# CERT-FR flags Oracle WebLogic RCE flaws

Published: 2026-09-16 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/43b798f8-e838-55ac-a591-81896efcce2f/cert-fr-flags-oracle-weblogic-rce-flaws

> CERT-FR advisory lists multiple vulnerabilities in Oracle WebLogic Server allowing remote code execution; patches available via Oracle's September 2026 CPU.

CERT-FR published an advisory summarizing multiple vulnerabilities affecting Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerabilities, tracked under five CVE identifiers, allow an attacker to achieve remote arbitrary code execution. No further technical detail on exploitation vectors, exploitability without authentication, or in-the-wild exploitation is provided in this advisory.

Oracle addressed these issues as part of its Critical Patch Update cspusep2026, released 15 September 2026. Defenders running any of the affected WebLogic versions should consult the Oracle security bulletin and apply the corresponding patches. As WebLogic is a common target for opportunistic and targeted attackers seeking initial access into enterprise environments, organizations should prioritize patching internet-facing or otherwise exposed WebLogic instances and monitor for post-patch exploitation attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1186

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/43b798f8-e838-55ac-a591-81896efcce2f/cert-fr-flags-oracle-weblogic-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
