SYS::ONLINE
Wasteland.
Briefs1410
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60208 2026-07-21

CVE-2026-60208: Critical Unauthenticated RCE-Class Flaw in Oracle WebLogic Server

"A critical, easily exploitable vulnerability in Oracle WebLogic Server lets an unauthenticated network attacker compromise the server and read or alter all accessible data, carrying a CVSS 3.1 base score of 9.1."

A critical, easily exploitable vulnerability in Oracle WebLogic Server lets an unauthenticated network attacker compromise the server and read or alter all accessible data, carrying a CVSS 3.1 base score of 9.1.

What Is It

CVE-2026-60208 is a vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the server. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) reflects network attack vector, low complexity, and no privileges or user interaction required.

Why It Matters

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all WebLogic Server accessible data, as well as unauthorized read access up to complete access of all WebLogic Server accessible data. Because the attack requires no authentication and no user interaction over HTTP, the barrier to exploitation is low. The vulnerability scores 9.1 CRITICAL, with HIGH confidentiality and HIGH integrity impact (availability impact is rated NONE).

What's Vulnerable

Oracle WebLogic Server is affected across the following supported versions:

Patch Status

The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update Advisory (July 2026) and apply the corresponding fixes for affected WebLogic Server versions. No CISA KEV entry confirming active exploitation was supplied with this record.

Sources