Oracle WebLogic flaws enable RCE across versions
Oracle patched 13 vulnerabilities in WebLogic Server versions 12.2.1.4.0 through 15.1.1.0.0, including flaws allowing remote code execution, data breaches, and denial of service.
CERT-FR published an advisory detailing multiple vulnerabilities discovered in Oracle WebLogic Server affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerabilities enable attackers to execute arbitrary code remotely, cause denial of service conditions, and compromise data confidentiality and integrity.
Oracle addressed these issues in their June 2026 Critical Patch Update, releasing fixes for 13 CVEs. The affected WebLogic Server versions are widely deployed in enterprise environments for Java application hosting and middleware services. Organizations running these versions should prioritize patching to mitigate the risk of exploitation.
The advisory references Oracle's security bulletin for detailed remediation guidance. No active exploitation or proof-of-concept code is mentioned in the CERT-FR notice, though the severity of remote code execution capabilities warrants prompt attention from affected organizations.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0769
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free