
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60698 is a critical remote code execution vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability is easily exploitable by unauthenticated attackers with network access via the IIOP (Internet Inter-ORB Protocol) protocol, enabling full server takeover. It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory, Feedly).
The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the IIOP protocol, which is used for remote object communication in Java EE environments. WebLogic's IIOP listener accepts unauthenticated remote connections, and the flaw allows attackers to leverage this interface to achieve arbitrary code execution — consistent with deserialization or remote object invocation weaknesses historically associated with WebLogic's IIOP stack (CWE-502 or similar). No authentication or user interaction is required, and attack complexity is low, making this trivially exploitable by any network-accessible attacker. No public proof-of-concept code has been identified at this time (Oracle Advisory, Feedly).
Successful exploitation results in complete takeover of the affected Oracle WebLogic Server instance, with high impact to confidentiality, integrity, and availability. An unauthenticated remote attacker can execute arbitrary commands with the privileges of the WebLogic server process, read and modify sensitive application data, and disrupt service availability. Given WebLogic's typical role as a critical application server in enterprise environments, compromise could enable lateral movement to backend databases, connected services, and internal network segments (Oracle Advisory, Feedly).
As of the time of disclosure (August 18, 2026), there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation. The EPSS score is reported at 0.0, reflecting the early stage of public awareness. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. However, the combination of a CVSS 9.8 score, unauthenticated network exploitability via IIOP, and Oracle WebLogic's history as a high-value target makes rapid weaponization a significant concern (Feedly, Oracle Advisory).
server.log) showing unusual IIOP connection attempts or deserialization errors; access logs with unexpected remote object invocation requests.cmd.exe, /bin/bash, curl, wget, powershell) indicating command execution.Oracle has addressed this vulnerability as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) immediately. As a temporary workaround, restrict network access to WebLogic IIOP ports (TCP 2809, 7001, 7002) using firewalls or network ACLs, allowing only trusted systems to connect. Implement network segmentation to limit IIOP exposure to internal trusted networks only, and monitor IIOP traffic for anomalous activity. Oracle strongly recommends applying patches without delay rather than relying on workarounds as a long-term solution (Oracle Advisory).
The vulnerability was disclosed as part of Oracle's August 2026 Critical Security Patch Update, which contained 943 new security patches across Oracle product families. Security news outlets including CyberSecurityNews and SecurityOnline.info covered the broader Oracle patch release, highlighting the critical WebLogic vulnerabilities. Community attention has focused on the unauthenticated IIOP attack vector, consistent with prior high-profile WebLogic IIOP vulnerabilities that have historically been rapidly weaponized (CyberSecurityNews, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."