logo

Mitel 0-day, 5-year-old Oracle RCE bug under active exploit

ID: ee5328ae-29f3-5b3b-a2ff-37e5a6946d32

STIX ID: report--ee5328ae-29f3-5b3b-a2ff-37e5a6946d32

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-01-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cybercriminals are actively exploiting two Mitel MiCollab path-traversal vulnerabilities (CVE-2024-41713 — critical and patched; CVE-2024-55550 — low severity, currently mitigated but not fully patched) and a long-exploited Oracle WebLogic RCE (CVE-2020-2883 — critical, previously patched but abused in the wild). CISA has added all three to its Known Exploited Vulnerabilities Catalog; organizations using MiCollab or affected WebLogic versions should apply available updates immediately to prevent data leakage, system compromise, and potential eavesdropping or remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.