An unpatched URI handler vulnerability in Windows Search allows attackers to extract NTLMv2 hashes and potentially gain access to Windows authentication tokens.
IBM has patched security vulnerabilities in WebSphere Application Server and Business Automation Workflow that allowed attackers to bypass security mechanisms.
CISA warns of active exploitation of CVE-2024-21182 in Oracle WebLogic Server with low attack complexity and focus on data leakage; federal agencies must patch by June 4, 2026.
The time window between vulnerability disclosure and patch deployment becomes a critical security gap due to AI-accelerated exploitation and patch implementation challenges — approximately one-third of ransomware incidents could have been prevented through patching.
A two-year-old WebLogic vulnerability is listed on CISA’s catalog of actively exploited vulnerabilities, signaling attackers to target long-unpatched systems.