Oracle patched 943 vulnerabilities, including critical remotely exploitable flaws.
The post Oracle Patches 943 Vulnerabilities, Including Critical WebLogic Bugs appeared first on eSecurity Planet.
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More
Oracle’s August 2026 patch release addresses 943 vulnerabilities across its enterprise software portfolio.
Several of the critical WebLogic Server flaws could allow remote attackers to compromise vulnerable systems without authentication.
Key takeaways of the Oracle August 2026 security updateOracle’s August update patches vulnerabilities across its enterprise portfolio, including Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, PeopleSoft, and other platforms.
Several of the most critical fixes affect Oracle WebLogic Server, where remotely exploitable vulnerabilities could compromise business critical applications and sensitive data.
CVE-2026-60698CVE-2026-60698 is a critical WebLogic Server Core vulnerability with a CVSS score of 9.8 that can be remotely exploited without authentication via IIOP.
CVE-2026-60672CVE-2026-60672 is a CVSS 9.8 WebLogic Server Core flaw reachable through T3 and IIOP.
An unauthenticated remote attacker could exploit the vulnerability to compromise affected WebLogic environments.
CVE-2026-60696CVE-2026-60696 also carries a CVSS score of 9.8 and affects WebLogic Server Core through T3 and IIOP.
The vulnerability requires no authentication and could allow a remote attacker to compromise data and services on an affected server.
CVE-2026-60977Oracle also addressed CVE-2026-60977, a CVSS 9.8 vulnerability affecting WebLogic Server WLS Core Components.
The flaw can also be remotely exploited via RMI, providing another attack path when the affected service is exposed to untrusted networks.
CVE-2026-60702The most severe WebLogic vulnerability addressed in the release, CVE-2026-60702, carries a CVSS score of 9.9 and affects WebLogic Server Core through T3 and IIOP.
Although exploitation requires low-privileged authentication, an attacker with existing access could leverage the flaw to further compromise the affected environment.
Fusion Middleware receives 262 security fixesThe August update extends beyond WebLogic, with Oracle Fusion Middleware receiving 262 security patches, including 182 that address vulnerabilities remotely exploitable without authentication.
CVE-2026-61241Among the most critical flaws is CVE-2026-61241, a CVSS 10.0 vulnerability in the LDAP Server component of Oracle Internet Directory.
An unauthenticated attacker with network access to the LDAP service can remotely exploit affected systems without valid credentials.
Oracle did not report any active exploitation of these vulnerabilities at the time of publication.
How to reduce Oracle security risksOrganizations should prioritize remediation based on system exposure, vulnerability severity, and the criticality of affected workloads.
Together, these measures can reduce exposure to WebLogic attacks while strengthening resilience against exploitation and subsequent compromise.
Bottom lineOracle’s August 2026 release is a reminder to treat large quarterly patch cycles as a risk prioritization exercise rather than a simple patch counting task.
The concentration of unauthenticated, remotely exploitable flaws in WebLogic and Fusion Middleware makes external exposure, protocol reachability, and asset criticality key factors for remediation sequencing.
Security teams should also verify that vulnerable middleware is fully inventoried, compensating controls are enforceable where patching is delayed, and detection coverage is sufficient to identify exploitation attempts.
Zero Trust solutions can further help reduce exposure by continuously validating access and limiting blast radius.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | 1434 уязвимости в продуктах Oracle, 82 из которых затрагивают Java, MySQL, VirtualBox и Solaris | 0 | 14.15 | 25-07-2026 |
| 2 | 1434 уязвимости в продуктах Oracle, 82 из которых затрагивают Java, MySQL, VirtualBox и Solaris | 0 | 10.06 | 26-07-2026 |
| 3 | Apple Patches Critical iPhone Flaws: Attackers Could Run Malicious Code | 0 | 6.23 | 20-08-2026 |
| 4 | GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability | 0 | 6.97 | 19-08-2026 |
| 5 | У Oracle случился свой собственный «баг-апокалипсис» | 0 | 18.17 | 24-07-2026 |
| 6 | Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices | 0 | 9.67 | 28-07-2026 |
| 7 | More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity | 0 | 10.32 | 28-07-2026 |
| 8 | Nissan пострадал от уязвимости в ERP-системе сбежавшей из России Oracle | -2 | 6 | 02-07-2026 |
| 9 | Nissan пострадал от уязвимости в ERP-системе сбежавшей из России Oracle | -2 | 6 | 02-07-2026 |
| 10 | Nissan пострадал от уязвимости в ERP-системе сбежавшей из России Oracle | -3 | 7 | 02-07-2026 |