Junglewise Threat Intelligence

CVE-2026-60199: Oracle WebLogic Server remote compromise in Core component

CVE-2026-60199 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server, a critical platform for running enterprise business applications, contains a severe security flaw in its core component. An unauthorized person can use this vulnerability over the internet to take complete control of the server without needing a username or password. This could lead to the theft of sensitive data, disruption of business operations, and full system compromise.

Technical details

A critical vulnerability exists in the Core component of Oracle WebLogic Server. The flaw is easily exploitable by an unauthenticated attacker with network access via the HTTP protocol. Successful exploitation allows for a complete takeover of the affected WebLogic Server instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats