Skip to content

Oracle WebLogic Server β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NameOracle WebLogic Server
Vendor / Projectoracle
Canonical IDoracle:weblogic
Versioning Schemegeneric
CPE Identifierscpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe Release14.1.2.0.0-Patch

Documented CVEs

2 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

1 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

2 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to 14.1.2.0.0-Patch to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

42.5 %

= Stable over 30d

CISA KEV Activity

1

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10
2026-08-24: KEV: CVE-2026-21962

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2026-8302110 (CRITICAL)0.4%NovAll supported production branches to v14.1.2.0.0-Analysis β†’
CVE-2026-219629.8 (CRITICAL)42.5%CISA KEV≀ v14.1.2.0.014.1.2.0.0-PatchAnalysis β†’

Vulnerabilities impacting Oracle WebLogic Server are actively leveraged in real-world intrusion campaigns:


Are you operating Oracle WebLogic Server in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: