logo

Hackers Actively Exploiting Critical WebLogic RCE Vulnerabilities in Attacks

ID: d9f20625-2a96-5f56-9670-22b128c9cfa9

STIX ID: report--d9f20625-2a96-5f56-9670-22b128c9cfa9

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-05-05

Author: Abinaya

...
...

A high-interaction honeypot recorded immediate, large-scale automated exploitation attempts targeting a newly disclosed critical Oracle WebLogic RCE (CVE-2026-21962, CVSS 10.0) after exploit code was published. Attackers used rented VPS hosts and tools such as libredtail-http and the Nmap Scripting Engine to perform broad "spray and pray" scans, attempted the new ProxyServlet GET exploit and probed for historical WebLogic and unrelated vulnerabilities; the report urges immediate patching, restricting console access, deploying WAFs, and monitoring logs to avoid total compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.