Vendor
Oracle
As of , 46 Oracle vulnerabilities are on CISA's list of exploited vulnerabilities, 13 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-21962.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-21962Improper Access Control | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Patch nowForensic triage required by CISA | 0.73 | ||
| 2 | CVE-2025-61884Server-Side Request Forgery (SSRF) | Oracle E-Business Suite | Patch nowRansomware use, listed within a year | 0.96 | ||
| 3 | CVE-2026-35273Missing Authentication for Critical Function | Oracle PeopleSoft Enterprise PeopleTools | Patch nowRansomware use, listed within a year | 0.09 | ||
| 4 | CVE-2026-46817Improper Privilege Management | Oracle E-Business Suite | Patch nowForensic triage required by CISA | 0.01 | ||
| 5 | CVE-2018-2628Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 6 | CVE-2010-0840JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 7 | CVE-2013-0422JRE Remote Code Execution | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 8 | CVE-2013-0431JRE Sandbox Bypass | Oracle Java Runtime Environment (JRE) | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| 9 | CVE-2013-2423JRE Unspecified | Oracle Java Runtime Environment (JRE) | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 10 | CVE-2012-5076Sandbox Bypass | Oracle Java SE | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| 11 | CVE-2013-2465Unspecified | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 12 | CVE-2011-3544Java SE Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE JDK and JRE | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 13 | CVE-2012-0507Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry | 0.98 | ||
| 14 | CVE-2012-1723Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry | 0.94 | ||
| 15 | CVE-2012-4681Runtime Environment (JRE) Arbitrary Code Execution | Oracle Java SE | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 16 | CVE-2017-10271Corporation WebLogic Server Remote Code Execution | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 17 | CVE-2019-2725WebLogic Server, Injection | Oracle WebLogic Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 18 | CVE-2012-3152Unspecified | Oracle Fusion Middleware | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 19 | CVE-2015-4852Deserialization of Untrusted Data | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry | 0.96 | ||
| 20 | CVE-2020-2555Remote Code Execution | Oracle Multiple Products | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 21 | CVE-2025-61882Unspecified | Oracle E-Business Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 22 | CVE-2020-2883Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 23 | CVE-2023-21839Unspecified | Oracle WebLogic Server | Patch this weekMetasploit module; EPSS 0.99 | 0.99 | ||
| 24 | CVE-2022-21587Unspecified | Oracle E-Business Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 25 | CVE-2021-35587Unspecified | Oracle Fusion Middleware | Patch this weekMetasploit module; EPSS 0.96 | 0.96 |
Products
- WebLogic Server12 entries
- Java SE7 entries
- Fusion Middleware6 entries
- E-Business Suite4 entries
- Java Runtime Environment (JRE)4 entries
- Agile Product Lifecycle Management (PLM)2 entries
- ADF Faces1 entry
- BI Publisher (Formerly XML Publisher)1 entry
- HTTP Server and Oracle Weblogic Server Proxy Plug-in1 entry
- Intelligence Enterprise Edition1 entry
- Java SE and JRockit1 entry
- Java SE JDK and JRE1 entry
- Multiple Products1 entry
- PeopleSoft Enterprise PeopleTools1 entry
- Solaris1 entry
- Solaris and Zettabyte File System (ZFS)1 entry
- VirtualBox1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 7 |
| 2022 | 22 |
| 2023 | 4 |
| 2024 | 4 |
| 2025 | 5 |
| 2026 | 4 |
Used in ransomware
Changes CISA made to these entries
- CVE-2025-61882 Oracle E-Business SuiteDeadline moved from 28 October 2025 to 27 October 2025. Listing date changed from 7 October 2025 to 6 October 2025.