CISA added this CVE — a coincidence that at least lands in the right direction.

Action1 field CTO Gene Moody framed the underlying problem in terms that any security team should recognize. The average organization takes roughly 60 days to apply a patch. Attackers build working exploits in hours. That gap is not a nuance; it is an attack window, and unpatched systems sitting inside it are straightforward targets.

Moody's broader point is worth keeping: a system carrying a multi-year-old unpatched vulnerability is rarely an isolated exception. It usually signals weak asset tracking, unclear patch ownership, or competing priorities that consistently beat out remediation. One stale CVE tends to bring friends.

For private-sector WebLogic operators, the KEV designation is not legally binding — but it is a reasonable proxy for 'someone is actively using this against real targets.' Treat it accordingly.

© 2026 Threat Vectr