CVE-2018-2628

ENISA EUVD: EUVD-2018-14483 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 2 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.42%
probability
This CVE has a 94.42% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
9.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

Attack Intelligence

Exploits & PoC

0xn0ne/weblogicScanner

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-20

2070
tdy218/ysoserial-cve-2018-2628

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

114
jas502n/CVE-2018-2628

Weblogic 反序列化漏洞(CVE-2018-2628)

107
shengqi158/CVE-2018-2628

CVE-2018-2628 & CVE-2018-2893

78
20
aedoo/CVE-2018-2628-MultiThreading

WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading

15
jiansiting/weblogic-cve-2018-2628

PoC CVE-2018-2628 — jiansiting/weblogic-cve-2018-2628

14
0xMJ/CVE-2018-2628

漏洞利用工具

12
Nervous/WebLogic-RCE-exploit

A remote code execution exploit for WebLogic based on CVE-2018-2628

5
9 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
75%
EPSS 94.42%
CVSS v3.1 9.8
Mentions 2
Last Seen Jul 26, 2018

CNA Information

Analyst Note

CVE-2018-2628 is a critical Oracle WebLogic vulnerability (CVSS 9.8) published April 19, 2018. CERT-EU explicitly documented exploitation in the wild. While Google Project Zero and CISA KEV listings are absent, the contemporary CERT-EU advisory reporting active exploitation coinciding with the April 2018 publication date supports zero-day classification. The unauthenticated network-accessible attack vector and immediate real-world exploitation align with zero-day indicators.

Triage Info

Decided atMar 05, 2026