
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60702 is a critical remote code execution vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows a low-privileged attacker with network access via the T3 or IIOP protocols to fully compromise the WebLogic Server, with potential scope change impacting additional products. It carries a CVSS v3.1 base score of 9.9 (Critical) (Oracle Advisory, Feedly). The vulnerability was published on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026.
The vulnerability resides in the Core component of Oracle WebLogic Server and is exploitable via the T3 and IIOP protocols, which are commonly used for Java EE remote method invocation and inter-process communication in WebLogic environments. The attack requires only low privileges (authenticated network access) and no user interaction, making it easily exploitable. The scope change indicator in the CVSS vector (S:C) suggests that a successful exploit can affect resources beyond the WebLogic Server itself, such as other systems or services in the same environment. The specific root cause (CWE classification) has not been publicly disclosed by Oracle, consistent with their standard vulnerability disclosure policy (Oracle Advisory).
Successful exploitation results in complete takeover of the Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability. An attacker can read, modify, or delete any data accessible to the server, disrupt service availability, and potentially pivot to other systems within the environment due to the scope change component of the vulnerability. The broad version coverage (four major supported versions) and the network-accessible attack vector significantly expand the potential attack surface across enterprise deployments (Oracle Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is currently 0.0, reflecting the early stage of public awareness. The vulnerability has not yet been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, given Oracle WebLogic's history as a high-value target and the critical severity of this flaw, the risk of future weaponization is elevated. Qualys has detected this vulnerability in its scanning platform (detection ID 87617) (Feedly).
server.log) showing unexpected deserialization errors, unusual class loading activity, or authentication events from low-privileged accounts followed by privileged operations; access logs showing repeated or malformed T3/IIOP requests.cmd.exe, /bin/bash, powershell.exe, curl, wget); unusual Java process activity or memory anomalies.Oracle has released patches for CVE-2026-60702 as part of the August 2026 Critical Security Patch Update (CSPU); administrators should apply the relevant patches for affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) immediately (Oracle Advisory). As a temporary workaround, restrict network access to T3 and IIOP protocol ports (typically 7001 and 2809) to only trusted, internal IP ranges using firewall rules or network ACLs. Additionally, limit network access for low-privileged accounts that can connect via these protocols, and monitor for exploitation attempts. Oracle strongly recommends upgrading to patched versions rather than relying on workarounds as a long-term solution.
The vulnerability was covered by several security news outlets shortly after Oracle's August 2026 CSPU release, with coverage noting the breadth of the patch bundle (943 security patches) and highlighting the critical WebLogic vulnerabilities (SecurityOnline, CyberPress, CybersecurityNews). Community attention has focused on the 9.9 CVSS score and the scope change, given WebLogic's history as a frequent target for ransomware and nation-state actors. No notable individual researcher commentary or vendor statements beyond the official Oracle advisory have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."