Cross-Vendor Patch Advisories
Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.
Browse Advisories
46 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.
| CVE | Vendor | Product | Vulnerability | EVRS | EPSS | Ransomware | CISA due |
|---|---|---|---|---|---|---|---|
| CVE-2026-35273 | Oracle | PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | 97 Immediate | 0.955 (99.86th pctl) | Known | 2026-06-15 |
| CVE-2025-61882 | Oracle | E-Business Suite | Oracle E-Business Suite Unspecified Vulnerability | 96 Immediate | 0.997 (99.95th pctl) | Known | 2025-10-27 |
| CVE-2019-2725 | Oracle | WebLogic Server | Oracle WebLogic Server, Injection | 94 Immediate | 0.999 (99.98th pctl) | Known | 2022-07-10 |
| CVE-2013-2465 | Oracle | Java SE | Oracle Java SE Unspecified Vulnerability | 93 Immediate | 0.987 (99.92nd pctl) | Known | 2022-04-18 |
| CVE-2012-4681 | Oracle | Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | 93 Immediate | 0.985 (99.92nd pctl) | Known | 2022-03-24 |
| CVE-2022-21587 | Oracle | E-Business Suite | Oracle E-Business Suite Unspecified Vulnerability | 93 Immediate | 0.983 (99.91st pctl) | Known | 2023-02-23 |
| CVE-2012-0507 | Oracle | Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | 93 Immediate | 0.981 (99.91st pctl) | Known | 2022-03-24 |
| CVE-2025-61884 | Oracle | E-Business Suite | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability | 93 Immediate | 0.978 (99.9th pctl) | Known | 2025-11-10 |
| CVE-2013-0422 | Oracle | Java Runtime Environment (JRE) | Oracle JRE Remote Code Execution Vulnerability | 93 Immediate | 0.976 (99.9th pctl) | Known | 2022-06-15 |
| CVE-2012-1723 | Oracle | Java SE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | 92 Immediate | 0.937 (99.84th pctl) | Known | 2022-03-24 |
| CVE-2017-10271 | Oracle | WebLogic Server | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | 91 Immediate | 0.999 (99.99th pctl) | Known | 2022-08-10 |
| CVE-2020-14882 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 87 Immediate | 0.999 (99.99th pctl) | Unknown/None | 2022-05-03 |
| CVE-2018-2628 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 87 Immediate | 0.994 (99.94th pctl) | Unknown/None | 2022-09-29 |
| CVE-2020-14750 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 87 Immediate | 0.993 (99.93rd pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-2883 | Oracle | WebLogic Server | Oracle WebLogic Server Unspecified Vulnerability | 87 Immediate | 0.949 (99.85th pctl) | Unknown/None | 2025-01-28 |
| CVE-2020-14644 | Oracle | WebLogic Server | Oracle WebLogic Server Remote Code Execution Vulnerability | 87 Immediate | 0.945 (99.85th pctl) | Unknown/None | 2024-10-09 |
| CVE-2025-61757 | Oracle | Fusion Middleware | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | 87 Immediate | 0.882 (99.76th pctl) | Unknown/None | 2025-12-12 |
| CVE-2012-3152 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 86 Immediate | 0.988 (99.92nd pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-2555 | Oracle | Multiple Products | Oracle Multiple Products Remote Code Execution Vulnerability | 86 Immediate | 0.971 (99.89th pctl) | Unknown/None | 2022-05-03 |
| CVE-2011-3544 | Oracle | Java SE JDK and JRE | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability | 86 Immediate | 0.967 (99.88th pctl) | Unknown/None | 2022-03-24 |
| CVE-2010-0840 | Oracle | Java Runtime Environment (JRE) | Oracle JRE Unspecified Vulnerability | 86 Immediate | 0.963 (99.88th pctl) | Unknown/None | 2022-06-15 |
| CVE-2021-35587 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 86 Immediate | 0.963 (99.88th pctl) | Unknown/None | 2022-12-19 |
| CVE-2015-4852 | Oracle | WebLogic Server | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | 86 Immediate | 0.960 (99.87th pctl) | Unknown/None | 2022-05-03 |
| CVE-2020-2551 | Oracle | Fusion Middleware | Oracle Fusion Middleware Unspecified Vulnerability | 85 Immediate | 0.932 (99.83rd pctl) | Unknown/None | 2023-12-07 |
| CVE-2016-3427 | Oracle | Java SE and JRockit | Oracle Java SE and JRockit Unspecified Vulnerability | 85 Immediate | 0.923 (99.82nd pctl) | Unknown/None | 2023-06-02 |
Exactly the 46 advisory(ies) matching the filters above.
Advisory detail
Expand any advisory for its description, CISA's own required action, and research links.
CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2026-06-12
CISA remediation due: 2026-06-15
Known ransomware campaign use: Known
CVE-2025-61882 — Oracle E-Business Suite: Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-06
CISA remediation due: 2025-10-27
Known ransomware campaign use: Known
CVE-2019-2725 — Oracle WebLogic Server: Oracle WebLogic Server, Injection
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-01-10
CISA remediation due: 2022-07-10
Known ransomware campaign use: Known
CVE-2013-2465 — Oracle Java SE: Oracle Java SE Unspecified Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.987.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.987 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-28
CISA remediation due: 2022-04-18
Known ransomware campaign use: Known
CVE-2012-4681 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2022-21587 — Oracle E-Business Suite: Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-02-02
CISA remediation due: 2023-02-23
Known ransomware campaign use: Known
CVE-2012-0507 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.981.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.981 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2025-61884 — Oracle E-Business Suite: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.978.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.978 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-10-20
CISA remediation due: 2025-11-10
Known ransomware campaign use: Known
CVE-2013-0422 — Oracle Java Runtime Environment (JRE): Oracle JRE Remote Code Execution Vulnerability
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.976.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.976 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Known
CVE-2012-1723 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Known
CVE-2017-10271 — Oracle WebLogic Server: Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
CISA required action: Apply updates per vendor instructions.
CVSS: 7.5 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-02-10
CISA remediation due: 2022-08-10
Known ransomware campaign use: Known
CVE-2020-14882 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2018-2628 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-09-08
CISA remediation due: 2022-09-29
Known ransomware campaign use: Unknown/None
CVE-2020-14750 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.993 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-2883 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.949.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.949 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-01-07
CISA remediation due: 2025-01-28
Known ransomware campaign use: Unknown/None
CVE-2020-14644 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.945.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.945 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2024-09-18
CISA remediation due: 2024-10-09
Known ransomware campaign use: Unknown/None
CVE-2025-61757 — Oracle Fusion Middleware: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
Recommended priority: Patch Immediately
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.
CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2025-11-21
CISA remediation due: 2025-12-12
Known ransomware campaign use: Unknown/None
CVE-2012-3152 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.988.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.1 (NVD)
FIRST EPSS: 0.988 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-2555 — Oracle Multiple Products: Oracle Multiple Products Remote Code Execution Vulnerability
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2011-3544 — Oracle Java SE JDK and JRE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-03-03
CISA remediation due: 2022-03-24
Known ransomware campaign use: Unknown/None
CVE-2010-0840 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-05-25
CISA remediation due: 2022-06-15
Known ransomware campaign use: Unknown/None
CVE-2021-35587 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2022-11-28
CISA remediation due: 2022-12-19
Known ransomware campaign use: Unknown/None
CVE-2015-4852 — Oracle WebLogic Server: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2021-11-03
CISA remediation due: 2022-05-03
Known ransomware campaign use: Unknown/None
CVE-2020-2551 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-11-16
CISA remediation due: 2023-12-07
Known ransomware campaign use: Unknown/None
CVE-2016-3427 — Oracle Java SE and JRockit: Oracle Java SE and JRockit Unspecified Vulnerability
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.
Recommended priority: Out-of-Band / Urgent Remediation
Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.923.
Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.
CISA required action: Apply updates per vendor instructions.
CVSS: 9.8 (NVD)
FIRST EPSS: 0.923 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA added: 2023-05-12
CISA remediation due: 2023-06-02
Known ransomware campaign use: Unknown/None