What is CVE-2026-60672?
A critical vulnerability in the Core component of Oracle WebLogic Server allows an unauthenticated attacker with network access via T3 and IIOP protocols to easily compromise the system. Affected versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 must be patched immediately using Oracle's official updates.
Azərbaycanca: Oracle WebLogic Server-in Core komponentində aşkar edilmiş kritik boşluq autentifikasiya olunmamış təcavüzkara şəbəkə üzərindən T3 və IIOP protokolları vasitəsilə asanlıqla sistemə müdaxilə etməyə imkan verir. 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 və 15.1.1.0.0 versiyaları təsirə məruz qalır, dərhal Oracle-ın rəsmi yamaqları tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
Which versions of Oracle WebLogic Server are affected by CVE-2026-60672?
This vulnerability affects Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
How can an attacker exploit the CVE-2026-60672 vulnerability to compromise the system?
An unauthenticated attacker can easily compromise the system via the T3 and IIOP protocols over the network.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.