Back to advisories

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Oracle WebLogic Server CVE-2023-21931 is being actively exploited in the wild, allowing unauthenticated attackers to read or modify sensitive data. Federal agencies are mandated to patch by August 27, 2024. Any organization running unpatched WebLogic instances is at immediate risk of compromise.

CRITICALAdvisoryAug 26, 2026
Action required
Identify all Oracle WebLogic Server instances in your environment and patch to the latest version immediately. Prioritize internet-facing deployments and scan logs for exploitation attempts using the WebLogic proxy endpoints.
Affected products
Oracle WebLogic ServerOracle