Oracle just patched five separate 9.8 bugs that hand WebLogic to an anonymous attacker. patch all of them

CVE-2026-60198 and four siblings let an unauthenticated attacker take over Oracle WebLogic Server over T3, IIOP, HTTP or SOAP. Five critical holes,…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

Five 9.8 flaws: CVE-2026-60198/-60202/-60204 (T3/IIOP), -60199 (HTTP), -60200 (SOAP).

What you need to know

All unauthenticated — the class is CWE-306, missing authentication for a critical function.

What you need to know

Affected: WebLogic 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

What you need to know

Result: complete takeover of the WebLogic server with full data and system compromise.

What you need to know

Fix: the July 2026 Oracle Critical Patch Update. And get WebLogic's admin protocols off the internet.

Aliteq

Read the full story

Oracle just patched five separate 9.8 bugs that hand WebLogic to an anonymous attacker. patch all of them

Read the full story on Aliteq