
Software
Oracle just patched five separate 9.8 bugs that hand WebLogic to an anonymous attacker. patch all of them
CVE-2026-60198 and four siblings let an unauthenticated attacker take over Oracle WebLogic Server over T3, IIOP, HTTP or SOAP. Five critical holes, one July patch — here's what to do.
Priya Nair · 2d ago · 9 min