High-Privilege Console Flaw in Oracle WebLogic Server Enables Full Takeover
CISA: Oracle WebLogic Server Unspecified Vulnerability
CVSS 3.1
7.2high
EPSS
98%p100
Published
()
KEV added
AI analysis
CVE-2020-14883 is a vulnerability in the Console component of Oracle WebLogic Server that is exploitable over HTTP by a high-privileged attacker with network access; a successful attack results in complete takeover of the WebLogic Server, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 7.2). Oracle rates it as easily exploitable (low attack complexity, no user interaction required), and public reporting on the actively exploited WebLogic flaws describes unauthenticated attackers accessing critical data, typically because the required privileged console access is first obtained via the related unauthenticated console flaw fixed in the same October 2020 Critical Patch Update. All supported WebLogic versions listed by Oracle are affected - 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 - wherever the administration console is network-reachable. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with applying vendor updates as the required action, EPSS assigns a 97.9% probability of exploitation within 30 days (100th percentile), and public reporting describes malware campaigns against exposed WebLogic servers, including the 8220 gang exploiting older WebLogic flaws to deliver infostealers and cryptominers.
What to do: Apply Oracle's October 2020 Critical Patch Update or later to all affected WebLogic Server versions (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0), per the vendor's instructions. Until patched, restrict HTTP access to the WebLogic administration console to trusted admin networks and hunt for signs of compromise on internet-facing consoles, given confirmed in-the-wild exploitation and malware campaigns targeting exposed servers.
Affected
Oracle WebLogic Server (Console component, Oracle Fusion Middleware)
largeabout 10,000-40,000 internet-exposed WebLogic servers (order of magnitude: tens of thousands) — Public internet-wide scans have historically counted Oracle WebLogic among the most prevalent exposed middleware products at roughly tens of thousands of reachable hosts, and its ubiquity in enterprise data centers implies many more…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
CISA added actively exploited Oracle WebLogic flaw CVE-2026-21962 (CVSS 10.0) to its KEV catalog, letting unauthenticated attackers access or modify critical data.
CISA added CVE-2026-21962, a CVSS 10.0 improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Oracle shipped patches in January 2026, and GreyNoise, CloudSEK, and SOCRadar have since reported exploitation attempts, including a lone IP scanning multiple WebLogic, Ivanti, GNU InetUtils, and GLPI vulnerabilities. The flaw is also among several exploited by a China-linked actor delivering the SNOWLIGHT downloader to government and commercial infrastructure in more than 100 countries. Federal civilian agencies must apply fixes by August 27, 2026 under BOD 26-04.
CISA added actively exploited CVE-2026-21962, a CVSS 10.0 unauthenticated flaw in Oracle HTTP Server and WebLogic Proxy Plug-in, to KEV with an August 27 deadline.
CISA added CVE-2026-21962 (CVSS 10.0), an improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate by August 27, 2026. The unauthenticated flaw allows remote attackers with network access to create, delete, or modify critical data, potentially gain broad access, and cause a scope change to other systems; affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. CloudSEK honeypot data from January-February 2026 showed widespread exploitation of the flaw alongside older WebLogic RCEs including CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271.