CVE-2026-60702Disclosure(oracle / weblogic_server)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oracle weblogic_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weblogic_server

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-19); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
weblogic_server

4 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-19: 3Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-19: 2Technical Details · 2026-08-19: 3Technical Details · 2026-08-21: 108-1908-21
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-193
Disclosure1Patch2
2026-08-211
Disclosure1
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    An Oracle WebLogic vulnerability, CVE-2026-60702 (CVSS 9.9), allows full server takeover. Oracle patched nine flaws, five critical. Update now. #OracleWebLogic #CVE202660702 #RCE #FusionMiddleware #ServerTakeover #InfoSec https://securityonline.info/oracle-weblogic-vulnerability-cve-2026-60702/

    Post summary

    The post highlights a critical Oracle WebLogic CVE (CVE-2026-60702) that allows full server takeover, notes vendor patching of multiple related flaws, and urges immediate update.

    015041121.6K
    13.0K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-60702 and other: Vulnerabilities in Oracle WebLogic Server, up to 9.9 rating ‍🔥 A recently disclosed vulnerabilities in Oracle WebLogic Server allow low-privileged or unauthenticated attacker to compromise the server. 👉 https://nt.ls/jX2A4

    Post summary

    The text announces the disclosure of CVE-2026-60702, a vulnerability in Oracle WebLogic Server that permits low-privileged or unauthenticated attackers to compromise the server, with a severity rating up to 9.9.

    04065779
    7.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    "CVE-2026-60702 carries a CVSS score of 9.9 and could allow a low-privileged attacker with existing access to further compromise WebLogic environments…CVE-2026-61241 received the maximum CVSS score of 10.0 and affects the LDAP Server component of OID" https://x.com/catnap707/status/2090617083096907855?s=20

    Post summary

    The tweet announces high‑severity CVE-2026-60702 and CVE-2026-61241, providing their CVSS scores and possible impact areas, but offers no proof of concept, exploit code, active exploitation evidence, or patch information.

    00010174
    3.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities in #Oracle products. CVE-2026-60702 (CVSS 9.9) and multiple CVEs rated 9.8 could enable remote attackers to takeover #WebLogic Server and #Identity Manager. #Patch #Patch #Patch

    Post summary

    Alert about critical Oracle WebLogic and Identity Manager vulnerabilities (CVE-2026-60702, CVSS 9.9, others 9.8) urging immediate patching.

    01000318
    7.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleweblogic_server12.2.1.4.0--
Apporacleweblogic_server14.1.1.0.0--
Apporacleweblogic_server14.1.2.0.0--
Apporacleweblogic_server15.1.1.0.0--

Explore more