CVE-2026-60702
Oracle WebLogic Server vulnerability analysis and mitigation

Overview

CVE-2026-60702 is a critical remote code execution vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows a low-privileged attacker with network access via the T3 or IIOP protocols to fully compromise the WebLogic Server, with potential scope change impacting additional products. It carries a CVSS v3.1 base score of 9.9 (Critical) (Oracle Advisory, Feedly). The vulnerability was published on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026.

Technical details

The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the T3 and IIOP protocols, which are commonly used for Java EE remote method invocation and inter-process communication in WebLogic environments. The attack requires only low privileges (authenticated network access) and no user interaction, making it easily exploitable. The scope change indicator in the CVSS vector (S:C) suggests that a successful exploit can affect resources beyond the WebLogic Server itself, such as other systems or services in the same environment. The specific root cause (CWE classification) has not been publicly disclosed by Oracle, consistent with their standard vulnerability disclosure policy (Oracle Advisory).

Impact

Successful exploitation results in complete takeover of the Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker can read, modify, or delete any data accessible to the server, disrupt service availability, and potentially pivot to other systems within the environment due to the scope change component of the vulnerability. The broad version coverage (four major supported versions) and the network-accessible attack vector significantly expand the potential attack surface across enterprise deployments (Oracle Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is currently 0.0, reflecting the early stage of public awareness. The vulnerability has not yet been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, given Oracle WebLogic's history as a high-value target and the critical severity of this flaw, the risk of future weaponization is elevated. Qualys has detected this vulnerability in its scanning platform (detection ID 87617) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Oracle WebLogic Server instances running affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0) using tools such as Shodan, Censys, or internal network scanners targeting default T3 (port 7001) and IIOP (port 2809) ports.
  2. Obtain low-privileged credentials: Acquire any valid low-privileged account credentials for the WebLogic environment, which may be obtained through phishing, credential stuffing, or reuse of default credentials.
  3. Establish protocol connection: Connect to the target WebLogic Server via the T3 or IIOP protocol using a Java-based client or a tool capable of speaking these protocols.
  4. Deliver malicious payload: Send a crafted request over T3 or IIOP that exploits the Core component vulnerability to trigger arbitrary code execution on the server.
  5. Achieve server takeover: Leverage the code execution to establish persistence, exfiltrate data, or pivot to other systems within the environment, taking advantage of the scope change to impact additional products (Oracle Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected or anomalous connections to WebLogic T3 (default port 7001) or IIOP (default port 2809) from untrusted or external IP addresses; unusual outbound connections from the WebLogic server process to unknown external hosts.
  • Logs: WebLogic server logs (server.log) showing unexpected deserialization errors, unusual class loading activity, or authentication events from low-privileged accounts followed by privileged operations; access logs showing repeated or malformed T3/IIOP requests.
  • Process: Unexpected child processes spawned by the WebLogic JVM (e.g., cmd.exe, /bin/bash, powershell.exe, curl, wget); unusual Java process activity or memory anomalies.
  • File System: New or modified files in the WebLogic deployment directories; unexpected web shells, scripts, or executables created under the WebLogic installation path; new scheduled tasks or cron jobs created by the WebLogic service account.

Mitigation and workarounds

Oracle has released patches for CVE-2026-60702 as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) immediately (Oracle Advisory). As a temporary workaround, restrict network access to T3 and IIOP protocol ports (typically 7001 and 2809) to only trusted, internal IP ranges using firewall rules or network ACLs. Additionally, limit network access for low-privileged accounts that can connect via these protocols, and monitor for exploitation attempts. Oracle strongly recommends upgrading to patched versions rather than relying on workarounds as a long-term solution.

Community reactions

The vulnerability was covered by several security news outlets shortly after Oracle's August 2026 CSPU release, with coverage noting the breadth of the patch bundle (943 security patches) and highlighting the critical WebLogic vulnerabilities (SecurityOnline, CyberPress, CybersecurityNews). Community attention has focused on the 9.9 CVSS score and the scope change, given WebLogic's history as a frequent target for ransomware and nation-state actors. No notable individual researcher commentary or vendor statements beyond the official Oracle advisory have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Oracle WebLogic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60702CRITICAL9.9
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60977CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60698CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60696CRITICAL9.8
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026
CVE-2026-60699HIGH8.6
  • Oracle WebLogic Server logoOracle WebLogic Server
  • cpe:2.3:a:oracle:weblogic_server
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management