Summary
CVE-2026-60672 is a critical vulnerability in the Core component of Oracle WebLogic Server that allows an unauthenticated attacker with network access via the T3 or IIOP protocols to fully take over the affected server. The flaw impacts confidentiality, integrity, and availability, and Oracle rates it 9.8 (Critical) on the CVSS v3.1 scale.
Technical details
- Root cause: a flaw in Oracle WebLogic Server’s Core component reachable through the T3 and IIOP protocols.
- Trigger conditions: no authentication or user interaction is required; the attacker only needs network access to a listener exposing T3 or IIOP.
- Attack vector: network (remote, low attack complexity).
- Impact: complete takeover of the Oracle WebLogic Server, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle WebLogic Server 12.2.1.4.0
- Oracle WebLogic Server 14.1.1.0.0
- Oracle WebLogic Server 14.1.2.0.0
- Oracle WebLogic Server 15.1.1.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the Oracle Critical Patch Update (August 2026) that addresses CVE-2026-60672 for the affected WebLogic Server versions listed above.
- If patching cannot be performed immediately: restrict network access to the T3 and IIOP protocols/ports at the firewall so they are not reachable from untrusted networks, and disable the T3 and IIOP protocols on WebLogic channels where they are not required for legitimate application traffic.

