What is CVE-2026-60415?
This critical vulnerability in Oracle WebLogic Server can be exploited via T3/IIOP protocols without authentication. Affected versions (12.2.1.4.0 to 15.1.1.0.0) are susceptible to network-based attacks. Apply Oracle's security patches immediately or temporarily disable unnecessary ports.
Azərbaycanca: Bu kritik zəiflik Oracle WebLogic Server-in T3/IIOP protokolları vasitəsilə istismar olunur. Təsirə məruz qalan versiyalar (12.2.1.4.0 - 15.1.1.0.0) üçün autentifikasiya olunmadan şəbəkə üzərindən hücum mümkündür. Dərhal Oracle-ın təhlükəsizlik yamalarını tətbiq edin və ya müvəqqəti olaraq lazımsız portları bağlayın.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
What immediate steps should be taken to protect against CVE-2026-60415?
Immediately apply Oracle's security patches for the affected Oracle WebLogic Server versions 12.2.1.4.0 to 15.1.1.0.0, or as a temporary measure, disable unnecessary ports.
How can CVE-2026-60415 be exploited without authentication?
The vulnerability can be exploited without authentication over the network via the T3/IIOP protocols in Oracle WebLogic Server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.