Summary
CVE-2026-60200 is a critical vulnerability in the Core component of Oracle WebLogic Server, disclosed as part of Oracle’s July 2026 Critical Patch Update. The flaw enables unauthenticated remote attackers with network access to exploit Oracle WebLogic Server’s SOAP interface, leading to complete server takeover — full compromise of confidentiality, integrity, and availability. With a CVSS 3.1 score of 9.8 (Critical), this vulnerability requires no authentication, no user interaction, and no special conditions to trigger.
Technical details
- Root cause: Oracle classifies this as an "easily exploitable vulnerability" in the Core component of Oracle WebLogic Server; specific technical root-cause details have not been publicly disclosed at time of publication.
- Trigger conditions: An unauthenticated attacker with network access to an affected Oracle WebLogic Server instance sends crafted requests over the SOAP protocol.
- Attack vector: Network-based (AV:N), no privileges required (PR:N), no user interaction required (UI:N), low attack complexity (AC:L).
- Impact: Successful exploitation results in complete takeover of Oracle WebLogic Server, with full compromise of confidentiality (C:H), integrity (I:H), and availability (A:H).
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU) patches for Oracle WebLogic Server. Patch documentation is available through Oracle Support under advisory CPU211 (Fusion Middleware). Customers should apply the relevant CPU patches for all deployed versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0).
- If immediate patching is not possible: Restrict inbound network access to Oracle WebLogic Server’s SOAP endpoints and administrative interfaces (default ports 7001/7002) at the network perimeter via firewall rules or access control lists. Prioritize internet-facing deployments for immediate remediation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

