Junglewise Threat Intelligence

CVE-2026-70756: Oracle WebLogic Server remote code execution in T3/IIOP

CVE-2026-70756 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Oracle WebLogic Server is a Java application server used to host enterprise applications and services. An unauthenticated attacker on the network can exploit a flaw in the core component via T3 or IIOP protocols to gain complete control of the server, potentially compromising all data and applications running on it and disrupting business operations.

Technical details

This vulnerability is an unauthenticated remote code execution flaw in the Core component of Oracle WebLogic Server, exploitable via the T3 (Proprietary Oracle) or IIOP (CORBA) network protocols. No authentication or user interaction is required; a network-accessible attacker can directly trigger the vulnerability. Successful exploitation results in complete takeover of the WebLogic Server instance, granting an attacker the ability to execute arbitrary code, steal sensitive data, modify applications, and disrupt service availability. The affected versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Patch availability from Oracle has not been confirmed in the provided advisory.

Affected products

  • Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0

Timeline

  • 2026-09-15: disclosed: CVE-2026-70756 published

References

Related threats