CVE-2026-60696: Critical severity Oracle WebLogic Server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Oracle WebLogic Server deployments on supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected when an attacker has network access through T3 or IIOP.
Does exploitation require credentials or user interaction?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access, and it requires neither privileges nor user interaction.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact.