CVE-2020-14750Active Exploitation(oracle / weblogic_server)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for oracle weblogic_server systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblogic_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
weblogic_server

5 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-10: 1Active Exploitation · 2026-08-10: 1Technical Details · 2026-08-10: 108-10
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Eric CIAramella’s Dirty Whistle@TheAndersPaul
    Active Exploitation

    This election doc caught my eye. SQL injection in New York and Delaware Oracle Exploitation attempts in Delaware. Major Vulnerabilities: CVE-2020-14882: A critical remote code execution flaw in the WebLogic Server console with a maximum severity score of 9.8. CVE-2020-14750: An easily exploitable follow-up bug related to the same WebLogic console component that allowed full system takeover. CVE-2020-2883: Another remote code execution flaw tied to insecure Java object handling in WebLogic. ® Key Characteristics No Password Needed: Attackers did not need user accounts or credentials to break in; simple network HTTP requests were enough. Active Exploitation: Threat actors scanned the internet for exposed management consoles to run malicious

    Post summary

    The post enumerates high‑severity WebLogic Server RCE CVEs, confirms that threat actors are actively exploiting exposed consoles, and provides technical details of the vulnerabilities without mentioning patches or PoC code.

    4101323934
    14.8K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--

Explore more