Summary
CVE-2026-60204 is a critical, unauthenticated remote code execution vulnerability affecting the Core component of Oracle WebLogic Server within Oracle Fusion Middleware. Published on 2026-07-21 as part of Oracle’s July 2026 Critical Patch Update, the flaw allows a remote, unauthenticated attacker to achieve complete takeover of an affected WebLogic Server instance with no user interaction required. With a CVSS v3.1 base score of 9.8 (Critical), this vulnerability represents one of the most severe issues addressed in the July 2026 CPU.
Technical details
- Root cause: A vulnerability in the Core component of Oracle WebLogic Server accessible over the T3 and IIOP protocols, enabling unauthenticated remote exploitation.
- Trigger conditions: The vulnerability is exploitable by any attacker with network access to the target on the T3 or IIOP listener port (typically TCP 7001/7002). No valid credentials and no prior access are required.
- Attack vector: Network-reachable (AV:N), low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Successful exploitation results in complete compromise of the Oracle WebLogic Server: full loss of confidentiality, integrity, and availability (C:H/I:H/A:H), consistent with server takeover.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patches provided in Oracle’s July 2026 Critical Patch Update (CPUJul2026) for the affected WebLogic Server versions. Oracle’s advisory is the authoritative source for the specific patch identifiers applicable to each release.
- Network mitigation (if patching is not immediately possible): Restrict network access to the T3 and IIOP protocol ports (default TCP 7001/7002) from untrusted networks and the internet using firewall rules or WebLogic Server’s built-in connection filter. Disabling T3 and IIOP entirely on internet-facing nodes is strongly recommended where application requirements permit.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

