Summary
CVE-2026-60312 is a high-severity vulnerability in the Core component of Oracle WebLogic Server, disclosed as part of Oracle’s July 2026 Critical Patch Update. The flaw allows unauthenticated remote attackers with network access via the T3 and IIOP protocols to compromise affected WebLogic Server instances, with Oracle noting potential complete server takeover as the consequence. The vulnerability carries a CVSS v3.1 base score of 8.1 (HIGH), with maximum impact across confidentiality, integrity, and availability.
Technical details
- Attack vector: Remotely exploitable over the network; no local access or lateral movement required. The attack is delivered via Oracle WebLogic’s native T3 and IIOP protocols, which are typically exposed on port 7001 and used for Java EE application communication.
- Authentication requirement: None — exploitation requires no prior credentials or account on the target system.
- Attack complexity: High (AC:H) — certain conditions must be present for exploitation to succeed, reducing the pool of immediately vulnerable targets compared to a lower-complexity flaw. However, a subset of internet-exposed WebLogic deployments will meet these conditions.
- Impact: Successful exploitation results in complete compromise of the Oracle WebLogic Server instance, with high impact to confidentiality, integrity, and availability, and potential full server takeover.
- User interaction: None required on the part of any authenticated user.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 8.1 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU) patches for all affected WebLogic Server versions (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) as directed in Oracle’s official advisory at https://www.oracle.com/security-alerts/cpujul2026.html.
- Network-level mitigation (if patching is not immediately feasible): Restrict external network access to the T3 and IIOP protocol ports (default: 7001, 7002) to trusted internal networks only, using firewall rules or network segmentation. Blocking unauthenticated external access to these protocols removes the primary attack surface identified in this CVE.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

