CVE-2020-2551 is a critical flaw in the WLS Core Components of Oracle WebLogic Server that allows an unauthenticated attacker with network access to the IIOP protocol to remotely compromise the server. An attacker sends crafted IIOP requests directly to a listening WebLogic instance and gains takeover of the server, with high impact to confidentiality, integrity, and availability (CVSS 9.8). Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0 are affected, spanning widely deployed enterprise and government middleware environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), indicating active and likely broad targeting. Because exploitation requires only network reachability to the IIOP listener and no credentials or user interaction, internet-exposed WebLogic servers are the primary targets.
What to do: Apply the Oracle fixes for CVE-2020-2551 (October 2020 Critical Patch Update) to each affected WebLogic release, or move to a patched supported release per Oracle's instructions, consistent with CISA's KEV required action. Until patched, block or restrict IIOP traffic to WebLogic listeners (default port 7001) from untrusted networks and remove direct internet exposure of WebLogic admin and application servers. Review access logs for anomalous IIOP connections and check patched and unpatched hosts for signs of compromise.
Affected
Oracle WebLogic Server (Oracle Fusion Middleware, WLS Core Components)
10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
Estimated exposure
largeorder of 10,000–50,000 internet-exposed WebLogic instances (public internet-wide scans have repeatedly shown tens of thousands of hosts exposing WebLogic… — Public internet-wide scan data has repeatedly shown on the order of tens of thousands of hosts exposing WebLogic application ports, and WebLogic's broad use as enterprise middleware suggests many additional instances exist behind firewalls…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CISA Known Exploited Vulnerability
Affected
Oracle Fusion Middleware
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA added actively exploited Oracle WebLogic flaw CVE-2026-21962 (CVSS 10.0) to its KEV catalog, letting unauthenticated attackers access or modify critical data.
CISA added CVE-2026-21962, a CVSS 10.0 improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Oracle shipped patches in January 2026, and GreyNoise, CloudSEK, and SOCRadar have since reported exploitation attempts, including a lone IP scanning multiple WebLogic, Ivanti, GNU InetUtils, and GLPI vulnerabilities. The flaw is also among several exploited by a China-linked actor delivering the SNOWLIGHT downloader to government and commercial infrastructure in more than 100 countries. Federal civilian agencies must apply fixes by August 27, 2026 under BOD 26-04.
CISA added actively exploited CVE-2026-21962, a CVSS 10.0 unauthenticated flaw in Oracle HTTP Server and WebLogic Proxy Plug-in, to KEV with an August 27 deadline.
CISA added CVE-2026-21962 (CVSS 10.0), an improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate by August 27, 2026. The unauthenticated flaw allows remote attackers with network access to create, delete, or modify critical data, potentially gain broad access, and cause a scope change to other systems; affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. CloudSEK honeypot data from January-February 2026 showed widespread exploitation of the flaw alongside older WebLogic RCEs including CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271.