Summary
CVE-2026-60201 is a critical, unauthenticated remote code execution vulnerability in the Core component of Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Published on July 21, 2026 as part of the Oracle July 2026 Critical Patch Update, successful exploitation allows a remote, unauthenticated attacker to fully take over the affected server. The vulnerability carries a CVSS 3.1 base score of 8.1 (HIGH).
Technical details
- Component: Core component of Oracle WebLogic Server (part of Oracle Fusion Middleware)
- Attack vector: Exploitable remotely over the network via Oracle’s proprietary T3 and IIOP protocols, which are enabled by default on WebLogic instances (typically accessible on ports 7001/7002)
- Authentication: No authentication or user interaction required to trigger exploitation
- Attack complexity: High — specific conditions must be met for successful exploitation, but this does not reduce the urgency of patching, as affected configurations exist in production deployments
- Impact: Complete system compromise — successful exploitation results in full takeover of the Oracle WebLogic Server host, with Confidentiality, Integrity, and Availability all rated HIGH
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector string:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Apply the patches provided in the Oracle July 2026 Critical Patch Update for all affected WebLogic Server versions. Oracle recommends applying CPU patches without delay.
- Network-level mitigation: If immediate patching is not possible, restrict or block access to the T3 and IIOP protocols at the network perimeter (firewall rules on ports 7001/7002 and associated T3/IIOP listener ports) to limit the attack surface to trusted sources only.
- Review exposure: Audit all internet-facing WebLogic instances to confirm protocol exposure and ensure any externally reachable listeners are either patched or isolated behind access controls.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

