TL;DR
Oracle patched 11 flaws in the WebLogic Server Core component this July. Most allow a full Oracle WebLogic Server takeover. The top issue, CVE-2026-60206, carries a CVSS score of 9.9 and can spread beyond the server itself.
Why it matters
WebLogic Server runs critical Java applications in many enterprises. It also sits exposed to networks, which makes it a favourite target. Nine of these eleven bugs need no login at all.
Attackers have hit WebLogic hard in past years. A fresh batch of takeover-grade flaws therefore deserves fast action.
How the attacks work
Each Oracle WebLogic Server vulnerability lives in the same Core component. The paths in differ, though. Attackers reach these flaws over HTTP, T3, IIOP, SOAP or SAML.
CVE-2026-60206 stands apart. It needs only low privileges, yet it carries a scope change. As a result, a successful attack can affect other products, not just WebLogic.
The 9.8-rated cluster
Eight more flaws share a CVSS score of 9.8. CVE-2026-60205, CVE-2026-60204 and CVE-2026-60202 all allow unauthenticated takeover. CVE-2026-60198, CVE-2026-60294, CVE-2026-60200, CVE-2026-60291, CVE-2026-60292 and CVE-2026-60199 round out that group.
One flaw scores slightly lower. CVE-2026-60208, rated 9.1, exposes or alters critical data without granting full control.
Affected versions
The bugs hit several supported branches. These include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Coverage varies by CVE, so check each one.
Exploitation status
No confirmed in-the-wild exploitation targets this Oracle WebLogic Server vulnerability set. No public proof-of-concept code exists for these specific CVEs either. Still, the low complexity raises real concern.
Patch and mitigation
Apply the fixes without delay. The Oracle Critical Patch Update advisory for July 2026 lists the patch details for every affected version.
Two steps reduce exposure while you patch. First, restrict access to T3, IIOP and admin ports. Second, place WebLogic behind a firewall and block untrusted network traffic.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.