Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

46 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability 97 Immediate 0.955 (99.86th pctl) Known 2026-06-15
CVE-2025-61882 Oracle E-Business Suite Oracle E-Business Suite Unspecified Vulnerability 96 Immediate 0.997 (99.95th pctl) Known 2025-10-27
CVE-2019-2725 Oracle WebLogic Server Oracle WebLogic Server, Injection 94 Immediate 0.999 (99.98th pctl) Known 2022-07-10
CVE-2013-2465 Oracle Java SE Oracle Java SE Unspecified Vulnerability 93 Immediate 0.987 (99.92nd pctl) Known 2022-04-18
CVE-2012-4681 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability 93 Immediate 0.985 (99.92nd pctl) Known 2022-03-24
CVE-2022-21587 Oracle E-Business Suite Oracle E-Business Suite Unspecified Vulnerability 93 Immediate 0.983 (99.91st pctl) Known 2023-02-23
CVE-2012-0507 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability 93 Immediate 0.981 (99.91st pctl) Known 2022-03-24
CVE-2025-61884 Oracle E-Business Suite Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability 93 Immediate 0.978 (99.9th pctl) Known 2025-11-10
CVE-2013-0422 Oracle Java Runtime Environment (JRE) Oracle JRE Remote Code Execution Vulnerability 93 Immediate 0.976 (99.9th pctl) Known 2022-06-15
CVE-2012-1723 Oracle Java SE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability 92 Immediate 0.937 (99.84th pctl) Known 2022-03-24
CVE-2017-10271 Oracle WebLogic Server Oracle Corporation WebLogic Server Remote Code Execution Vulnerability 91 Immediate 0.999 (99.99th pctl) Known 2022-08-10
CVE-2020-14882 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability 87 Immediate 0.999 (99.99th pctl) Unknown/None 2022-05-03
CVE-2018-2628 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability 87 Immediate 0.994 (99.94th pctl) Unknown/None 2022-09-29
CVE-2020-14750 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability 87 Immediate 0.993 (99.93rd pctl) Unknown/None 2022-05-03
CVE-2020-2883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability 87 Immediate 0.949 (99.85th pctl) Unknown/None 2025-01-28
CVE-2020-14644 Oracle WebLogic Server Oracle WebLogic Server Remote Code Execution Vulnerability 87 Immediate 0.945 (99.85th pctl) Unknown/None 2024-10-09
CVE-2025-61757 Oracle Fusion Middleware Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability 87 Immediate 0.882 (99.76th pctl) Unknown/None 2025-12-12
CVE-2012-3152 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 86 Immediate 0.988 (99.92nd pctl) Unknown/None 2022-05-03
CVE-2020-2555 Oracle Multiple Products Oracle Multiple Products Remote Code Execution Vulnerability 86 Immediate 0.971 (99.89th pctl) Unknown/None 2022-05-03
CVE-2011-3544 Oracle Java SE JDK and JRE Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability 86 Immediate 0.967 (99.88th pctl) Unknown/None 2022-03-24
CVE-2010-0840 Oracle Java Runtime Environment (JRE) Oracle JRE Unspecified Vulnerability 86 Immediate 0.963 (99.88th pctl) Unknown/None 2022-06-15
CVE-2021-35587 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 86 Immediate 0.963 (99.88th pctl) Unknown/None 2022-12-19
CVE-2015-4852 Oracle WebLogic Server Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability 86 Immediate 0.960 (99.87th pctl) Unknown/None 2022-05-03
CVE-2020-2551 Oracle Fusion Middleware Oracle Fusion Middleware Unspecified Vulnerability 85 Immediate 0.932 (99.83rd pctl) Unknown/None 2023-12-07
CVE-2016-3427 Oracle Java SE and JRockit Oracle Java SE and JRockit Unspecified Vulnerability 85 Immediate 0.923 (99.82nd pctl) Unknown/None 2023-06-02
Download filtered advisories (CSV)

Exactly the 46 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

EVULNABLE Risk · priority 97/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.955.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.955 (99.86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-12

CISA remediation due: 2026-06-15

Known ransomware campaign use: Known

CVE-2025-61882 — Oracle E-Business Suite: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

EVULNABLE Risk · priority 96/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-06

CISA remediation due: 2025-10-27

Known ransomware campaign use: Known

CVE-2019-2725 — Oracle WebLogic Server: Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-01-10

CISA remediation due: 2022-07-10

Known ransomware campaign use: Known

CVE-2013-2465 — Oracle Java SE: Oracle Java SE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.987.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.987 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-28

CISA remediation due: 2022-04-18

Known ransomware campaign use: Known

CVE-2012-4681 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2022-21587 — Oracle E-Business Suite: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.983.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.983 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-02-02

CISA remediation due: 2023-02-23

Known ransomware campaign use: Known

CVE-2012-0507 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.981.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.981 (99.91st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2025-61884 — Oracle E-Business Suite: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.978.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.978 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-10-20

CISA remediation due: 2025-11-10

Known ransomware campaign use: Known

CVE-2013-0422 — Oracle Java Runtime Environment (JRE): Oracle JRE Remote Code Execution Vulnerability

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.976.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.976 (99.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Known

CVE-2012-1723 — Oracle Java SE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

EVULNABLE Risk · priority 92/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.937.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.937 (99.84th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Known

CVE-2017-10271 — Oracle WebLogic Server: Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 91/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-02-10

CISA remediation due: 2022-08-10

Known ransomware campaign use: Known

CVE-2020-14882 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2018-2628 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.994.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.994 (99.94th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-09-08

CISA remediation due: 2022-09-29

Known ransomware campaign use: Unknown/None

CVE-2020-14750 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.993.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.993 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-2883 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.949.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.949 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-07

CISA remediation due: 2025-01-28

Known ransomware campaign use: Unknown/None

CVE-2020-14644 — Oracle WebLogic Server: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.945.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.945 (99.85th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-18

CISA remediation due: 2024-10-09

Known ransomware campaign use: Unknown/None

CVE-2025-61757 — Oracle Fusion Middleware: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.882.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.882 (99.76th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-11-21

CISA remediation due: 2025-12-12

Known ransomware campaign use: Unknown/None

CVE-2012-3152 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.988.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.988 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-2555 — Oracle Multiple Products: Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.971.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.971 (99.89th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2011-3544 — Oracle Java SE JDK and JRE: Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.967.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.967 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-03-03

CISA remediation due: 2022-03-24

Known ransomware campaign use: Unknown/None

CVE-2010-0840 — Oracle Java Runtime Environment (JRE): Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-05-25

CISA remediation due: 2022-06-15

Known ransomware campaign use: Unknown/None

CVE-2021-35587 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.963.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.963 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2022-11-28

CISA remediation due: 2022-12-19

Known ransomware campaign use: Unknown/None

CVE-2015-4852 — Oracle WebLogic Server: Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.960.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.960 (99.87th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2020-2551 — Oracle Fusion Middleware: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.932.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.932 (99.83rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-11-16

CISA remediation due: 2023-12-07

Known ransomware campaign use: Unknown/None

CVE-2016-3427 — Oracle Java SE and JRockit: Oracle Java SE and JRockit Unspecified Vulnerability

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.923.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.923 (99.82nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-05-12

CISA remediation due: 2023-06-02

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.