SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60977 2026-08-18

Oracle WebLogic Server RMI Flaw CVE-2026-60977 Allows Unauthenticated Takeover

"Oracle disclosed CVE-2026-60977, a critical (CVSS 9.8) vulnerability in Oracle WebLogic Server's WLS Core Components that lets an unauthenticated remote attacker fully compromise the server over RMI."

Oracle disclosed CVE-2026-60977, a critical (CVSS 9.8) vulnerability in Oracle WebLogic Server's WLS Core Components that lets an unauthenticated remote attacker fully compromise the server over RMI.

What Is It

CVE-2026-60977 is a vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, in the WLS Core Components component. Per the CVE record's description, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Successful attacks can result in takeover of the server.

Oracle, acting as the CNA for this CVE, assigns a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. This is the CNA-supplied assessment; NVD has not yet published its own analysis of the record.

Why It Matters

The combination of no authentication, low complexity, and full takeover impact puts this at the top end of the severity scale. The exploitability sub-score is the maximum 3.9, with an impact sub-score of 5.9. Any WebLogic instance exposing RMI to an untrusted network is reachable by an attacker with no credentials and no user interaction, and the outcome is compromise of the entire server rather than a partial data or availability impact.

The CVE was published 2026-08-18 and is currently in NVD Received status, meaning NVD enrichment (including CPE assignment and independent CVSS analysis) is not yet complete. The source identifier is Oracle's own security alert address, [email protected]. Scores and affected-version data below should be read as vendor-supplied and may shift once NVD completes enrichment.

No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no KEV-mandated remediation deadline in the available source material.

What's Vulnerable

Oracle Corporation; Oracle WebLogic Server. Supported versions listed as affected:

No affected CPE entries were present in the NVD record at time of writing.

Patch Status

The sole reference supplied is Oracle's Critical Patch Update advisory for August 2026 (cpuaug2026.html). That page is the quarterly CPU landing document covering hundreds of fixes across Oracle's product lines rather than a CVE-specific advisory, so the WebLogic Server entry for CVE-2026-60977 has to be located within the Fusion Middleware risk matrix on that page. Consult it for the applicable patch for your version. No specific fixed version numbers, workarounds, or required-action deadlines were included in the supplied source material.

Sources