CVE-2024-21182, a two-year-old high-severity vulnerability in Oracle WebLogic Server (versions 12.2.1.4.0 and 14.1.1.0.0), has been added to CISA's Known Exploited Vulnerabilities catalog, giving US federal agencies until Thursday to patch. Despite being patched by Oracle in July 2024, active exploitation is now confirmed. Security experts note that over 40% of KEV-listed CVEs are added two or more years after discovery, reflecting widespread slow patching. The average organization takes ~60 days to apply patches while attackers weaponize exploits in hours. Oracle recently switched to monthly patch cycles to address the growing threat landscape. Experts warn that unpatched old vulnerabilities signal broader security hygiene problems beyond a single flaw.

5m read timeFrom csoonline.com
Post cover image
332 Impressions