Security Issues

Three Critical Oracle WebLogic Vulnerabilities: T3, IIOP and the August CSPU

A protocol-focused response guide for three unauthenticated WebLogic Server Core vulnerabilities fixed through Oracle's August 2026 CSPU.

Three critical Oracle WebLogic vulnerabilities cover
Three critical Oracle WebLogic vulnerabilities cover

Three unauthenticated network CVEs

Oracle's August 2026 Critical Security Patch Update lists CVE-2026-60672, CVE-2026-60696 and CVE-2026-60698 in WebLogic Server Core. All three carry CVSS 3.1 scores of 9.8, require no authentication or user interaction, and can affect confidentiality, integrity and availability.

Affected releases and protocols

The affected releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. CVE-2026-60672 and CVE-2026-60696 are reachable through T3 and IIOP; CVE-2026-60698 is associated with IIOP. Inventory every admin, managed, standby and disaster-recovery node and map its listening channels.

Five steps from WebLogic version and T3 IIOP exposure to CSPU validation
Protocol reachability, patch deployment and service validation

Apply the August CSPU

Select the platform-specific August 2026 CSPU through Oracle's supported patch path. Review prerequisites, OPatch requirements, conflicts and rollback instructions. Patch rolling-cluster nodes in a documented order and rebuild container base images rather than changing only running containers.

Validate every node

Confirm OPatch inventory and startup logs, then test applications, data sources, JMS, EJB or CORBA, batch jobs and failover. Approved internal T3 or IIOP calls should continue while unapproved network paths remain blocked. Update autoscaling and disaster-recovery templates so old images cannot return.

Evidence and long-term controls

Correlate T3 or IIOP connection logs with WebLogic audit, proxy and host telemetry. Track each domain role, protocol channel, reachable network, CSPU and validation owner in the asset inventory. Completion requires consistent patch inventory, service validation and denied unapproved protocol paths.

Sources reviewed

  1. August 2026 Critical Security Patch UpdateOracle · Official source
  2. August 2026 Critical Security Patch Update — Risk MatricesOracle · Official source

SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.

READER COMMENTS

Comments

0

No comments yet.

Do not include personal information, advertising, or contact details.