CVE-2020-2551Active Exploitation(oracle / weblogic_server)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for oracle weblogic_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-12-07. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblogic_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
weblogic_server

4 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Active Exploitation · 2026-04-01: 1Technical Details · 2026-04-01: 104-01
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • ZeitTrender@ZeitTrender
    Active Exploitation

    🚨 Hackers are actively exploiting a new critical (CVSS 10.0) unauthenticated RCE in Oracle WebLogic Server — CVE-2026-21962 — along with several older high-severity flaws (CVE-2020-14882/83, CVE-2020-2551, CVE-2017-10271). Exploitation of the new flaw began the same day public PoC dropped. Honeypots saw immediate automated attacks. Full details: https://gbhackers.com/hackers-exploit-critical-weblogic-rce-vulnerabilities/

    Post summary

    Hackers are actively exploiting CVE-2026-21962, a critical unauthenticated RCE in Oracle WebLogic, with a public PoC released the same day and automated attacks detected by honeypots.

    00000100
    59 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleweblogic_server10.3.6.0.0--
Apporacleweblogic_server12.1.3.0.0--
Apporacleweblogic_server12.2.1.3.0--
Apporacleweblogic_server12.2.1.4.0--

Explore more