Brand
Oracle: actively exploited vulnerabilities
46 vulnerabilities in Oracle products (WebLogic Server, Java SE (JRE / JDK), E-Business Suite…) are in CISA’s catalog of exploited vulnerabilities, 2 of them added in the last 90 days. Last added: August 24, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
7 vulnerabilities added in the last 12 months
-
46 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Oracle category to your radar, or open its page.
- Web and application servers 17 vulnerabilities
- Frameworks and libraries 14 vulnerabilities
- ERP, business applications and databases 9 vulnerabilities
- Identity and access 3 vulnerabilities
- Operating systems 2 vulnerabilities
- Virtualization, VDI and cloud 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- WebLogic Server 14 vulnerabilities · Web servers
- Java SE (JRE / JDK) 13 vulnerabilities · Frameworks
- E-Business Suite 4 vulnerabilities · Business apps and data
- Identity and Access Management (OIM / OAM) 3 vulnerabilities · Identity and access
- Agile PLM 2 vulnerabilities · Business apps and data
- Business Intelligence (OBIEE / BI Publisher) 2 vulnerabilities · Business apps and data
- Fusion Middleware 2 vulnerabilities · Web servers
- Solaris 2 vulnerabilities · Operating systems
- ADF Faces 1 vulnerability · Frameworks
- Coherence 1 vulnerability · Web servers
- PeopleSoft 1 vulnerability · Business apps and data
- VirtualBox 1 vulnerability · Virtualization and VDI
Name used by CISA: Oracle. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 2 |
| Nov 3, 2025 to Dec 2, 2025 | 1 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 0 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 2 |
| Jul 1, 2026 to Jul 30, 2026 | 1 |
| Jul 31, 2026 to Aug 29, 2026 | 1 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Oracle list.
Rank 1Oracle WebLogic Server
CVE-2026-21962Hunt for compromise (CISA)
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 24, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Oracle E-Business Suite
CVE-2026-46817Hunt for compromise (CISA)
Oracle E-Business Suite Improper Privilege Management Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 15, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3Oracle PeopleSoft
CVE-2026-35273Ransomware
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 12, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Oracle Identity and Access Management (OIM / OAM)
CVE-2025-61757Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 21, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Oracle E-Business Suite
CVE-2025-61882Ransomware
Oracle E-Business Suite Unspecified Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 6, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6Oracle WebLogic Server
CVE-2024-21182CVE from 2024, added in 2026
Oracle WebLogic Server Unspecified Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 1, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.5 (high)
Rank 7Oracle E-Business Suite
CVE-2025-61884Ransomware
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 8Oracle Solaris
CVE-2020-14871Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 9Oracle WebLogic Server
CVE-2020-2883CVE from 2020, added in 2025
Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Oracle WebLogic Server
CVE-2020-14644CVE from 2020, added in 2024
Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 36 more vulnerabilities
Rank 11Oracle ADF Faces
CVE-2022-21445CVE from 2022, added in 2024
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Oracle WebLogic Server
CVE-2020-2551CVE from 2020, added in 2023
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Oracle Java SE (JRE / JDK)
CVE-2016-3427CVE from 2016, added in 2023
Oracle Java SE and JRockit Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 12, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Oracle E-Business Suite
CVE-2022-21587Ransomware
Oracle E-Business Suite Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Oracle Identity and Access Management (OIM / OAM)
CVE-2021-35587Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16Oracle WebLogic Server
CVE-2018-2628CVE from 2018, added in 2022
Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17Oracle Java SE (JRE / JDK)
CVE-2010-0840CVE from 2010, added in 2022
Oracle JRE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Oracle Fusion Middleware
CVE-2012-1710RansomwareCVE from 2012, added in 2022
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Oracle Java SE (JRE / JDK)
CVE-2013-0422RansomwareCVE from 2013, added in 2022
Oracle JRE Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Oracle Java SE (JRE / JDK)
CVE-2012-5076CVE from 2012, added in 2022
Oracle Java SE Sandbox Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Oracle Java SE (JRE / JDK)
CVE-2013-2465RansomwareCVE from 2013, added in 2022
Oracle Java SE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Oracle Java SE (JRE / JDK)
CVE-2011-3544CVE from 2011, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23Oracle Java SE (JRE / JDK)
CVE-2012-0507RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Oracle Java SE (JRE / JDK)
CVE-2012-1723RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Oracle Java SE (JRE / JDK)
CVE-2012-4681RansomwareCVE from 2012, added in 2022
Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Oracle Java SE (JRE / JDK)
CVE-2015-2590CVE from 2015, added in 2022
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Oracle WebLogic Server
CVE-2019-2725RansomwareCVE from 2019, added in 2022
Oracle WebLogic Server, Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 28Oracle WebLogic Server
CVE-2015-4852CVE from 2015, added in 2021
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 29Oracle WebLogic Server
CVE-2020-14750Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 30Oracle WebLogic Server
CVE-2020-14882Oracle WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 31Oracle Coherence
CVE-2020-2555Oracle Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 32Oracle Fusion Middleware
CVE-2012-3152CVE from 2012, added in 2021
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.1 (critical)
Rank 33Oracle Agile PLM
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 34Oracle Solaris
CVE-2019-3010CVE from 2019, added in 2022
Oracle Solaris Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 35Oracle VirtualBox
CVE-2008-3431CVE from 2008, added in 2022
Oracle VirtualBox Insufficient Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 36Oracle Agile PLM
CVE-2024-21287Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 21, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 37Oracle WebLogic Server
CVE-2023-21839Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 1, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 38Oracle WebLogic Server
CVE-2017-10271RansomwareCVE from 2017, added in 2022
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 39Oracle Business Intelligence (OBIEE / BI Publisher)
CVE-2020-14864CVE from 2020, added in 2022
Oracle Business Intelligence Enterprise Edition Path Transversal
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 40Oracle WebLogic Server
CVE-2017-3506CVE from 2017, added in 2024
Oracle WebLogic Server OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 3, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.4 (high)
Rank 41Oracle Business Intelligence (OBIEE / BI Publisher)
CVE-2019-2616CVE from 2019, added in 2022
Oracle BI Publisher Unauthorized Access Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 42Oracle WebLogic Server
CVE-2020-14883Oracle WebLogic Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
Rank 43Oracle Java SE (JRE / JDK)
CVE-2013-0431RansomwareCVE from 2013, added in 2022
Oracle JRE Sandbox Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 44Oracle Java SE (JRE / JDK)
CVE-2015-4902CVE from 2015, added in 2022
Oracle Java SE Integrity Check Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 45Oracle Identity and Access Management (OIM / OAM)
CVE-2012-0518CVE from 2012, added in 2022
Oracle Fusion Middleware Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 28, 2022
- CISA deadline
- 21 days
- CVSS severity
- 4.7 (medium)
Rank 46Oracle Java SE (JRE / JDK)
CVE-2013-2423CVE from 2013, added in 2022
Oracle JRE Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 3.7 (low)
Follow and verify
Get new Oracle vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.