SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60698 2026-08-18

CVE-2026-60698: Unauthenticated IIOP Takeover of Oracle WebLogic Server

"Oracle disclosed a critical (CVSS 9.8) flaw in the Core component of Oracle WebLogic Server that lets an unauthenticated remote attacker fully compromise the server over IIOP."

Oracle disclosed a critical (CVSS 9.8) flaw in the Core component of Oracle WebLogic Server that lets an unauthenticated remote attacker fully compromise the server over IIOP.

What Is It

CVE-2026-60698 is a vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, in the Core component. Oracle describes it as an easily exploitable vulnerability that allows an unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks result in takeover of the WebLogic Server instance.

The CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability. The record was published 2026-08-18 by Oracle ([email protected]) and currently carries NVD status "Received."

Why It Matters

Full takeover with no credentials and no user interaction is the worst-case profile for an application server. WebLogic typically sits behind business-critical Fusion Middleware deployments, so a successful attack hands over whatever data and downstream connectivity that server holds. The combination Oracle states explicitly, "easily exploitable," unauthenticated, network-reachable, means exposure is determined largely by whether the IIOP listener is reachable from an attacker's position.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the source material provided here.

What's Vulnerable

Oracle lists the following supported versions of Oracle WebLogic Server as affected:

The attack path named in the advisory is IIOP network access to the affected component (Core).

Patch Status

The single reference supplied is Oracle's Critical Security Patch Update advisory for August 2026, which is the authoritative source for fixed versions and patch availability. No separate KEV remediation deadline or required action was included in the supplied data.

Sources