CVE-2026-70757
largeUnauthenticated Takeover of Oracle WebLogic Server via T3/IIOP
A critical flaw (CVSS 9.8) in the Core component of Oracle WebLogic Server allows an unauthenticated remote attacker with network access to the T3 or IIOP protocols to fully compromise the server, resulting in complete takeover of the WebLogic instance and its hosted applications. Exploitation requires no privileges, credentials, or user interaction, and a successful attack impacts confidentiality, integrity, and availability. All currently supported releases are affected: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw is not yet in CISA's KEV catalog and no public proof-of-concept is known, but unauthenticated T3/IIOP vulnerabilities in WebLogic have historically been rapidly weaponized after disclosure, so patching should not be delayed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-70757 to every affected WebLogic installation (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) as soon as it is available. Until patched, block or tightly restrict T3 and IIOP traffic at perimeter firewalls and use WebLogic connection filters so only trusted hosts can reach those protocols. Review logs and server state for unexpected T3/IIOP connections, newly deployed applications, or unfamiliar administrative accounts.
| Oracle WebLogic Server (Oracle Fusion Middleware, Core component) | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.