Oracle WebLogic Server known exploited vulnerabilities, ranked
CISA lists 12 Oracle WebLogic Server CVEs as exploited in the wild. 1 were added in the last 12 months and 2 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2020-14882: EPSS 100.00%, added 2021-11-03
- CVE-2017-10271: EPSS 99.99%, used in ransomware, added 2022-02-10
- CVE-2019-2725: EPSS 99.96%, used in ransomware, added 2022-01-10
- CVE-2018-2628: EPSS 99.96%, added 2022-09-08
- CVE-2023-21839: EPSS 99.90%, added 2023-05-01
All 12 Oracle WebLogic Server CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2020-14882 | WebLogic Server Remote Code Execution | 100.00% | – | 2021-11-03 | 2022-05-03 |
| 2 | CVE-2017-10271 | Corporation WebLogic Server Remote Code Execution | 99.99% | Yes | 2022-02-10 | 2022-08-10 |
| 3 | CVE-2019-2725 | WebLogic Server, Injection | 99.96% | Yes | 2022-01-10 | 2022-07-10 |
| 4 | CVE-2018-2628 | WebLogic Server Unspecified | 99.96% | – | 2022-09-08 | 2022-09-29 |
| 5 | CVE-2023-21839 | WebLogic Server Unspecified | 99.90% | – | 2023-05-01 | 2023-05-22 |
| 6 | CVE-2020-14750 | WebLogic Server Remote Code Execution | 99.27% | – | 2021-11-03 | 2022-05-03 |
| 7 | CVE-2020-14883 | WebLogic Server Unspecified | 97.9% | – | 2021-11-03 | 2022-05-03 |
| 8 | CVE-2017-3506 | WebLogic Server OS Command Injection | 96.3% | – | 2024-06-03 | 2024-06-24 |
| 9 | CVE-2015-4852 | WebLogic Server Deserialization of Untrusted Data | 96.0% | – | 2021-11-03 | 2022-05-03 |
| 10 | CVE-2020-2883 | WebLogic Server Unspecified | 94.9% | – | 2025-01-07 | 2025-01-28 |
| 11 | CVE-2020-14644 | WebLogic Server Remote Code Execution | 94.5% | – | 2024-09-18 | 2024-10-09 |
| 12 | CVE-2024-21182 | WebLogic Server Unspecified | 74.2% | – | 2026-06-01 | 2026-06-04 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Oracle KEV CVEs · other Oracle products: Fusion Middleware · Java SE · free KEV badge for Oracle · all vendors