Vendor

Oracle

As of , 46 Oracle vulnerabilities are on CISA's list of exploited vulnerabilities, 13 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-21962.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-21962Improper Access ControlOracle HTTP Server and Oracle Weblogic Server Proxy Plug-inPatch nowForensic triage required by CISA0.73
2CVE-2025-61884Server-Side Request Forgery (SSRF)Oracle E-Business SuitePatch nowRansomware use, listed within a year0.96
3CVE-2026-35273Missing Authentication for Critical FunctionOracle PeopleSoft Enterprise PeopleToolsPatch nowRansomware use, listed within a year0.09
4CVE-2026-46817Improper Privilege ManagementOracle E-Business SuitePatch nowForensic triage required by CISA0.01
5CVE-2018-2628UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
6CVE-2010-0840JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
7CVE-2013-0422JRE Remote Code ExecutionOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.97; verified Exploit-DB entry0.97
8CVE-2013-0431JRE Sandbox BypassOracle Java Runtime Environment (JRE)Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
9CVE-2013-2423JRE UnspecifiedOracle Java Runtime Environment (JRE)Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85
10CVE-2012-5076Sandbox BypassOracle Java SEPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
11CVE-2013-2465UnspecifiedOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
12CVE-2011-3544Java SE Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SE JDK and JREPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
13CVE-2012-0507Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.98; verified Exploit-DB entry0.98
14CVE-2012-1723Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.94; verified Exploit-DB entry0.94
15CVE-2012-4681Runtime Environment (JRE) Arbitrary Code ExecutionOracle Java SEPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
16CVE-2017-10271Corporation WebLogic Server Remote Code ExecutionOracle WebLogic ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
17CVE-2019-2725WebLogic Server, InjectionOracle WebLogic ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
18CVE-2012-3152UnspecifiedOracle Fusion MiddlewarePatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
19CVE-2015-4852Deserialization of Untrusted DataOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
20CVE-2020-2555Remote Code ExecutionOracle Multiple ProductsPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
21CVE-2025-61882UnspecifiedOracle E-Business SuitePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
22CVE-2020-2883UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.950.95
23CVE-2023-21839UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
24CVE-2022-21587UnspecifiedOracle E-Business SuitePatch this weekRansomware use; Metasploit module; EPSS 0.980.98
25CVE-2021-35587UnspecifiedOracle Fusion MiddlewarePatch this weekMetasploit module; EPSS 0.960.96

The next 21, from number 26

Products

  • WebLogic Server12 entries
  • Java SE7 entries
  • Fusion Middleware6 entries
  • E-Business Suite4 entries
  • Java Runtime Environment (JRE)4 entries
  • Agile Product Lifecycle Management (PLM)2 entries
  • ADF Faces1 entry
  • BI Publisher (Formerly XML Publisher)1 entry
  • HTTP Server and Oracle Weblogic Server Proxy Plug-in1 entry
  • Intelligence Enterprise Edition1 entry
  • Java SE and JRockit1 entry
  • Java SE JDK and JRE1 entry
  • Multiple Products1 entry
  • PeopleSoft Enterprise PeopleTools1 entry
  • Solaris1 entry
  • Solaris and Zettabyte File System (ZFS)1 entry
  • VirtualBox1 entry

Added each year

1020302021: 7720212022: 222220222023: 4420232024: 4420242025: 5520252026: 442026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20217
202222
20234
20244
20255
20264

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inEdited: required action.
  2. CVE-2013-0422 Oracle Java Runtime Environment (JRE)Ransomware use: Unknown to Known.
  3. CVE-2025-61884 Oracle E-Business SuiteRansomware use: Unknown to Known.
  4. CVE-2025-61882 Oracle E-Business SuiteRansomware use: Unknown to Known.
  5. CVE-2025-61882 Oracle E-Business SuiteDeadline moved from 28 October 2025 to 27 October 2025. Listing date changed from 7 October 2025 to 6 October 2025.
  6. CVE-2012-4681 Oracle Java SERansomware use: Unknown to Known.
  7. CVE-2012-1710 Oracle Fusion MiddlewareRansomware use: Unknown to Known.

Every change we recorded