
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70757 is a critical improper authentication vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability allows unauthenticated attackers with network access via the T3 or IIOP protocols to fully compromise the affected server. It was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).
The vulnerability is classified under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), indicating that critical server functions accessible via the T3 and IIOP protocols lack adequate authentication controls. T3 and IIOP are WebLogic-specific protocols used for remote Java object communication (RMI/CORBA), and they have historically been vectors for deserialization and authentication bypass attacks in WebLogic environments. An unauthenticated attacker with network-level access to the WebLogic listen port (typically 7001/7002) can exploit this flaw without any user interaction or special privileges, making it highly automatable. No public proof-of-concept or technical write-up has been identified at the time of disclosure (Oracle Advisory).
Successful exploitation results in a complete takeover of the Oracle WebLogic Server, with full impact to confidentiality, integrity, and availability. An attacker can execute arbitrary code, read or modify sensitive data and configurations, and disrupt service availability — effectively gaining the same level of access as the WebLogic service account. Given WebLogic's typical role as an enterprise application server, compromise could enable lateral movement into connected databases, backend services, and internal networks (Oracle Advisory).
As of the disclosure date (September 15, 2026), there is no evidence of public proof-of-concept code or active in-the-wild exploitation. The vulnerability is classified as "automatable" by NVD SSVC analysis, meaning it can be exploited at scale without manual interaction. The EPSS score is approximately 0.0033 (0.33%), reflecting a currently low but non-negligible probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Oracle Advisory).
Note: No public PoC or detailed technical write-up is available at this time; the above steps are based on the vulnerability's characteristics and historical T3/IIOP attack patterns against WebLogic (Oracle Advisory).
server.log) showing unauthenticated or failed authentication attempts on T3/IIOP endpoints; unexpected class loading or deserialization events in application logs./domains/<domain>/servers/<server>/tmp/, /autodeploy/).cmd.exe, /bin/bash, curl, wget, powershell); unexpected scheduled tasks or cron jobs created under the WebLogic service account.Oracle has released patches for all affected versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0) as part of the September 2026 Critical Security Patch Update; applying these patches immediately is the recommended remediation (Oracle Advisory). As a temporary workaround, restrict network access to the WebLogic T3 and IIOP protocol ports (typically 7001, 7002, 9002) to trusted IP addresses only using firewall rules or network ACLs. Oracle also recommends implementing network segmentation to limit exposure of WebLogic Server instances to untrusted networks. Organizations should ensure they are running actively supported versions eligible for security patches under Oracle's Lifetime Support Policy.
The vulnerability was covered in Oracle's September 2026 CSPU, which addressed 673 vulnerabilities across Oracle product families — a release scale that drew attention from the security community. Waratek published an analysis of the September 2026 Oracle CSPU (Waratek Analysis), and AusCERT issued a security bulletin (ASB-2026.0229) referencing the advisory. Beyond Machines also noted the breadth of the patch release. No specific high-profile researcher commentary or social media discussion focused exclusively on CVE-2026-70757 has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."