Multiple vulnerabilities in Oracle Weblogic (July 23, 2026)
Multiple vulnerabilities have been discovered in Oracle Weblogic. They allow an attacker to cause data confidentiality breaches and data integrity breaches.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause data confidentiality breaches and data integrity breaches.
- Who is affected
- Deployments of Oracle Weblogic are affected.
- Urgency
- Remediation is urgent due to potential data breaches.
- Action
- Apply available patches as they are released.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Weblogic
Get an email when a new Weblogic advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0920/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-603120.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-601980.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Low exploitation riskCVE-2026-602930.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-602080.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-602010.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-602920.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Low exploitation riskCVE-2026-601990.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-602050.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
- Low exploitation riskCVE-2026-605290.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-602040.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- low[UPDATE] [low] Apache log4j: Vulnerability allows information disclosurecert-bund
- medium[UPDATE] [medium] Apache log4j: Multiple vulnerabilities allow file manipulationcert-bund
- high[NEW] [high] SAP Patch Day July 2026cert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat JBoss Enterprise Application Platform (bouncycastle): Vulnerability allows informati…cert-bund
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Oracle MySQL (July 23, 2026)cert-fr-avis
- unknownNCSC-2026-0259 [1.00] [M/H] Vulnerabilities fixed in Oracle Analyticsncsc-nl
- unknownNCSC-2026-0258 [1.00] [M/H] Vulnerabilities fixed in Oracle Financial Servicesncsc-nl
- unknownNCSC-2026-0257 [1.00] [M/H] Vulnerabilities fixed in Oracle Enterprise Managerncsc-nl
- unknownNCSC-2026-0252 [1.00] [H/H] Vulnerabilities fixed in Oracle Fusion middlewarencsc-nl
Recent advisories for Oracle Weblogic
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-60529: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Co…nvd · 2026-07-21
- highCVE-2026-60528: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Co…nvd · 2026-07-21
- highCVE-2026-60527: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Co…nvd · 2026-07-21
- criticalCVE-2026-60365: Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware …nvd · 2026-07-21
- criticalCVE-2026-60364: Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware …nvd · 2026-07-21
- highCVE-2026-60343: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Co…nvd · 2026-07-21
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31