ZeroHour

CVE-2026-70757

large

Unauthenticated Takeover of Oracle WebLogic Server via T3/IIOP

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical flaw (CVSS 9.8) in the Core component of Oracle WebLogic Server allows an unauthenticated remote attacker with network access to the T3 or IIOP protocols to fully compromise the server, resulting in complete takeover of the WebLogic instance and its hosted applications. Exploitation requires no privileges, credentials, or user interaction, and a successful attack impacts confidentiality, integrity, and availability. All currently supported releases are affected: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The flaw is not yet in CISA's KEV catalog and no public proof-of-concept is known, but unauthenticated T3/IIOP vulnerabilities in WebLogic have historically been rapidly weaponized after disclosure, so patching should not be delayed.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-70757 to every affected WebLogic installation (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) as soon as it is available. Until patched, block or tightly restrict T3 and IIOP traffic at perimeter firewalls and use WebLogic connection filters so only trusted hosts can reach those protocols. Review logs and server state for unexpected T3/IIOP connections, newly deployed applications, or unfamiliar administrative accounts.

Affected
Oracle WebLogic Server (Oracle Fusion Middleware, Core component)12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Estimated exposure
largetens of thousands of installations, with roughly 10,000–50,000 internet-exposed T3/IIOP endpoints (order-of-magnitude estimate) — Internet-wide scans (Shodan/Censys-style) have consistently shown tens of thousands of WebLogic servers with T3/IIOP listeners reachable from the internet, and WebLogic is deployed broadly across mid-size and large enterprises worldwide.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.