Skip to content
English

Products › Brands

Brand

Oracle: actively exploited vulnerabilities

46 vulnerabilities in Oracle products (WebLogic Server, Java SE (JRE / JDK), E-Business Suite…) are in CISA’s catalog of exploited vulnerabilities, 2 of them added in the last 90 days. Last added: August 24, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Oracle category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • WebLogic Server 14 vulnerabilities · Web servers
  • Java SE (JRE / JDK) 13 vulnerabilities · Frameworks
  • E-Business Suite 4 vulnerabilities · Business apps and data
  • Identity and Access Management (OIM / OAM) 3 vulnerabilities · Identity and access
  • Agile PLM 2 vulnerabilities · Business apps and data
  • Business Intelligence (OBIEE / BI Publisher) 2 vulnerabilities · Business apps and data
  • Fusion Middleware 2 vulnerabilities · Web servers
  • Solaris 2 vulnerabilities · Operating systems
  • ADF Faces 1 vulnerability · Frameworks
  • Coherence 1 vulnerability · Web servers
  • PeopleSoft 1 vulnerability · Business apps and data
  • VirtualBox 1 vulnerability · Virtualization and VDI

Name used by CISA: Oracle. Product families: indicative classification by this site.

Pace of additions

Number of Oracle vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20252
Nov 3, 2025 to Dec 2, 20251
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20260
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20262
Jul 1, 2026 to Jul 30, 20261
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Oracle list.

  1. Rank 1Oracle WebLogic Server

    CVE-2026-21962

    Hunt for compromise (CISA)

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 24, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Oracle E-Business Suite

    CVE-2026-46817

    Hunt for compromise (CISA)

    Oracle E-Business Suite Improper Privilege Management Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 15, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Oracle PeopleSoft

    CVE-2026-35273

    Ransomware

    Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Oracle Identity and Access Management (OIM / OAM)

    CVE-2025-61757

    Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 21, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Oracle E-Business Suite

    CVE-2025-61882

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Oracle WebLogic Server

    CVE-2024-21182

    CVE from 2024, added in 2026

    Oracle WebLogic Server Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 1, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  7. Rank 7Oracle E-Business Suite

    CVE-2025-61884

    Ransomware

    Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  8. Rank 8Oracle Solaris

    CVE-2020-14871

    Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  9. Rank 9Oracle WebLogic Server

    CVE-2020-2883

    CVE from 2020, added in 2025

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Oracle WebLogic Server

    CVE-2020-14644

    CVE from 2020, added in 2024

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 36 more vulnerabilities
  1. Rank 11Oracle ADF Faces

    CVE-2022-21445

    CVE from 2022, added in 2024

    Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Oracle WebLogic Server

    CVE-2020-2551

    CVE from 2020, added in 2023

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Oracle Java SE (JRE / JDK)

    CVE-2016-3427

    CVE from 2016, added in 2023

    Oracle Java SE and JRockit Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Oracle E-Business Suite

    CVE-2022-21587

    Ransomware

    Oracle E-Business Suite Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 2, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Oracle Identity and Access Management (OIM / OAM)

    CVE-2021-35587

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Oracle WebLogic Server

    CVE-2018-2628

    CVE from 2018, added in 2022

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Oracle Java SE (JRE / JDK)

    CVE-2010-0840

    CVE from 2010, added in 2022

    Oracle JRE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Oracle Fusion Middleware

    CVE-2012-1710

    RansomwareCVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Oracle Java SE (JRE / JDK)

    CVE-2013-0422

    RansomwareCVE from 2013, added in 2022

    Oracle JRE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Oracle Java SE (JRE / JDK)

    CVE-2012-5076

    CVE from 2012, added in 2022

    Oracle Java SE Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Oracle Java SE (JRE / JDK)

    CVE-2013-2465

    RansomwareCVE from 2013, added in 2022

    Oracle Java SE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Oracle Java SE (JRE / JDK)

    CVE-2011-3544

    CVE from 2011, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Oracle Java SE (JRE / JDK)

    CVE-2012-0507

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Oracle Java SE (JRE / JDK)

    CVE-2012-1723

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Oracle Java SE (JRE / JDK)

    CVE-2012-4681

    RansomwareCVE from 2012, added in 2022

    Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Oracle Java SE (JRE / JDK)

    CVE-2015-2590

    CVE from 2015, added in 2022

    Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Oracle WebLogic Server

    CVE-2019-2725

    RansomwareCVE from 2019, added in 2022

    Oracle WebLogic Server, Injection

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Oracle WebLogic Server

    CVE-2015-4852

    CVE from 2015, added in 2021

    Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Oracle WebLogic Server

    CVE-2020-14750

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Oracle WebLogic Server

    CVE-2020-14882

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Oracle Coherence

    CVE-2020-2555

    Oracle Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Oracle Fusion Middleware

    CVE-2012-3152

    CVE from 2012, added in 2021

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  23. Rank 33Oracle Agile PLM

    CVE-2024-20953

    Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 24, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  24. Rank 34Oracle Solaris

    CVE-2019-3010

    CVE from 2019, added in 2022

    Oracle Solaris Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  25. Rank 35Oracle VirtualBox

    CVE-2008-3431

    CVE from 2008, added in 2022

    Oracle VirtualBox Insufficient Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  26. Rank 36Oracle Agile PLM

    CVE-2024-21287

    Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  27. Rank 37Oracle WebLogic Server

    CVE-2023-21839

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  28. Rank 38Oracle WebLogic Server

    CVE-2017-10271

    RansomwareCVE from 2017, added in 2022

    Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  29. Rank 39Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2020-14864

    CVE from 2020, added in 2022

    Oracle Business Intelligence Enterprise Edition Path Transversal

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  30. Rank 40Oracle WebLogic Server

    CVE-2017-3506

    CVE from 2017, added in 2024

    Oracle WebLogic Server OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.4 (high)
  31. Rank 41Oracle Business Intelligence (OBIEE / BI Publisher)

    CVE-2019-2616

    CVE from 2019, added in 2022

    Oracle BI Publisher Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  32. Rank 42Oracle WebLogic Server

    CVE-2020-14883

    Oracle WebLogic Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  33. Rank 43Oracle Java SE (JRE / JDK)

    CVE-2013-0431

    RansomwareCVE from 2013, added in 2022

    Oracle JRE Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  34. Rank 44Oracle Java SE (JRE / JDK)

    CVE-2015-4902

    CVE from 2015, added in 2022

    Oracle Java SE Integrity Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  35. Rank 45Oracle Identity and Access Management (OIM / OAM)

    CVE-2012-0518

    CVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.7 (medium)
  36. Rank 46Oracle Java SE (JRE / JDK)

    CVE-2013-2423

    CVE from 2013, added in 2022

    Oracle JRE Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    3.7 (low)

Follow and verify

Get new Oracle vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.