ZeroHour

CVE-2026-70756

large

Unauthenticated Remote Takeover of Oracle WebLogic Server via T3/IIOP

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-70756 is a critical (CVSS 9.8) vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. An unauthenticated attacker with network access to the T3 or IIOP protocols can exploit it easily and achieve a complete compromise of the WebLogic Server, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, which are widely deployed in enterprise and government environments that expose administrative or cluster protocols to internal or external networks. There is no known public proof-of-concept and the flaw is not on the CISA Known Exploited Vulnerabilities list, but unauthenticated WebLogic protocol flaws of this type are frequently weaponized once details circulate. Defenders should treat internet- or DMZ-facing WebLogic instances as the highest-priority patch targets.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-70756 to all affected WebLogic installations (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) as a top priority. Until patched, block or restrict T3 and IIOP traffic (including ports such as 7001/7002 and IIOP listeners) at perimeter firewalls so only trusted admin/cluster hosts can reach them. Audit logs for unauthenticated T3/IIOP connection attempts and unexpected process or deployment activity on WebLogic servers, and verify whether any instances are internet-facing.

Affected
Oracle WebLogic Server (Oracle Fusion Middleware, Core component)12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Estimated exposure
large≈tens of thousands (roughly 20,000–50,000) internet-reachable WebLogic endpoints, plus a larger internal enterprise install base — Public scan engines (Shodan/Censys) have historically shown tens of thousands of internet-exposed WebLogic admin/T3 ports, and WebLogic is a staple enterprise middleware product typically deployed in large private datacenters.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.