Oracle known exploited vulnerabilities
CISA lists 46 Oracle CVEs as exploited in the wild. 7 were added in the last 12 months (latest 2026-08-24), and 13 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-14882 (WebLogic Server): EPSS 100.0%, added 2021-11-03
- CVE-2017-10271 (WebLogic Server): EPSS 100.0%, added 2022-02-10
- CVE-2019-2725 (WebLogic Server): EPSS 100.0%, added 2022-01-10
- CVE-2018-2628 (WebLogic Server): EPSS 100.0%, added 2022-09-08
- CVE-2023-21839 (WebLogic Server): EPSS 99.9%, added 2023-05-01
Most affected Oracle products
WebLogic Server (12), Java SE (7), Fusion Middleware (6), E-Business Suite (4), Java Runtime Environment (JRE) (4), Agile Product Lifecycle Management (PLM) (2), HTTP Server and Oracle Weblogic Server Proxy Plug-in (1), PeopleSoft Enterprise PeopleTools (1), ADF Faces (1), Java SE and JRockit (1), Solaris (1), BI Publisher (Formerly XML Publisher) (1).
All Oracle CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-21962 | HTTP Server and Oracle Weblogic Server Proxy Plug-in | HTTP Server and Weblogic Server Proxy Plug-in Improper Access Control | 2026-08-24 | 2026-08-27 | 70.9% | – |
| CVE-2026-46817 | E-Business Suite | E-Business Suite Improper Privilege Management | 2026-07-15 | 2026-07-18 | 0.8% | – |
| CVE-2026-35273 | PeopleSoft Enterprise PeopleTools | PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function | 2026-06-12 | 2026-06-15 | 9.4% | Yes |
| CVE-2024-21182 | WebLogic Server | WebLogic Server Unspecified | 2026-06-01 | 2026-06-04 | 74.2% | – |
| CVE-2025-61757 | Fusion Middleware | Fusion Middleware Missing Authentication for Critical Function | 2025-11-21 | 2025-12-12 | 88.6% | – |
| CVE-2025-61884 | E-Business Suite | E-Business Suite Server-Side Request Forgery (SSRF) | 2025-10-20 | 2025-11-10 | 95.9% | Yes |
| CVE-2025-61882 | E-Business Suite | E-Business Suite Unspecified | 2025-10-06 | 2025-10-27 | 99.7% | Yes |
| CVE-2024-20953 | Agile Product Lifecycle Management (PLM) | Agile Product Lifecycle Management (PLM) Deserialization | 2025-02-24 | 2025-03-17 | 3.9% | – |
| CVE-2020-2883 | WebLogic Server | WebLogic Server Unspecified | 2025-01-07 | 2025-01-28 | 94.9% | – |
| CVE-2024-21287 | Agile Product Lifecycle Management (PLM) | Agile Product Lifecycle Management (PLM) Incorrect Authorization | 2024-11-21 | 2024-12-12 | 1.7% | – |
| CVE-2022-21445 | ADF Faces | ADF Faces Deserialization of Untrusted Data | 2024-09-18 | 2024-10-09 | 62.5% | – |
| CVE-2020-14644 | WebLogic Server | WebLogic Server Remote Code Execution | 2024-09-18 | 2024-10-09 | 94.5% | – |
| CVE-2017-3506 | WebLogic Server | WebLogic Server OS Command Injection | 2024-06-03 | 2024-06-24 | 96.3% | – |
| CVE-2020-2551 | Fusion Middleware | Fusion Middleware Unspecified | 2023-11-16 | 2023-12-07 | 93.2% | – |
| CVE-2016-3427 | Java SE and JRockit | Java SE and JRockit Unspecified | 2023-05-12 | 2023-06-02 | 92.3% | – |
| CVE-2023-21839 | WebLogic Server | WebLogic Server Unspecified | 2023-05-01 | 2023-05-22 | 99.9% | – |
| CVE-2022-21587 | E-Business Suite | E-Business Suite Unspecified | 2023-02-02 | 2023-02-23 | 98.3% | Yes |
| CVE-2021-35587 | Fusion Middleware | Fusion Middleware Unspecified | 2022-11-28 | 2022-12-19 | 96.3% | – |
| CVE-2018-2628 | WebLogic Server | WebLogic Server Unspecified | 2022-09-08 | 2022-09-29 | 100.0% | – |
| CVE-2019-3010 | Solaris | Solaris Privilege Escalation | 2022-05-25 | 2022-06-15 | 13.4% | – |
| CVE-2013-2423 | Java Runtime Environment (JRE) | JRE Unspecified | 2022-05-25 | 2022-06-15 | 85.2% | – |
| CVE-2013-0431 | Java Runtime Environment (JRE) | JRE Sandbox Bypass | 2022-05-25 | 2022-06-15 | 90.2% | Yes |
| CVE-2013-0422 | Java Runtime Environment (JRE) | JRE Remote Code Execution | 2022-05-25 | 2022-06-15 | 97.0% | Yes |
| CVE-2012-1710 | Fusion Middleware | Fusion Middleware Unspecified | 2022-05-25 | 2022-06-15 | 7.8% | Yes |
| CVE-2010-0840 | Java Runtime Environment (JRE) | JRE Unspecified | 2022-05-25 | 2022-06-15 | 96.3% | – |
| CVE-2013-2465 | Java SE | Java SE Unspecified | 2022-03-28 | 2022-04-18 | 98.8% | Yes |
| CVE-2012-5076 | Java SE | Java SE Sandbox Bypass | 2022-03-28 | 2022-04-18 | 91.2% | – |
| CVE-2012-0518 | Fusion Middleware | Fusion Middleware Unspecified | 2022-03-28 | 2022-04-18 | 4.7% | – |
| CVE-2019-2616 | BI Publisher (Formerly XML Publisher) | BI Publisher Unauthorized Access | 2022-03-25 | 2022-04-15 | 92.2% | – |
| CVE-2015-4902 | Java SE | Java SE Integrity Check | 2022-03-03 | 2022-03-24 | 13.6% | – |
| CVE-2015-2590 | Java SE | Java SE and Java SE Embedded Remote Code Execution | 2022-03-03 | 2022-03-24 | 25.5% | – |
| CVE-2012-4681 | Java SE | Java SE Runtime Environment (JRE) Arbitrary Code Execution | 2022-03-03 | 2022-03-24 | 98.5% | Yes |
| CVE-2012-1723 | Java SE | Java SE Runtime Environment (JRE) Arbitrary Code Execution | 2022-03-03 | 2022-03-24 | 93.7% | Yes |
| CVE-2012-0507 | Java SE | Java SE Runtime Environment (JRE) Arbitrary Code Execution | 2022-03-03 | 2022-03-24 | 98.1% | Yes |
| CVE-2011-3544 | Java SE JDK and JRE | Java SE Runtime Environment (JRE) Arbitrary Code Execution | 2022-03-03 | 2022-03-24 | 96.7% | – |
| CVE-2008-3431 | VirtualBox | VirtualBox Insufficient Input Validation | 2022-03-03 | 2022-03-24 | 6.9% | – |
| CVE-2017-10271 | WebLogic Server | Corporation WebLogic Server Remote Code Execution | 2022-02-10 | 2022-08-10 | 100.0% | Yes |
| CVE-2020-14864 | Intelligence Enterprise Edition | Business Intelligence Enterprise Edition Path Transversal | 2022-01-18 | 2022-07-18 | 97.2% | – |
| CVE-2019-2725 | WebLogic Server | WebLogic Server, Injection | 2022-01-10 | 2022-07-10 | 100.0% | Yes |
| CVE-2020-2555 | Multiple Products | Multiple Products Remote Code Execution | 2021-11-03 | 2022-05-03 | 97.1% | – |
| CVE-2020-14883 | WebLogic Server | WebLogic Server Unspecified | 2021-11-03 | 2022-05-03 | 97.9% | – |
| CVE-2020-14882 | WebLogic Server | WebLogic Server Remote Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | – |
| CVE-2020-14871 | Solaris and Zettabyte File System (ZFS) | Solaris and Zettabyte File System (ZFS) Unspecified | 2021-11-03 | 2022-05-03 | 80.2% | – |
| CVE-2020-14750 | WebLogic Server | WebLogic Server Remote Code Execution | 2021-11-03 | 2022-05-03 | 99.3% | – |
| CVE-2015-4852 | WebLogic Server | WebLogic Server Deserialization of Untrusted Data | 2021-11-03 | 2022-05-03 | 96.0% | – |
| CVE-2012-3152 | Fusion Middleware | Fusion Middleware Unspecified | 2021-11-03 | 2022-05-03 | 98.8% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors