CVE-2021-2135: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Suppor
criticalvulnerability
security
Summary
A critical vulnerability (CVE-2021-2135) exists in Oracle WebLogic Server's Coherence Container component, affecting versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0, that allows an attacker without authentication to take over the server through network access. The vulnerability has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 9.8, meaning it is extremely serious and can compromise the confidentiality (keeping data private), integrity (ensuring data isn't modified), and availability (keeping systems running) of the affected server.
Vulnerability Details
CVSS Score
9.8(critical)
EPSS (30-day exploit probability)
EPSS: 71.4%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-2135
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%