THREAT OPS › Threat News › [NVD] CVE-2026-60977 (CRITICAL 9.8) — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access
[NVD] CVE-2026-60977 (CRITICAL 9.8) — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access
CVE-2026-60977 CVSS: 9.8 CRITICAL Published: 2026-08-18T21:16:50.097
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebLogic Server. Su
Indicators of compromise
- CVE-2026-60977cve
- 12.2.1.4ipv4
- 14.1.1.0ipv4
- 14.1.2.0ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60977