#WebLogic
Happy Friday. Even if you're not in Oracle Cloud, you probably have vendors who are. So I guess enjoy untangling this mess? No surprise BTW that it's yet another issue in WebLogic that's likely to blame.
www.cloudsek.com/blog/the-big...
March 21, 2025 at 10:34 PM
shit's running on oracle weblogic
September 19, 2025 at 10:08 AM
CISAがOracle WebLogicの脆弱性が悪用されたことを警告

サイバーセキュリティ機関であるCISAは、Oracle WebLogicサーバーに対する攻撃で広く悪用されている重大な脆弱性について、政府機関に対し直ちにパッチを適用するよう指示した。

リモートコード実行の脆弱性(CVE-2026-21962、CVSSスコア10)は、Oracle HTTP ServerおよびHTTP ServerとWebLogicを接続するWebLogic Serverプロキシプラグインに影響を与えます。

このセキュリティホールは認証なしで悪用され、影響を受けるサーバーへのハッキングに悪用され...
CISA Warns of Exploited Oracle WebLogic Vulnerability
Threat actors have been exploiting CVE-2026-21962, a critical Oracle HTTP Server and WebLogic vulnerability patched in January.
www.securityweek.com
September 24, 2026 at 10:30 PM
Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht. #Security
Attacken auf Oracle Weblogic und HTTP-Server beobachtet
Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht.
www.heise.de
August 25, 2026 at 6:14 AM
Oracle has finally moved to at least monthly patch releases instead of quarterly and every product has 10s. I think just weblogic had like 4 RCEs this month
September 22, 2026 at 7:34 PM
Dependendo da versão… dá tempo sair e voltar… weblogic, eu estou olhando pra vc…
February 2, 2025 at 1:19 AM
Oracle WebLogic Server OS Command Injection Flaw Under Active Attack
Oracle WebLogic Server OS Command Injection Flaw Under Active Attack
The U.S. cybersecurity agency has added Oracle WebLogic Server Vulnerability CVE-2017-3506 to its Known Exploited Vulnerabilities catalog.
thehackernews.com
June 4, 2024 at 4:47 AM
ウェブサーバ向け「WebLogic」連携モジュールの脆弱性悪用に注意

米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「Oracle WebLogic Server Proxy Plug-in(mod_wl_ohs)」の脆弱性が悪用されているとして注意喚起を行った。

現地時間2026年8月24日、「悪用が確認された脆弱性カタログ(KEV)」へアクセス制御不備の脆弱性「CVE-2026-21962」を追加したもの。

同製品はウェブサーバから「Oracle WebLogic Server」へのリクエストをプロキシ処理できるプラグイン。

プラグインは「Oracl...
【セキュリティ ニュース】ウェブサーバ向け「WebLogic」連携モジュールの脆弱性悪用に注意(1ページ目 / 全2ページ):Security NEXT
米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「Oracle WebLogic Server Proxy Plug-in(mod_wl_ohs)」の脆弱性が悪用されているとして注意喚起を行った。 :Security NEXT
www.security-next.com
September 24, 2026 at 10:23 PM
The 2024 Cloud Native #Java Survey results are out:
Nice to see GlassFish at 20% adoption, ahead of Payara, JBoss, Liberty, TomEE, Jetty,WebSphere and Weblogic! Quarkus adoption has also been very impressive.
jakarta.ee/blogs/2024-cloud...
February 11, 2025 at 3:51 PM
CERTFR-2025-AVI-0604: Multiples vulnérabilités dans Oracle Weblogic
https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0604/
July 18, 2025 at 3:24 PM
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
www.bleepingcomputer.com
January 7, 2025 at 6:45 PM
PeopleTools 8.62 + WebLogic Remote Console: The Middleware Upgrade You Didn't Know You Needed: https://aaronengelsrud.com/2025/07/13/peopletools-weblogic-remote-console-the.html

PeopleTools 8.62 introduces official support for the WebLogic Remote Console, enhancing security, performance, and usa...
July 13, 2025 at 10:28 PM
New Linux Malware Campaign Exploits Oracle Weblogic to Mine Cryptocurrency #cybersecurity #infosec #privacy #news thehackernews.com/20...
September 13, 2024 at 12:51 PM
CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.
CISA flags two-year-old Oracle flaw as actively exploited in attacks
CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks.
www.bleepingcomputer.com
June 2, 2026 at 12:40 PM
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution securityonline.info/cve-2025-215...
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Learn about the potential risks of the CVE-2025-21535 vulnerability in WebLogic Server. Stay protected from unauthenticated remote attacks that could exploit this critical flaw.
securityonline.info
January 24, 2025 at 1:14 PM
New Breach Please, @malwarejake.bsky.social & I talk 15 state AGs subpoenaing OpenAI over the Hugging Face hack & evidence preservation. Then we talk about the older perfect 10 Weblogic vuln being actively exploited

YouTube: www.youtube.com/watch?v=twwt...
Apple: podcasts.apple.com/nz/podcast/b...
August 26, 2026. S0E21:Alabama Comes for OpenAI, WebLogic Comes for Everyone
YouTube video by Breach Please
www.youtube.com
August 26, 2026 at 2:22 PM
CERTFR-2025-AVI-0324: Vulnérabilité dans Oracle Weblogic
https://www.cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0324/
April 16, 2025 at 3:42 PM
Running WebLogic means following Oracle’s schedule. Learn how Payara Server offers monthly releases, rapid fixes, flexible Deployment Groups, and more in this blog: https://bit.ly/4c5E41M

#AzulPayara #OracleJava #Java #Developers #ApplicationModernization
6 Ways Azul Payara Server Is Better Than Oracle WebLogic Server
Learn why Azul Payara Server is better than Oracle WebLogic Server for modern, cloud-based Jakarta EE workloads.
https
April 14, 2026 at 9:25 PM
Notícia da SecurityOnline

"CVE-2025-21535 (CVSS 9.8): Vulnerabilidade no Oracle WebLogic Server Pode Levar à Execução Remota de Código" #bolhasec
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Learn about the potential risks of the CVE-2025-21535 vulnerability in WebLogic Server. Stay protected from unauthenticated remote attacks that could exploit this critical flaw.
securityonline.info
February 12, 2025 at 3:30 PM
Oracle WebLogicの脆弱性が悪用され、認証されていない攻撃者が重要なデータにアクセスできることが判明

米国のサイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)は月曜日、 Oracle HTTP ServerとOracle WebLogic Serverに影響を与える最高レベルのセキュリティ脆弱性を、既知の悪用事例(KEV)カタログに追加した。これは、実際に悪用されている証拠があるためだ。

CVE-2026-21962 (CVSSスコア:10.0)として追跡されているこの脆弱性により、HTTP経由でネットワークにアクセスできる認証されていない攻撃者が、Or...
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
CISA adds actively exploited CVE-2026-21962 to KEV; the Oracle flaw can expose or alter critical data via unauthenticated HTTP access.
thehackernews.com
September 24, 2026 at 10:29 PM
CERTFR-2026-AVI-0473: Multiples vulnérabilités dans Oracle Weblogic
https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0473/
April 22, 2026 at 12:47 PM
The own and control many technologies (Java, OracleDB, Mysql, SAP, BerkeleyDB, WebLogic) which are very important infrastructure pieces of our economy, but even that may not save their balance sheet. Oracle won't die as much as explode into a million pieces.
January 30, 2026 at 8:25 PM
Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability

cybersecuritynews.com/oracle-relea...

#Cybersecurity #LargeScaleImpact #Vulnerability
Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability
Oracle’s August 2026 update fixes 943 flaws, including critical WebLogic vulnerabilities enabling full server takeover.
cybersecuritynews.com
August 19, 2026 at 11:05 AM