# Oracle WebLogic flaws enable RCE across versions

Published: 2026-06-17 · Severity: high
Canonical: https://vorant.io/reports/6b0e87fc-ffa6-550c-9e70-32637e68713e/oracle-weblogic-flaws-enable-rce-across-versions

> Oracle patched 13 vulnerabilities in WebLogic Server versions 12.2.1.4.0 through 15.1.1.0.0, including flaws allowing remote code execution, data breaches, and denial of service.

CERT-FR published an advisory detailing multiple vulnerabilities discovered in Oracle WebLogic Server affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerabilities enable attackers to execute arbitrary code remotely, cause denial of service conditions, and compromise data confidentiality and integrity.

Oracle addressed these issues in their June 2026 Critical Patch Update, releasing fixes for 13 CVEs. The affected WebLogic Server versions are widely deployed in enterprise environments for Java application hosting and middleware services. Organizations running these versions should prioritize patching to mitigate the risk of exploitation.

The advisory references Oracle's security bulletin for detailed remediation guidance. No active exploitation or proof-of-concept code is mentioned in the CERT-FR notice, though the severity of remote code execution capabilities warrants prompt attention from affected organizations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35258, CVE-2026-35259, CVE-2026-35263, CVE-2026-35291, CVE-2026-35292, CVE-2026-35298, CVE-2026-35299, CVE-2026-35300, CVE-2026-35301, CVE-2026-35302, CVE-2026-35303, CVE-2026-35311, CVE-2026-46848

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0769

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6b0e87fc-ffa6-550c-9e70-32637e68713e/oracle-weblogic-flaws-enable-rce-across-versions.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
