CVE-2020-14882Active Exploitation(oracle / weblogic_server)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch oracle weblogic_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblogic_server

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-19)
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
weblogic_server

5 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-08: 1Mentions · 2026-06-02: 1Mentions · 2026-08-10: 1Mentions · 2026-08-19: 2PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-08-19: 1Exploit Tool / Code · 2026-08-19: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-08-10: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-08: 1Technical Details · 2026-06-02: 1Technical Details · 2026-08-10: 104-0104-0806-0208-1008-19
Signal classification3 categories
Active Exploitation
466.7%
General
116.7%
PoC
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
Active Exploitation1
2026-04-081
Active Exploitation1
2026-06-021
Active Exploitation1
2026-08-101
Active Exploitation1
2026-08-192
General1PoC1
Full discourse6 posts
  • Eric CIAramella’s Dirty Whistle@TheAndersPaul
    Active Exploitation

    This election doc caught my eye. SQL injection in New York and Delaware Oracle Exploitation attempts in Delaware. Major Vulnerabilities: CVE-2020-14882: A critical remote code execution flaw in the WebLogic Server console with a maximum severity score of 9.8. CVE-2020-14750: An easily exploitable follow-up bug related to the same WebLogic console component that allowed full system takeover. CVE-2020-2883: Another remote code execution flaw tied to insecure Java object handling in WebLogic. ® Key Characteristics No Password Needed: Attackers did not need user accounts or credentials to break in; simple network HTTP requests were enough. Active Exploitation: Threat actors scanned the internet for exposed management consoles to run malicious

    Post summary

    The post reports that WebLogic Server CVEs (CVE-2020-14882, CVE-2020-14750, CVE-2020-2883) are being actively exploited for remote code execution, requiring only network HTTP requests without credentials.

    4101323936
    14.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    Oracle WebLogic 脆弱性 CVE-2026-21962 (CVSS 10.0):実環境での継続的な悪用を確認 https://iototsecnews.jp/2026/04/01/hackers-actively-exploit-critical-weblogic-rce-vulnerabilities-in-ongoing-attacks/ Oracle WebLogic Server の脆弱性である CVE-2026-21962 が、実環境で積極的に悪用され続けています。この脆弱性を悪用する攻撃者は、認証を必要とせずに外部から OS コマンドを実行できます。攻撃者はパス・トラバーサルという手法を悪用し、本来アクセスできない領域を操作することで、システムの制御権を奪おうとします。また、過去に報告された CVE-2020-14882 や CVE-2017-10271 といった既知の脆弱性も、依然として攻撃の入り口として狙われています。これらは、設定の不備や修正プログラムの未適用を突くものであり、自動化されたツールにより日々スキャンされています。ご利用のチームは、ご注意ください。 #CVE202621962 #Exploit #Oracle #Vulnerability #WebLogic

    Post summary

    Oracle WebLogic Server’s CVE‑2026‑21962 is actively being exploited in the wild, enabling unauthenticated attackers to execute arbitrary OS commands via path traversal, with no patch or PoC detailed in the text.

    02011161
    483 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-bnhF7il [CRITICAL/PoC] Linked: CVE-2020-14882 CVE-2020-14882-WebLogic-Analysis 🔗 https://exploitgrid.net/exploits/fd377b0e-3a95-49e0-a256-eedaa402c61e

    Post summary

    The post offers a link to a PoC/exploit for WebLogic CVE-2020-14882 on exploitgrid, with no mention of patches or active exploitation.

    1000039
    35 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    Post summary

    The digest simply lists five CVEs without offering any technical details, exploitation info, or remediation guidance.

    1000056
    35 followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    Two years on the shelf. Now it has CISA's name on it. CVE-2024-21216, Oracle WebLogic Server, CVSS 9.8. Oracle patched it in the October 2024 CPU. CISA just KEV-listed it — meaning active exploitation is confirmed, federal agencies are on the clock, and the "should patch" conversation is over. The BleepingComputer headline frames this as a "two-year-old flaw," which is technically true and completely misses the point. The flaw isn't the story. The story is that unpatched WebLogic instances are still sitting in federal and critical infrastructure networks in mid-2026, and someone is actively walking through the door Oracle left open eighteen months ago. The vector is as clean as it gets for an attacker: AV:N/AC:L/PR:N/UI:N. No authentication. No user interaction. No complexity. WebLogic's T3 and IIOP protocols exposed to the internet, and a missing authorization check (CWE-862) between an unauthenticated request and complete server takeover. Affected versions are 12.2.1.4.0 and 14.1.1.0.0. If you applied the October 2024 CPU, you're covered. If your change management queue has been sitting on it — the queue loses. The attack chain maps cleanly to what we've seen in prior WebLogic exploitation campaigns — CVE-2023-21839, CVE-2020-14882, same playbook. T1190 for initial access via the exposed endpoint, T1059 for post-exploitation RCE, T1505.003 for persistence via web shell. Threat actors scanning for exposed WebLogic don't need novel techniques here. They never did. Worth cross-referencing: CVE-2024-20953, Oracle Agile PLM 9.3.6, CVSS 8.8, KEV-listed February 2025 with a federal remediation deadline that already passed in March. A deserialization flaw (CWE-502) in the HTTP Export component, exploitable by a low-privileged attacker. The exploit lifecycle model puts it at roughly 54% mass exploitation probability with an expected days-to-mass-exploitation of zero — the window isn't approaching, it's open. Two Oracle products. Same pattern: patched, forgotten, quietly weaponized. CISA's decision to add a two-year-old Oracle flaw to the KEV catalog is an editorial statement every time it happens. Someone, somewhere, still hasn't patched. The attackers know exactly who. We are nothing if not consistent. Three things worth doing right now if you're running WebLogic: audit any instance of 12.2.1.4.0 or 14.1.1.0.0 accessible via T3 or IIOP from the internet or untrusted segments, apply the October 2024 CPU if you haven't, and block T3/IIOP at the perimeter as a compensating control — those protocols have no business being internet-routable for most deployments. Check your Oracle PLM exposure separately while you're at it; the federal deadline on CVE-2024-20953 is already overdue. Federal agencies are operating under mandatory remediation timelines per CISA BOD 22-01. For everyone else, the KEV listing is the operational trigger it's designed to be. Treat it that way.

    Post summary

    The post highlights that CVE‑2024‑21216 is actively exploited, stresses the need to apply the October 2024 CPU patch and block exposed protocols, and warns of similar patterns in other Oracle products.

    1000030
    16 followersView on X
  • ZeitTrender@ZeitTrender
    Active Exploitation

    🚨 Hackers are actively exploiting a new critical (CVSS 10.0) unauthenticated RCE in Oracle WebLogic Server — CVE-2026-21962 — along with several older high-severity flaws (CVE-2020-14882/83, CVE-2020-2551, CVE-2017-10271). Exploitation of the new flaw began the same day public PoC dropped. Honeypots saw immediate automated attacks. Full details: https://gbhackers.com/hackers-exploit-critical-weblogic-rce-vulnerabilities/

    Post summary

    The post reports that the new Oracle WebLogic RCE (CVE‑2026‑21962) is already being exploited in the wild immediately after a public PoC was released, with honeypots recording automated attacks.

    00000100
    59 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--

Explore more