Summary
CVE-2026-60292 is a critical vulnerability in Oracle WebLogic Server that allows an unauthenticated remote attacker to fully compromise an affected system over HTTP, with no user interaction required. The flaw was disclosed as part of Oracle’s July 2026 Critical Patch Update and carries a CVSS v3.1 base score of 9.8, reflecting complete confidentiality, integrity, and availability impact. Oracle describes successful exploitation as enabling "takeover of Oracle WebLogic Server."
Technical details
- Root cause: The vulnerability resides in Oracle WebLogic Server’s HTTP interface. The CVE record describes it as an "easily exploitable vulnerability" that grants a remote unauthenticated attacker the ability to compromise the server via network-accessible HTTP endpoints.
- Trigger conditions: A remote attacker sends crafted HTTP requests to an exposed WebLogic Server instance; no credentials or victim interaction are required.
- Attack vector: Network (HTTP); Attack Complexity: Low; Privileges Required: None; User Interaction: None.
- Impact: High across all three impact dimensions — confidentiality, integrity, and availability — consistent with full server takeover.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
Severity
CVSS v3.1 base score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle July 2026 Critical Patch Update (CPU) patches for Oracle WebLogic Server, available via the Oracle security advisory linked in the references below.
- If immediate patching is not feasible: Restrict network-level access to WebLogic Server HTTP ports to trusted hosts only; isolate WebLogic instances from untrusted network segments; and monitor for anomalous HTTP activity targeting WebLogic administrative and application endpoints.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

