CVE-2026-60698
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-60698 is a critical remote code execution vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability is easily exploitable by unauthenticated attackers with network access via the IIOP (Internet Inter-ORB Protocol) protocol, enabling full server takeover. It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory, Feedly).

Technical details

The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the IIOP protocol, which is used for remote object communication in Java EE environments. WebLogic's IIOP listener accepts unauthenticated remote connections, and the flaw allows attackers to leverage this interface to achieve arbitrary code execution — consistent with deserialization or remote object invocation weaknesses historically associated with WebLogic's IIOP stack (CWE-502 or similar). No authentication or user interaction is required, and attack complexity is low, making this trivially exploitable by any network-accessible attacker. No public proof-of-concept code has been identified at this time (Oracle Advisory, Feedly).

Impact

Successful exploitation results in complete takeover of the affected Oracle WebLogic Server instance, with high impact to confidentiality, integrity, and availability. An unauthenticated remote attacker can execute arbitrary commands with the privileges of the WebLogic server process, read and modify sensitive application data, and disrupt service availability. Given WebLogic's typical role as a critical application server in enterprise environments, compromise could enable lateral movement to backend databases, connected services, and internal network segments (Oracle Advisory, Feedly).

Exploitability

As of the time of disclosure (August 18, 2026), there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation. The EPSS score is reported at 0.0, reflecting the early stage of public awareness. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. However, the combination of a CVSS 9.8 score, unauthenticated network exploitability via IIOP, and Oracle WebLogic's history as a high-value target makes rapid weaponization a significant concern (Feedly, Oracle Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Oracle WebLogic Server instances running affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) using tools such as Shodan or Censys, searching for open IIOP ports (default: TCP 2809 or 7001/7002 with IIOP enabled).
  2. Confirm IIOP exposure: Probe the target to confirm the IIOP listener is active and accessible without authentication.
  3. Craft malicious IIOP request: Prepare a malicious IIOP payload targeting the vulnerable Core component — historically, WebLogic IIOP vulnerabilities have involved crafted serialized Java objects sent to the IIOP endpoint.
  4. Deliver payload: Transmit the crafted IIOP request to the target server's IIOP port without providing any credentials.
  5. Achieve code execution: The server processes the malicious payload, resulting in arbitrary command execution with WebLogic server process privileges, enabling reverse shell establishment, data exfiltration, or further lateral movement (Oracle Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or anomalous inbound connections to WebLogic IIOP ports (TCP 2809, 7001, 7002) from untrusted external IP addresses; outbound connections from the WebLogic server process to unknown external hosts.
  • Logs: WebLogic server logs (server.log) showing unusual IIOP connection attempts or deserialization errors; access logs with unexpected remote object invocation requests.
  • Process: Unusual child processes spawned by the WebLogic JVM (e.g., cmd.exe, /bin/bash, curl, wget, powershell) indicating command execution.
  • File System: Unexpected new files, scripts, or web shells written to the WebLogic domain directory or deployment directories; new scheduled tasks or cron jobs created by the WebLogic service account.

Mitigation and workarounds

Oracle has addressed this vulnerability as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) immediately. As a temporary workaround, restrict network access to WebLogic IIOP ports (TCP 2809, 7001, 7002) using firewalls or network ACLs, allowing only trusted systems to connect. Implement network segmentation to limit IIOP exposure to internal trusted networks only, and monitor IIOP traffic for anomalous activity. Oracle strongly recommends applying patches without delay rather than relying on workarounds as a long-term solution (Oracle Advisory).

Community reactions

The vulnerability was disclosed as part of Oracle's August 2026 Critical Security Patch Update, which contained 943 new security patches across Oracle product families. Security news outlets including CyberSecurityNews and SecurityOnline.info covered the broader Oracle patch release, highlighting the critical WebLogic vulnerabilities. Community attention has focused on the unauthenticated IIOP attack vector, consistent with prior high-profile WebLogic IIOP vulnerabilities that have historically been rapidly weaponized (CyberSecurityNews, SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60702CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60977CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60698CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60696CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60699HIGH8.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management