Oracle Corporation vendor intelligence

Oracle Corporation Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Oracle Corporation products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
33
Known exploited vulnerabilities affecting Oracle Corporation products
In CISA KEV
27
Records also listed in the official catalog
Beyond CISA KEV
6
Additional exploited CVEs absent from CISA KEV
Sensor Observed
9
Oracle Corporation KEVs with sensor-observed exploitation activity

The catalog gap matters for Oracle Corporation exposure

Six of the 33 exploited Oracle Corporation CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.

82%
Covered by CISA
18%
Beyond CISA
17
Product families

Attested Oracle Corporation CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2021-2109

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server High Beyond CISA 15 Aug 2026
CVE-2026-46817

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are...

Oracle Payments Confirmed In CISA 29 Jun 2026
CVE-2026-35273

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions...

PeopleSoft Enterprise PeopleTools Confirmed In CISA 11 Jun 2026
CVE-2024-21182

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 01 Jun 2026
CVE-2022-21500

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable...

User Management High Beyond CISA 26 Jul 2025
CVE-2019-2768

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The...

BI Publisher (formerly XML Publisher) High Beyond CISA 15 Jul 2025
CVE-2018-2894

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are...

WebLogic Server Confirmed Beyond CISA 07 Jun 2025
CVE-2025-61757

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are...

Identity Manager Confirmed In CISA 01 Jun 2026
CVE-2025-61884

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are...

Oracle Configurator Confirmed In CISA 01 Jun 2026
CVE-2025-61882

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions...

Oracle Concurrent Processing Confirmed In CISA 29 May 2026
CVE-2020-14883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14882

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14750

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 03 Nov 2021
CVE-2020-14871

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected...

Solaris Operating System Confirmed In CISA 03 Nov 2021
CVE-2020-2555

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are...

WebCenter Portal, Utilities Framework Confirmed In CISA 03 Nov 2021
CVE-2019-2725

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Tape Library ACSLS Confirmed In CISA 10 Jan 2022
CVE-2020-14864

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...

Business Intelligence Enterprise Edition Confirmed In CISA 18 Jan 2022
CVE-2017-10271

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are...

WebLogic Server Confirmed In CISA 10 Feb 2022
CVE-2019-2616

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

BI Publisher (formerly XML Publisher) Confirmed In CISA 25 Mar 2022
CVE-2019-3010

Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily...

Solaris Operating System Confirmed In CISA 25 May 2022
CVE-2018-2628

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

WebLogic Server Confirmed In CISA 08 Sep 2022
CVE-2021-35587

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are...

Access Manager Confirmed In CISA 28 Nov 2022
CVE-2022-21587

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are...

Web Applications Desktop Integrator Confirmed In CISA 02 Feb 2023
CVE-2023-21839

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 01 May 2023
CVE-2020-2551

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are...

WebLogic Server Confirmed In CISA 16 Nov 2023
CVE-2017-3506

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

WebLogic Server Confirmed In CISA 03 Jun 2024
CVE-2022-21445

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions...

Application Development Framework (ADF) Confirmed In CISA 18 Sep 2024
CVE-2020-14644

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 18 Sep 2024
CVE-2024-21287

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The...

Oracle Agile PLM Framework Confirmed In CISA 21 Nov 2024
CVE-2020-2883

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...

WebLogic Server Confirmed In CISA 07 Jan 2025
CVE-2024-20953

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily...

Agile PLM Framework Confirmed In CISA 24 Feb 2025
CVE-2019-2618

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...

WebLogic Server High Beyond CISA 23 Apr 2019
CVE-2019-2588

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...

BI Publisher (formerly XML Publisher) High Beyond CISA 23 Apr 2019

Showing 33 of 33 Oracle Corporation known exploited vulnerabilities.

Recurring weakness patterns

Missing authentication for critical function, deserialization, and authentication account for fourteen mapped occurrences across this Oracle Corporation KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.