Summary
CVE-2026-60199 is a critical vulnerability in the Core component of Oracle WebLogic Server, disclosed on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update. The flaw allows unauthenticated attackers with network access to fully compromise affected WebLogic Server instances over HTTP, with no privileges or user interaction required, earning a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Affected component: Core component of Oracle WebLogic Server
- Attack vector: Network (HTTP) — remotely exploitable from the internet with no authentication and no user interaction required
- Exploitation complexity: Low; Oracle’s advisory describes the vulnerability as "easily exploitable"
- Impact: Full compromise of confidentiality, integrity, and availability of the affected server (CVSS C:H / I:H / A:H), consistent with complete system takeover
- Root cause: The specific technical root cause has not yet been publicly disclosed; no CWE identifier has been assigned in the CVE record
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update, which addresses this vulnerability across all four affected versions. Patches are distributed through Oracle’s Fusion Middleware patch availability documentation linked from the official CPU advisory.
- If immediate patching is not feasible: Restrict network-level access to WebLogic listener ports (typically TCP 7001 and 7002) to trusted IP ranges only. Disable or block external access to the WebLogic Administration Console and T3/IIOP endpoints at the perimeter firewall until patching can be completed.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

