Summary
CVE-2026-60205 is a critical unauthenticated remote code execution vulnerability affecting the Core component of Oracle WebLogic Server, disclosed as part of Oracle’s July 2026 Critical Patch Update (CPU) released on July 21, 2026. With a CVSS v3.1 base score of 9.8 (Critical), the flaw allows a remote, unauthenticated attacker with network access via TCP to fully take over an affected Oracle WebLogic Server instance — resulting in complete compromise of confidentiality, integrity, and availability.
Technical details
- Root cause: An easily exploitable flaw in the Core component of Oracle WebLogic Server, reachable over a standard TCP network connection.
- Trigger conditions: No authentication and no user interaction are required; any network-accessible WebLogic Server instance running an affected version is exposed.
- Attack vector: Network (TCP); attack complexity is low, no privileges are required, and no victim interaction is needed.
- Impact: Complete compromise of confidentiality, integrity, and availability — Oracle describes successful exploitation as enabling full "takeover of Oracle WebLogic Server."
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.2.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update for Oracle WebLogic Server. Customers running versions 12.2.1.4.0 or 14.1.2.0.0 should apply the CPU patch without delay.
- If immediate patching is not feasible: Restrict inbound network access to WebLogic Server ports (typically 7001/7002) and any exposed administrative interfaces using firewall rules or network segmentation to limit exposure to trusted sources only.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

