SYS::ONLINE
Wasteland.
Briefs1402
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60199 2026-07-21

CVE-2026-60199: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60199, a CVSS 9.8 vulnerability in Oracle WebLogic Server that lets an unauthenticated attacker fully compromise the server over the network via HTTP."

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60199, a CVSS 9.8 vulnerability in Oracle WebLogic Server that lets an unauthenticated attacker fully compromise the server over the network via HTTP.

What Is It

CVE-2026-60199 is a critical vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. According to Oracle's advisory, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise the server. A successful attack can result in complete takeover of Oracle WebLogic Server.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-reachable, low-complexity, requires no privileges and no user interaction, and delivers high impact to confidentiality, integrity, and availability.

Why It Matters

WebLogic Server is widely deployed as an enterprise application and middleware platform, often exposed to internal and external networks. Because this flaw requires no authentication and no user interaction, an attacker who can reach the HTTP interface can achieve full server takeover. The combined high confidentiality, integrity, and availability impact means a successful exploit compromises the entire host application environment.

What's Vulnerable

The following supported versions of Oracle WebLogic Server are affected:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes documented in the Oracle Critical Patch Update Advisory for July 2026 without delay, given the flaw's critical severity and low exploitation barrier.

The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the wild at this time.

Sources