Remote Code Execution Vulnerability in Oracle WebLogic Server by Oracle
CVE-2026-60312

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60312?

A vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware allows unauthenticated attackers with network access to exploit the system via T3 and IIOP protocols. If successfully exploited, an attacker could take control of the server, severely compromising confidentiality, integrity, and availability of the applications running on it. The affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. It is crucial for users to update and patch their systems as a precaution.

Affected Version(s)

Oracle WebLogic Server 12.2.1.4.0

Oracle WebLogic Server 14.1.1.0.0

Oracle WebLogic Server 14.1.2.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.