Summary
CVE-2026-60198 is a critical-severity vulnerability in Oracle WebLogic Server that allows unauthenticated remote attackers to fully compromise affected systems via network access over the T3 and IIOP protocols. Disclosed as part of Oracle’s July 2026 Critical Patch Update, the vulnerability carries a CVSS v3.1 base score of 9.8 and affects four actively maintained WebLogic Server versions spanning the 12.x and 14.x–15.x release lines.
Technical details
- Attack vector: Exploitation occurs over the network via Oracle’s T3 and IIOP protocols, which operate on WebLogic’s default ports (7001/7002) — the same ports used for general HTTP/HTTPS traffic, making affected instances directly reachable from the internet
- Trigger conditions: No authentication is required, no user interaction is needed, and attack complexity is low — the official CVE record explicitly classifies this as an "easily exploitable" vulnerability
- Impact: Successful exploitation results in complete takeover of the Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU), which addresses this vulnerability across all affected versions. Patches are available via Oracle Support
- Network mitigation (if patching cannot be applied immediately): Restrict network access to WebLogic T3 and IIOP ports (7001/7002) from untrusted or internet-facing networks. Oracle’s standard guidance for T3-based vulnerabilities recommends applying T3 connection filters or disabling the T3 protocol entirely where it is not required for operations
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

