TL;DR
Oracle patched nine flaws in WebLogic Server in a special August 2026 update. Five carry critical scores. The top Oracle WebLogic vulnerability, CVE-2026-60702, scores a CVSS of 9.9. Successful attacks can result in a full takeover of Oracle WebLogic Server.
- Total: 9 CVEs
- Severity: 5 Critical · 4 High
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-60702
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-60702 | 9.9 | — | Not exploited |
| CVE-2026-60698 | 9.8 | — | Not exploited |
| CVE-2026-60977 | 9.8 | — | Not exploited |
| CVE-2026-60672 | 9.8 | — | Not exploited |
| CVE-2026-60696 | 9.8 | — | Not exploited |
| CVE-2026-60699 | 8.6 | — | Not exploited |
| CVE-2026-60680 | 8.1 | — | Not exploited |
| CVE-2026-60415 | 8.1 | — | Not exploited |
Why it matters
WebLogic Server runs core enterprise applications. A takeover there is severe. Five flaws in this Oracle WebLogic vulnerability set score 9.8 or higher. Most need no authentication at all.
Attackers often chase WebLogic after each Oracle update. History shows it. Older WebLogic bugs have landed on CISA’s exploited list before.
How the attacks work
Most flaws abuse legacy network protocols. These include T3, IIOP, and RMI. An attacker sends crafted traffic to these interfaces. That access can then result in a full server takeover.
The top flaw, CVE-2026-60702, needs only low privileges. It also carries a scope change, so it may hit other products. Four more unauthenticated bugs, CVE-2026-60698, CVE-2026-60977, CVE-2026-60672, and CVE-2026-60696, each score 9.8. Oracle’s August 2026 security alert lists the full set.
Affected versions
The flaws affect WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. One flaw, CVE-2026-60977, does not list the 15.1.1.0.0 branch.
Exploitation status and patch steps
Oracle has not confirmed in-the-wild exploitation of these specific flaws. Even so, apply the update at once. Oracle strongly recommends patching without delay. Where you can, restrict access to the T3 and IIOP protocols too.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.