← Vulnerability feed

Vulnerability record · CVE-2018-2628 · published 19 April 2018

CVE-2018-2628: Oracle WebLogic Server T3 deserialization allows unauthenticated remote takeover

Oracle · Weblogic Server

Oracle WebLogic Server contains a deserialization of untrusted data flaw (CWE-502) in the WLS Core Components, reachable over the T3 protocol. An unauthenticated network attacker can send crafted serialized data to the T3 listener and achieve remote code execution, leading to full takeover of the server. The affected supported versions are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.

9.8 CVSS 3.1 Critical CISA KEV since 8 Sep 2022 EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network RCE, CISA KEV listing, public exploits and near-maximum EPSS make this an urgent patch-or-mitigate item.

What it is

Oracle WebLogic Server contains a deserialization of untrusted data flaw (CWE-502) in the WLS Core Components, reachable over the T3 protocol. An unauthenticated network attacker can send crafted serialized data to the T3 listener and achieve remote code execution, leading to full takeover of the server. The affected supported versions are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.

Impact

Successful exploitation gives the attacker complete control of the WebLogic Server process, with high confidentiality, integrity and availability impact. This typically means arbitrary code execution in the server's context and potential lateral movement into connected systems.

Attack surface

The flaw is reached over the network via the T3 protocol, which is exposed by default on WebLogic Server. No authentication or user interaction is required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-09-08, and public Exploit-DB entries exist, indicating active exploitation. EPSS is 0.99448 (99.9th percentile), consistent with very high likelihood of exploitation.

What to do

  • Apply the Oracle April 2018 CPU patch for the affected WebLogic versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3) as the primary fix.
  • Restrict network access to the T3/T3S listener so only trusted hosts can reach it; block T3 from untrusted networks.
  • If T3 is not required, disable the T3 protocol or filter it at the network layer.
  • Run WebLogic with least privilege and isolate it from sensitive internal networks to limit post-exploitation movement.
  • Monitor for and apply any later Oracle CPU updates that supersede the April 2018 fix.

Detection

  • Monitor network traffic to WebLogic T3 ports for anomalous serialized payloads or unexpected T3 handshakes from untrusted sources.
  • Alert on WebLogic server process spawning child processes such as cmd.exe, /bin/sh, or other unexpected executables.
  • Review WebLogic logs for T3 connection errors, deserialization exceptions, or unusual class loading activity.
  • Hunt for outbound connections from WebLogic hosts to unknown external IPs following T3 traffic, which may indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-2628 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "Oracle WebLogic Server Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchVendor Advisory
http://www.securityfocus.com/bid/103776 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040696 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/brianwrf/CVE-2018-2628 Broken Link
https://www.exploit-db.com/exploits/44553/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45193/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46513/ ExploitThird Party AdvisoryVDB Entry
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchVendor Advisory
http://www.securityfocus.com/bid/103776 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040696 Broken LinkThird Party AdvisoryVDB Entry
https://github.com/brianwrf/CVE-2018-2628 Broken Link
https://www.exploit-db.com/exploits/44553/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45193/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/46513/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2628 US Government Resource

Track CVE-2018-2628 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2020-14750Oracle WebLogic Server Console unauthenticated remote code executionOracle WebLogic Server's Console component contains an easily exploitable flaw affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and …KEVEPSS 99%analysed9.8CVE-2020-14882Oracle WebLogic Server Console unauthenticated remote code executionThe Oracle WebLogic Server Console component contains an easily exploitable flaw that lets an unauthenticated attacker with network access take over …KEVEPSS 100%analysed9.8CVE-2020-14644Oracle WebLogic Server unauthenticated RCE via IIOP and T3Oracle WebLogic Server Core contains an easily exploitable flaw reachable over the network through IIOP and T3. An unauthenticated attacker can explo…KEVEPSS 95%analysed9.8CVE-2020-2883Oracle WebLogic Server Core unauthenticated remote code execution via IIOP/T3Oracle WebLogic Server Core contains an easily exploitable vulnerability reachable over the network through IIOP and T3. An unauthenticated attacker …KEVEPSS 95%analysed9.8CVE-2020-2551Oracle WebLogic Server IIOP Deserialization RCEOracle WebLogic Server contains an easily exploitable vulnerability in WLS Core Components reachable over IIOP. An unauthenticated network attacker c…KEVEPSS 93%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2018-2628), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.