logo

Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th)

ID: 65a3fce8-9c9d-5023-9249-1fa6024be52e

STIX ID: report--65a3fce8-9c9d-5023-9249-1fa6024be52e

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-01-28

Date Updated: 2026-04-19

...
...

A SANS analysis describes HTTP probe traffic targeting CVE-2026-21962 in Oracle WebLogic: a GET to /weblogic//weblogic/..;/bea_wls_internal/ProxyServlet with headers containing a base64 string that decodes to "cmd:whoami." The author discusses whether this is a working exploit or AI-generated "slop," notes a Russian source IP (193.24.123.42) with previous scanning activity, references PoC and write-ups, and records an uptick in similar requests beginning January 21st.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.