Summary
CVE-2026-60294 is a critical, unauthenticated remote code execution vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Disclosed on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update, the flaw is exploitable over the network via the SOAP protocol with no credentials or user interaction required, and carries a CVSS v3.1 base score of 9.8 (Critical). Successful exploitation grants an attacker complete control over the affected server, including full compromise of confidentiality, integrity, and availability.
Technical details
- Root cause: An easily exploitable vulnerability exists in the Core component of Oracle WebLogic Server within Oracle Fusion Middleware; no CWE identifier has been assigned at the time of publication.
- Trigger conditions: No authentication and no user interaction are required; attack complexity is low, meaning no special conditions or race conditions must be met.
- Attack vector: Network-accessible via the SOAP protocol, allowing remote exploitation from the internet without prior access to the target environment.
- Impact: Successful exploitation results in complete compromise of the target server — full unauthorized access to all data (confidentiality), the ability to modify or corrupt data and system state (integrity), and the potential to render the service unavailable (availability), consistent with Remote Code Execution or equivalent critical impact.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Apply the patches provided in Oracle’s July 2026 Critical Patch Update. Consult the Oracle CPU advisory at https://www.oracle.com/security-alerts/cpujul2026.html for the specific patch bundles applicable to each affected version.
- Network mitigation: If immediate patching is not feasible, restrict network access to WebLogic Server SOAP endpoints (typically on ports 7001/7002) at the perimeter to trusted sources only. This does not eliminate the vulnerability but reduces the attack surface for internet-exposed instances.
- Prioritization: Oracle WebLogic Server instances directly accessible from the internet should be treated as the highest remediation priority given the unauthenticated, network-exploitable nature of this flaw.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

