Exploitation timeline
Threadlinqs has recorded 36 Oracle CVEs published between and . The busiest month was 2026-07 (15 new CVEs). 13 of them (36%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Oracle CVEs.
- CVE-2014-6271critical 9.8KEVEPSS 100%
- CVE-2025-61884high 7.5KEVRansomwareEPSS 97.6%
- CVE-2020-14882critical 9.8KEVEPSS 94.5%
- CVE-2017-10271high 7.5KEVRansomwareEPSS 94.4%
- CVE-2020-14883high 7.2KEVEPSS 94.4%
- CVE-2020-2551critical 9.8KEVEPSS 94.4%
- CVE-2017-3506high 7.4KEVEPSS 94.4%
- CVE-2020-1472medium 5.5KEVRansomwareEPSS 94.4%
- CVE-2025-61882critical 9.8KEVRansomwareEPSS 89.4%
- CVE-2025-61757critical 9.8KEVEPSS 88.1%
- CVE-2021-4034high 7.8KEVEPSS 87.8%
- CVE-2023-41993high 8.8KEVEPSS 24.4%
- CVE-2026-35273critical 9.8KEVRansomwareEPSS 7.5%
- CVE-2026-46817critical 9.8EPSS 0.7%
- CVE-2026-35278critical 9.8EPSS 0.6%
- CVE-2026-60367critical 9.8EPSS 0.5%
- CVE-2026-60372critical 9.8EPSS 0.5%
- CVE-2026-60369critical 9.9EPSS 0.5%
- CVE-2026-60368high 8.8EPSS 0.5%
- CVE-2026-60373high 8.8EPSS 0.5%
- CVE-2026-60168critical 9.1EPSS 0.4%
- CVE-2026-60167high 7.5EPSS 0.4%
- CVE-2026-60170high 7.5EPSS 0.4%
- CVE-2026-60370high 7.5EPSS 0.4%
- CVE-2026-60169high 8.1EPSS 0.3%
- CVE-2026-35271high 8.7EPSS 0.3%
- CVE-2026-83357high 8.1EPSS 0.3%
- CVE-2026-83408high 8.1EPSS 0.3%
- CVE-2026-60371high 8EPSS 0.3%
- CVE-2026-83368high 7EPSS 0.2%
- CVE-2026-21992critical 9.8EPSS 0.1%
- CVE-2026-21962critical 9.8EPSS 0%
- CVE-2026-60366critical 10
- CVE-2026-60439high 8.8
- CVE-2026-60455high 8.8
- CVE-2026-61246high 8.8
Products affected
Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 19 distinct Oracle products are affected. The most frequently affected:
- Platform Security for Java 11 CVEs
- Weblogic Server 5 CVEs
- Hospitality Simphony 4 CVEs
- GraalVM for JDK, Oracle GraalVM 2 CVEs
- Http Server 2 CVEs
- Identity Manager 2 CVEs
- PeopleSoft Enterprise PT PeopleTools 2 CVEs
- Zfs Storage Appliance Kit 2 CVEs
- Concurrent Processing 1 CVE
- Configurator 1 CVE
- GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM 1 CVE
- Graalvm 1 CVE
- Jdk 1 CVE
- Jre 1 CVE
- Linux 1 CVE
- Payments 1 CVE
- PeopleSoft Enterprise PeopleTools 1 CVE
- Web Services Manager 1 CVE
- Weblogic Server Proxy Plug-In 1 CVE
Threat activity
54 tracked threat campaigns reference Oracle products or exploit Oracle CVEs; the 25 most recent are listed.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2HIGH
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)HIGH
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal DataHIGH
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI LeakCRITICAL
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour ExtortionMEDIUM
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling ObservedHIGH
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-ServiceHIGH
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)CRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September ElectionHIGH
- CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEVHIGH
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta InfrastructureHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including Unauthenticated Web Services Security Flaws (CVE-2026-71052, CVE-2026-71053)CRITICAL
- khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-ExploitationHIGH
- Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM AccessCRITICAL
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux HostHIGH
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via SteganographyHIGH
- Khunt Post-Exploitation Toolkit Deployed via Oracle Database JVM (Huntress Discovery)CRITICAL
- Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026)HIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)HIGH
- Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)CRITICAL
- Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop ExploitationCRITICAL
Threat actors targeting Oracle
Named threat actors attributed to campaigns that involve Oracle products or CVEs, with the number of linked campaigns:
How to prioritise Oracle patching
This order follows the data Threadlinqs holds for Oracle, not a generic severity checklist:
- 13 of 36 Oracle CVEs (36%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2014-6271, CVE-2025-61884, CVE-2020-14882.
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-46817 (0.7%), CVE-2026-35278 (0.6%), CVE-2026-60367 (0.5%).
- 15 CVEs score Critical and 20 High on CVSS v3 (maximum 10, average 8.7); sequence these after KEV and high-EPSS items.
- 4 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.