CVE-2026-60672: Critical severity Oracle Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this vulnerability?
Oracle WebLogic Server deployments running versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 are affected when an attacker has network access to the T3 or IIOP protocols.
Does exploitation require authentication or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access, and the CVSS vector indicates low attack complexity and no user interaction.
What is the potential impact of a successful attack?
A successful attack can result in takeover of Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability.