CERT-FR flags Oracle WebLogic RCE flaws
CERT-FR advisory lists multiple vulnerabilities in Oracle WebLogic Server allowing remote code execution; patches available via Oracle's September 2026 CPU.
CERT-FR published an advisory summarizing multiple vulnerabilities affecting Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerabilities, tracked under five CVE identifiers, allow an attacker to achieve remote arbitrary code execution. No further technical detail on exploitation vectors, exploitability without authentication, or in-the-wild exploitation is provided in this advisory.
Oracle addressed these issues as part of its Critical Patch Update cspusep2026, released 15 September 2026. Defenders running any of the affected WebLogic versions should consult the Oracle security bulletin and apply the corresponding patches. As WebLogic is a common target for opportunistic and targeted attackers seeking initial access into enterprise environments, organizations should prioritize patching internet-facing or otherwise exposed WebLogic instances and monitor for post-patch exploitation attempts.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1186
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free