# Oracle vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 36 Oracle CVEs, 13 in the CISA Known Exploited Vulnerabilities catalog, 5 used in ransomware campaigns, linked to 54 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 36 Oracle CVEs published between 2014-09-15 and 2026-09-15. The busiest month was 2026-07 (15 new CVEs). 13 of them (36%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Oracle CVEs.

- [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271) — CRITICAL 9.8 · KEV · EPSS 100% · 2014-09-24
- [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884) — HIGH 7.5 · KEV · Ransomware · EPSS 97.6% · 2025-10-12
- [CVE-2020-14882](https://intel.threadlinqs.com/cve/CVE-2020-14882) — CRITICAL 9.8 · KEV · EPSS 94.5% · 2020-10-21
- [CVE-2017-10271](https://intel.threadlinqs.com/cve/CVE-2017-10271) — HIGH 7.5 · KEV · Ransomware · EPSS 94.4% · 2017-10-19
- [CVE-2020-14883](https://intel.threadlinqs.com/cve/CVE-2020-14883) — HIGH 7.2 · KEV · EPSS 94.4% · 2020-10-21
- [CVE-2020-2551](https://intel.threadlinqs.com/cve/CVE-2020-2551) — CRITICAL 9.8 · KEV · EPSS 94.4% · 2020-01-15
- [CVE-2017-3506](https://intel.threadlinqs.com/cve/CVE-2017-3506) — HIGH 7.4 · KEV · EPSS 94.4% · 2017-04-24
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472) — MEDIUM 5.5 · KEV · Ransomware · EPSS 94.4% · 2020-08-17
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882) — CRITICAL 9.8 · KEV · Ransomware · EPSS 89.4% · 2025-10-05
- [CVE-2025-61757](https://intel.threadlinqs.com/cve/CVE-2025-61757) — CRITICAL 9.8 · KEV · EPSS 88.1% · 2025-10-21
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034) — HIGH 7.8 · KEV · EPSS 87.8% · 2022-01-28
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993) — HIGH 8.8 · KEV · EPSS 24.4% · 2023-09-21
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273) — CRITICAL 9.8 · KEV · Ransomware · EPSS 7.5% · 2026-06-11
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817) — CRITICAL 9.8 · EPSS 0.7% · 2026-05-28
- [CVE-2026-35278](https://intel.threadlinqs.com/cve/CVE-2026-35278) — CRITICAL 9.8 · EPSS 0.6% · 2026-06-16
- [CVE-2026-60367](https://intel.threadlinqs.com/cve/CVE-2026-60367) — CRITICAL 9.8 · EPSS 0.5% · 2026-07-22
- [CVE-2026-60372](https://intel.threadlinqs.com/cve/CVE-2026-60372) — CRITICAL 9.8 · EPSS 0.5% · 2026-07-22
- [CVE-2026-60369](https://intel.threadlinqs.com/cve/CVE-2026-60369) — CRITICAL 9.9 · EPSS 0.5% · 2026-07-22
- [CVE-2026-60368](https://intel.threadlinqs.com/cve/CVE-2026-60368) — HIGH 8.8 · EPSS 0.5% · 2026-07-22
- [CVE-2026-60373](https://intel.threadlinqs.com/cve/CVE-2026-60373) — HIGH 8.8 · EPSS 0.5% · 2026-07-22
- [CVE-2026-60168](https://intel.threadlinqs.com/cve/CVE-2026-60168) — CRITICAL 9.1 · EPSS 0.4% · 2026-07-21
- [CVE-2026-60167](https://intel.threadlinqs.com/cve/CVE-2026-60167) — HIGH 7.5 · EPSS 0.4% · 2026-07-21
- [CVE-2026-60170](https://intel.threadlinqs.com/cve/CVE-2026-60170) — HIGH 7.5 · EPSS 0.4% · 2026-07-21
- [CVE-2026-60370](https://intel.threadlinqs.com/cve/CVE-2026-60370) — HIGH 7.5 · EPSS 0.4% · 2026-07-22
- [CVE-2026-60169](https://intel.threadlinqs.com/cve/CVE-2026-60169) — HIGH 8.1 · EPSS 0.3% · 2026-07-21
- [CVE-2026-35271](https://intel.threadlinqs.com/cve/CVE-2026-35271) — HIGH 8.7 · EPSS 0.3% · 2026-06-16
- [CVE-2026-83357](https://intel.threadlinqs.com/cve/CVE-2026-83357) — HIGH 8.1 · EPSS 0.3% · 2026-09-15
- [CVE-2026-83408](https://intel.threadlinqs.com/cve/CVE-2026-83408) — HIGH 8.1 · EPSS 0.3% · 2026-09-15
- [CVE-2026-60371](https://intel.threadlinqs.com/cve/CVE-2026-60371) — HIGH 8 · EPSS 0.3% · 2026-07-22
- [CVE-2026-83368](https://intel.threadlinqs.com/cve/CVE-2026-83368) — HIGH 7 · EPSS 0.2% · 2026-09-15
- [CVE-2026-21992](https://intel.threadlinqs.com/cve/CVE-2026-21992) — CRITICAL 9.8 · EPSS 0.1% · 2026-03-20
- [CVE-2026-21962](https://intel.threadlinqs.com/cve/CVE-2026-21962) — CRITICAL 9.8 · EPSS 0% · 2026-01-20
- [CVE-2026-60366](https://intel.threadlinqs.com/cve/CVE-2026-60366) — CRITICAL 10 · 2026-07-22
- [CVE-2026-60439](https://intel.threadlinqs.com/cve/CVE-2026-60439) — HIGH 8.8 · 2026-07-22
- [CVE-2026-60455](https://intel.threadlinqs.com/cve/CVE-2026-60455) — HIGH 8.8 · 2026-07-22
- [CVE-2026-61246](https://intel.threadlinqs.com/cve/CVE-2026-61246) — HIGH 8.8 · 2026-07-22

## Products affected

Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 19 distinct Oracle products are affected. The most frequently affected:

- Platform Security for Java — 11 CVEs
- Weblogic Server — 5 CVEs
- Hospitality Simphony — 4 CVEs
- GraalVM for JDK, Oracle GraalVM — 2 CVEs
- Http Server — 2 CVEs
- Identity Manager — 2 CVEs
- PeopleSoft Enterprise PT PeopleTools — 2 CVEs
- Zfs Storage Appliance Kit — 2 CVEs
- Concurrent Processing — 1 CVE
- Configurator — 1 CVE
- GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM — 1 CVE
- Graalvm — 1 CVE
- Jdk — 1 CVE
- Jre — 1 CVE
- Linux — 1 CVE
- Payments — 1 CVE
- PeopleSoft Enterprise PeopleTools — 1 CVE
- Web Services Manager — 1 CVE
- Weblogic Server Proxy Plug-In — 1 CVE

## Threat activity

54 tracked threat campaigns reference Oracle products or exploit Oracle CVEs; the 25 most recent are listed.

- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — HIGH — 2026-10-01
- [Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)](https://intel.threadlinqs.com/threat/TL-2026-2796) — HIGH — 2026-09-29
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data](https://intel.threadlinqs.com/threat/TL-2026-2760) — HIGH — 2026-09-28
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — CRITICAL — 2026-09-22
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion](https://intel.threadlinqs.com/threat/TL-2026-2584) — MEDIUM — 2026-09-19
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)](https://intel.threadlinqs.com/threat/TL-2026-2572) — HIGH — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — HIGH — 2026-09-17
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — 2026-09-15
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — HIGH — 2026-09-08
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH — 2026-08-29
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-2220) — HIGH — 2026-08-29
- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2135) — HIGH — 2026-08-24
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including Unauthenticated Web Services Security Flaws (CVE-2026-71052, CVE-2026-71053)](https://intel.threadlinqs.com/threat/TL-2026-2064) — CRITICAL — 2026-08-18
- [khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2067) — HIGH — 2026-08-18
- [Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM Access](https://intel.threadlinqs.com/threat/TL-2026-1910) — CRITICAL — 2026-08-06
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — HIGH — 2026-08-06
- [DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography](https://intel.threadlinqs.com/threat/TL-2026-1847) — HIGH — 2026-08-03
- [Khunt Post-Exploitation Toolkit Deployed via Oracle Database JVM (Huntress Discovery)](https://intel.threadlinqs.com/threat/TL-2026-1903) — CRITICAL — 2026-07-27
- [Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026)](https://intel.threadlinqs.com/threat/TL-2026-1616) — HIGH — 2026-07-22
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — 2026-07-22
- [Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)](https://intel.threadlinqs.com/threat/TL-2026-1638) — CRITICAL — 2026-07-22
- [Estée Lauder Data Breach via Oracle E-Business Suite Zero-Day (CVE-2025-61882) — Clop Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1590) — CRITICAL — 2026-07-21

## Threat actors targeting Oracle

Named threat actors attributed to campaigns that involve Oracle products or CVEs, with the number of linked campaigns:

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4 campaigns
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2 campaigns
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 2 campaigns
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2 campaigns
- [Rhysida](https://intel.threadlinqs.com/actor/Rhysida) — 2 campaigns
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2 campaigns
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 2 campaigns
- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1 campaign
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1 campaign
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1 campaign
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1 campaign

## How to prioritise Oracle patching

This order follows the data Threadlinqs holds for Oracle, not a generic severity checklist:

- 13 of 36 Oracle CVEs (36%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2014-6271](https://intel.threadlinqs.com/cve/CVE-2014-6271), [CVE-2025-61884](https://intel.threadlinqs.com/cve/CVE-2025-61884), [CVE-2020-14882](https://intel.threadlinqs.com/cve/CVE-2020-14882).
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817) (0.7%), [CVE-2026-35278](https://intel.threadlinqs.com/cve/CVE-2026-35278) (0.6%), [CVE-2026-60367](https://intel.threadlinqs.com/cve/CVE-2026-60367) (0.5%).
- 15 CVEs score Critical and 20 High on CVSS v3 (maximum 10, average 8.7); sequence these after KEV and high-EPSS items.
- 4 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/oracle
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
