Skip to content

Data collected

CVEs Live

Oracle vulnerabilities exploited in the wild

The Oracle CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

46
flaws with confirmed attacks
13
used by ransomware
2.7%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-21962Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    70.9%99.4th pct

    KEV dates

    added due
  2. CVE-2026-46817Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · E-Business Suite

    Oracle E-Business Suite Improper Privilege Management Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    0.81%56th pct

    KEV dates

    added due
  3. CVE-2026-35273Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Oracle · PeopleSoft Enterprise PeopleTools

    Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    9.44%95th pct

    KEV dates

    added due
  4. CVE-2024-21182Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · WebLogic Server

    Oracle WebLogic Server Unspecified Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    74.2%99.5th pct

    KEV dates

    added due
  5. CVE-2025-61757Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · Fusion Middleware

    Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    88.6%99.8th pct

    KEV dates

    added due
  6. CVE-2025-61884Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Oracle · E-Business Suite

    Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    95.9%99.9th pct

    KEV dates

    added due
  7. CVE-2025-61882Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Oracle · E-Business Suite

    Oracle E-Business Suite Unspecified Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    99.7%100th pct

    KEV dates

    added due
  8. CVE-2024-20953Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · Agile Product Lifecycle Management (PLM)

    Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    3.93%90th pct

    KEV dates

    added due
  9. CVE-2020-2883Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · WebLogic Server

    Oracle WebLogic Server Unspecified Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    94.9%99.9th pct

    KEV dates

    added due
  10. CVE-2024-21287Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · Agile Product Lifecycle Management (PLM)

    Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    1.72%77th pct

    KEV dates

    added due
  11. CVE-2020-14644Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · WebLogic Server

    Oracle WebLogic Server Remote Code Execution Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    94.5%99.9th pct

    KEV dates

    added due
  12. CVE-2022-21445Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Oracle · ADF Faces

    Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · oracle.com

    Attack probability (EPSS)

    62.5%99.2th pct

    KEV dates

    added due

Oracle products in the catalog

Among the most recent entries, the products that appear most often are:

  • E-Business Suite3 entries
  • WebLogic Server3 entries
  • Agile Product Lifecycle Management (PLM)2 entries
  • HTTP Server and Oracle Weblogic Server Proxy Plug-in1 entry
  • PeopleSoft Enterprise PeopleTools1 entry
  • Fusion Middleware1 entry
  • ADF Faces1 entry

Product names are the ones CISA uses in the catalog. To check a specific Oracle CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: Oracle Security Alerts.

Other vendors

Questions

How many Oracle vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 46 Oracle vulnerabilities as of 3 Oct 2026. CISA marks 13 of them as known to be used in ransomware campaigns.

What is the most recent Oracle entry in KEV?

CVE-2026-21962 (Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability), added on 24 Aug 2026 with a due date of 27 Aug 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Oracle CVE?

No. It lists only the Oracle CVEs that CISA has confirmed as exploited. Oracle publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Oracle vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections