Skip to main content

Mitel 0-day, 5-year-old Oracle RCE bugs under active exploit


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

3 CVEs added to CISA's catalog

 

January 8, 2025 By Jessica Lyons

 

Cybercriminals are actively exploiting two vulnerabilities in Mitel MiCollab, including a zero-day flaw, alongside a critical remote code execution vulnerability in Oracle WebLogic Server that has been exploited for at least five years.

Here are the three, all of which the US Cybersecurity and Infrastructure Security Agency (CISA) added to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation:

Two of the three have been fixed by the respective vendors, but security researchers have sounded warnings for months about the Mitel bugs and for years about Oracle's.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply