CyberMax
Home › Exploited CVEs › Oracle

Oracle WebLogic Server known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 12 Oracle WebLogic Server CVEs as exploited in the wild. 1 were added in the last 12 months and 2 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 12 Oracle WebLogic Server CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2020-14882WebLogic Server Remote Code Execution100.00%–2021-11-032022-05-03
2CVE-2017-10271Corporation WebLogic Server Remote Code Execution99.99%Yes2022-02-102022-08-10
3CVE-2019-2725WebLogic Server, Injection99.96%Yes2022-01-102022-07-10
4CVE-2018-2628WebLogic Server Unspecified99.96%–2022-09-082022-09-29
5CVE-2023-21839WebLogic Server Unspecified99.90%–2023-05-012023-05-22
6CVE-2020-14750WebLogic Server Remote Code Execution99.27%–2021-11-032022-05-03
7CVE-2020-14883WebLogic Server Unspecified97.9%–2021-11-032022-05-03
8CVE-2017-3506WebLogic Server OS Command Injection96.3%–2024-06-032024-06-24
9CVE-2015-4852WebLogic Server Deserialization of Untrusted Data96.0%–2021-11-032022-05-03
10CVE-2020-2883WebLogic Server Unspecified94.9%–2025-01-072025-01-28
11CVE-2020-14644WebLogic Server Remote Code Execution94.5%–2024-09-182024-10-09
12CVE-2024-21182WebLogic Server Unspecified74.2%–2026-06-012026-06-04
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Oracle KEV CVEs · other Oracle products: Fusion Middleware · Java SE · free KEV badge for Oracle · all vendors