Product of Oracle

WebLogic Server

As of , 12 Oracle WebLogic Server vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2018-2628.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2018-2628UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
2CVE-2017-10271Corporation WebLogic Server Remote Code ExecutionOracle WebLogic ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2019-2725WebLogic Server, InjectionOracle WebLogic ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
4CVE-2015-4852Deserialization of Untrusted DataOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.96; verified Exploit-DB entry0.96
5CVE-2020-2883UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.950.95
6CVE-2023-21839UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
7CVE-2020-14750Remote Code ExecutionOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
8CVE-2020-14882Remote Code ExecutionOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.990.99
9CVE-2020-14883UnspecifiedOracle WebLogic ServerPatch this weekMetasploit module; EPSS 0.980.98
10CVE-2024-21182UnspecifiedOracle WebLogic ServerPatch this weekEPSS 0.740.74
11CVE-2020-14644Remote Code ExecutionOracle WebLogic ServerPatch this weekEPSS 0.950.95
12CVE-2017-3506OS Command InjectionOracle WebLogic ServerPatch this weekEPSS 0.960.96

Added each year

12342021: 4420212022: 3320222023: 1120232024: 2220242025: 1120252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20214
20223
20231
20242
20251
20261

Used in ransomware