Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability
Oracle has released 943 new security patches in its August 2026 Critical Security Patch Update, addressing flaws across its enterprise software portfolio.
The release includes several critical Oracle WebLogic Server vulnerabilities that could allow an unauthenticated remote attacker to take complete control of affected servers.
The update, published on August 18, covers Oracle Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, Communications products, and many other platforms.
Oracle strongly urged customers to apply the updates without delay, noting that attackers have previously exploited known flaws when organizations failed to patch them.
Oracle Releases 943 Security Patches
The most urgent fixes affect Oracle WebLogic Server, a widely deployed application server used by large organizations to host business-critical applications. Oracle fixed multiple remotely exploitable flaws with a CVSS severity score of 9.8 out of 10.
The affected flaws include CVE-2026-60698, CVE-2026-60672, and CVE-2026-60696, which impact the WebLogic Server Core component through the IIOP and T3 protocols.
These vulnerabilities are particularly dangerous because they can be exploited remotely without authentication and can affect confidentiality, integrity, and availability.
In practical terms, a successful attacker may be able to execute unauthorized actions, steal sensitive data, change application content, disrupt business services, or potentially gain full control of a vulnerable WebLogic environment.
Critical WebLogic vulnerabilities
| CVE | Affected Component | Protocol | CVSS 3.1 |
|---|---|---|---|
| CVE-2026-60698 | WebLogic Server Core | IIOP | 9.8 |
| CVE-2026-60672 | WebLogic Server Core | T3, IIOP | 9.8 |
| CVE-2026-60696 | WebLogic Server Core | T3, IIOP | 9.8 |
| CVE-2026-60977 | WebLogic Server WLS Core Components | RMI | 9.8 |
| CVE-2026-60702 | WebLogic Server Core | T3, IIOP | 9.9 |
CVE-2026-60698 affects WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. CVE-2026-60672 and CVE-2026-60696 affect the same versions.
Oracle also patched CVE-2026-60977, a critical RMI-related flaw affecting WebLogic Server releases 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. Each of these issues received a CVSS score of 9.8.
Another high-severity WebLogic issue, CVE-2026-60702, has a CVSS score of 9.9. It affects the WebLogic Core component and uses T3 or IIOP as the attack vector. Unlike the 9.8-rated flaws, this vulnerability requires a low-privileged authenticated user.
However, successful exploitation could still have a broad impact across the affected system, including a high level of compromise of data confidentiality, integrity, and availability.
Overall, Oracle Fusion Middleware received 262 new security patches, with 182 vulnerabilities identified as remotely exploitable without authentication.
This makes Fusion Middleware one of the most significant product groups in the August update. The advisory also includes a maximum-severity CVSS 10.0 flaw, CVE-2026-61241, in Oracle Internet Directory’s LDAP Server component.
Oracle also addressed serious vulnerabilities in other products. Oracle Commerce received 66 patches, including several remotely exploitable vulnerabilities with a CVSS score of 9.8.
Oracle E-Business Suite received 120 patches, while Oracle Database Products received 17 security fixes. Several high-impact issues were also patched in Oracle Essbase, Enterprise Manager, Financial Services applications, and Oracle Hospitality Simphony.
Organizations should prioritize internet-facing WebLogic servers, especially systems with T3, IIOP, or RMI services exposed to untrusted networks.
Security teams should identify affected versions, obtain the relevant patches through Oracle’s Patch Availability Documents, test updates in non-production environments, and deploy them as quickly as operationally possible.
Where immediate patching is not possible, administrators should restrict access to exposed protocols and limit unnecessary network reachability. However, Oracle cautions that such workarounds do not fix the underlying vulnerabilities.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Oracle Releases 943 Security Patches Including Critical WebLogic Full Takeover Vulnerability appeared first on Cyber Security News.
