SYS::ONLINE
Wasteland.
Briefs1413
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60204 2026-07-21

CVE-2026-60204: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server

"A critical, easily exploitable vulnerability in Oracle WebLogic Server lets an unauthenticated attacker fully compromise the server over the network, carrying a maximum-tier CVSS score of 9.8."

A critical, easily exploitable vulnerability in Oracle WebLogic Server lets an unauthenticated attacker fully compromise the server over the network, carrying a maximum-tier CVSS score of 9.8.

What Is It

CVE-2026-60204 is a critical vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via the T3 and IIOP protocols to compromise the server. A successful attack can result in complete takeover of the affected WebLogic Server instance.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That means network-reachable, low-complexity, requires no privileges and no user interaction, and results in high impact to confidentiality, integrity, and availability. Because exploitation needs no authentication and can be triggered remotely, any exposed WebLogic instance is at high risk of full compromise.

What's Vulnerable

The following Oracle WebLogic Server versions are listed as affected:

The vulnerability resides in the Core component and is reachable through the T3 and IIOP protocols.

Patch Status

Oracle addresses this vulnerability in its Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes for their WebLogic Server version. No CISA KEV entry confirming active exploitation was supplied with this record, so active exploitation is not confirmed in the available source material.

Sources