CISA adds a high-severity Oracle WebLogic Server vulnerability, CVE-2024-21182, to its Known Exploited Vulnerabilities (KEV) Catalog after receiving evidence that the flaw is being actively exploited. Both reports identify the issue as CVE-2024-21182 and describe it as affecting Oracle WebLogic Server deployments reachable over a network.

According to the accounts, the vulnerability can be exploited without authentication. An attacker with network access can take control of susceptible WebLogic servers by leveraging the flaw. The Hacker News reports a CVSS score of 7.5 for the vulnerability and frames the KEV addition as confirmation of real-world use rather than a purely theoretical risk. SecurityWeek similarly states the vulnerability is being exploited in the wild and emphasizes that attackers do not need valid credentials to compromise affected systems.

Together, the sources agree on the core points: the CVE identifier, the lack of authentication required for exploitation, and that observed activity prompted CISA’s KEV catalog update.