SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60971 2026-08-18

Oracle WebCenter Enterprise Capture Hit With 9.8 Pre-Auth Takeover Bug (CVE-2026-60971)

"Oracle's July 2026 Critical Patch Update fixes CVE-2026-60971, a CVSS 9.8 flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker take over the product over the network via T3 or IIOP."

Oracle's July 2026 Critical Patch Update fixes CVE-2026-60971, a CVSS 9.8 flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker take over the product over the network via T3 or IIOP.

What Is It

CVE-2026-60971 is a critical vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. Oracle describes it as "easily exploitable," allowing an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the product. Successful exploitation results in full takeover of Oracle WebCenter Enterprise Capture.

The CVSS 3.1 base score is 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The exploitability subscore is a maximum 3.9, and the impact subscore is 5.9.

Why It Matters

Every factor that makes a bug easy to exploit is present here: network attack vector, low attack complexity, no privileges required, and no user interaction. There is no authentication barrier between an attacker who can reach the T3 or IIOP listener and complete compromise of confidentiality, integrity, and availability.

T3 and IIOP are WebLogic-family remoting protocols that have historically been a favored path into Fusion Middleware deployments. Any Capture instance with those listeners reachable from an untrusted network should be treated as exposed.

Note: no source reviewed for this brief confirms active exploitation of CVE-2026-60971 in the wild. Defenders tracking exploitation status should check the CISA Known Exploited Vulnerabilities catalog directly, as its contents change on a rolling basis.

What's Vulnerable

No CPE match data was published in the NVD record at the time of writing, and the CVE remains in "Received" status; meaning NVD analysis is not yet complete. The CVSS data above is Oracle-supplied, as Oracle is the assigning CNA.

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Oracle ships CPUs on a fixed quarterly cadence, January, April, July, and October, so the July release is the current bundle for this fix, and the next scheduled update lands in October 2026. Administrators running the affected 12.2.1.4.0 and 14.1.2.0.0 versions should apply the CPU fixes. Given the pre-authentication nature of the flaw, restricting network access to T3 and IIOP listeners is a sound interim control until patching is complete.

Sources