CloudSEK honeypot logs show exploitation of CVE-2026-21962 against Oracle WebLogic began on Jan 22, the same day exploit code was published.
Part of the PlainSec briefing for 2026-03-27