Three Critical Oracle WebLogic Vulnerabilities: T3, IIOP and the August CSPU
A protocol-focused response guide for three unauthenticated WebLogic Server Core vulnerabilities fixed through Oracle's August 2026 CSPU.

Three unauthenticated network CVEs
Oracle's August 2026 Critical Security Patch Update lists CVE-2026-60672, CVE-2026-60696 and CVE-2026-60698 in WebLogic Server Core. All three carry CVSS 3.1 scores of 9.8, require no authentication or user interaction, and can affect confidentiality, integrity and availability.
Affected releases and protocols
The affected releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. CVE-2026-60672 and CVE-2026-60696 are reachable through T3 and IIOP; CVE-2026-60698 is associated with IIOP. Inventory every admin, managed, standby and disaster-recovery node and map its listening channels.

Apply the August CSPU
Select the platform-specific August 2026 CSPU through Oracle's supported patch path. Review prerequisites, OPatch requirements, conflicts and rollback instructions. Patch rolling-cluster nodes in a documented order and rebuild container base images rather than changing only running containers.
Validate every node
Confirm OPatch inventory and startup logs, then test applications, data sources, JMS, EJB or CORBA, batch jobs and failover. Approved internal T3 or IIOP calls should continue while unapproved network paths remain blocked. Update autoscaling and disaster-recovery templates so old images cannot return.
Evidence and long-term controls
Correlate T3 or IIOP connection logs with WebLogic audit, proxy and host telemetry. Track each domain role, protocol channel, reachable network, CSPU and validation owner in the asset inventory. Completion requires consistent patch inventory, service validation and denied unapproved protocol paths.
Sources reviewed
- August 2026 Critical Security Patch UpdateOracle · Official source
- August 2026 Critical Security Patch Update — Risk MatricesOracle · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.