Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4618 articles · 179881 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-60205PATCHED
oracle · oracle weblogic server

CVE-2026-60205: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products

VendorProductVersions
oracleoracle weblogic server12.2.1.4.0, 14.1.2.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
oraclefusion middlewarecert_advisory90%

References

  • https://www.oracle.com/security-alerts/cpujul2026.html(vendor-advisory)

Related News (3 articles)

Tier B
CERT-FR18h ago
Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[NEU] [hoch] Oracle Fusion Middleware: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-60205 | Oracle WebLogic Server 12.2.1.4.0/14.1.2.0.0 Core privileges management
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.oracle.com/security-alerts/cpujul2026.html
PublishedJul 21, 2026
Last enriched1d agov2
Trending Score56
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-35273EXPKEV
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
Trending: 146
CRITICALCVE-2026-46817EXPKEV
CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Trending: 58
CRITICALCVE-2026-60198
CVE-2026-60198: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Trending: 56
CRITICALCVE-2026-61233
CVE-2026-61233: Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integratio
Trending: 56
CRITICALCVE-2026-60208
CVE-2026-60208: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Trending: 56

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: description, cweIds
Jul 21, 2026
Patch Available
Jul 23, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Added CWE-269 (Improper Access Control / Privilege Management) based on article's clarification that the vulnerability involves improper privilege management

descriptioncweIds
via VulDB
v11d ago

Initial creation