Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?, (Wed, Jan 28th)
ID: 65a3fce8-9c9d-5023-9249-1fa6024be52e
STIX ID: report--65a3fce8-9c9d-5023-9249-1fa6024be52e
Feed Name: SANS ISC Diary
Threat Score
A SANS analysis describes HTTP probe traffic targeting CVE-2026-21962 in Oracle WebLogic: a GET to /weblogic//weblogic/..;/bea_wls_internal/ProxyServlet with headers containing a base64 string that decodes to "cmd:whoami." The author discusses whether this is a working exploit or AI-generated "slop," notes a Russian source IP (193.24.123.42) with previous scanning activity, references PoC and write-ups, and records an uptick in similar requests beginning January 21st.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
