Documented CVEs
2 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Oracle WebLogic Server |
| Vendor / Project | oracle |
| Canonical ID | oracle:weblogic |
| Versioning Scheme | generic |
| CPE Identifiers | cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:* |
| Overall Posture | CRITICAL |
| Recommended Safe Release | 14.1.2.0.0-Patch |
Documented CVEs
2 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
1 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
2 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to 14.1.2.0.0-Patch to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
42.5 %
= Stable over 30d
1
Active in-the-wild exploitation
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2026-83021 | 10 (CRITICAL) | 0.4% | No | vAll supported production branches to v14.1.2.0.0 | - | Analysis β |
| CVE-2026-21962 | 9.8 (CRITICAL) | 42.5% | CISA KEV | β€ v14.1.2.0.0 | 14.1.2.0.0-Patch | Analysis β |
Vulnerabilities impacting Oracle WebLogic Server are actively leveraged in real-world intrusion campaigns:
Are you operating Oracle WebLogic Server in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: