Multiple critical vulnerabilities have been identified in Oracle WebLogic Server and Oracle Internet Directory as part of Oracle’s August 2026 Critical Security Patch Update. The flaws include unauthenticated remote compromise through IIOP, T3, RMI, and LDAP, with CVSS scores reaching 10.0. Successful exploitation could allow attackers to take complete control of affected application or directory servers, compromise sensitive information, modify data, and disrupt critical services.
• CVE-2026-61241 with a CVSS score of 10.0 – A critical vulnerability in Oracle Internet Directory OID LDAP Server allows an unauthenticated remote attacker to compromise the directory through LDAP and potentially achieve complete takeover.[/subscribe_to_unlock_form]
Multiple critical vulnerabilities have been identified in Oracle WebLogic Server and Oracle Internet Directory as part of Oracle’s August 2026 Critical Security Patch Update. The flaws include unauthenticated remote compromise through IIOP, T3, RMI, and LDAP, with CVSS scores reaching 10.0. Successful exploitation could allow attackers to take complete control of affected application or directory servers, compromise sensitive information, modify data, and disrupt critical services.
• CVE-2026-61241 with a CVSS score of 10.0 – A critical vulnerability in Oracle Internet Directory OID LDAP Server allows an unauthenticated remote attacker to compromise the directory through LDAP and potentially achieve complete takeover.[emaillocker id="1283"]
• CVE-2026-60977 with a CVSS score of 9.8 – A critical vulnerability in WebLogic Server WLS Core Components can be exploited remotely without authentication through RMI, potentially resulting in complete server compromise.
• CVE-2026-60698 with a CVSS score of 9.8 – A critical WebLogic Server Core vulnerability exploitable through IIOP allows an unauthenticated remote attacker to compromise the affected server and potentially achieve full takeover.
• CVE-2026-60702 with a CVSS score of 9.9 – A critical WebLogic Server Core vulnerability reachable through T3 and IIOP can be exploited by a low-privileged remote attacker and may result in complete compromise of the WebLogic environment.
• CVE-2026-60672 with a CVSS score of 9.8 – A critical WebLogic Server Core vulnerability affecting T3 and IIOP allows an unauthenticated remote attacker to compromise the server, impacting confidentiality, integrity, and availability.
• CVE-2026-60696 with a CVSS score of 9.8 – A critical WebLogic Server Core vulnerability affecting T3 and IIOP can be remotely exploited without authentication and may result in compromise of sensitive data and services.
These vulnerabilities affect Oracle WebLogic Server releases including 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and, where applicable, 15.1.1.0.0. CVE-2026-61241 affects Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. Organizations should prioritize remediation of internet-facing or otherwise untrusted-network-accessible WebLogic and Internet Directory deployments.
We recommend you to Upgrade Oracle WebLogic Server to 12.2.1.4.260728, 14.1.1.0.260728, 14.1.2.0.260728, or 15.1.1.0.260728, as applicable.
The following reports contain further technical details:
[/emaillocker]