Oracle Issues 943 Security Patches, Addresses Critical WebLogic Vulnerabilities

Oracle has released its August 2026 Critical Security Patch Update, delivering 943 security patches across its extensive product suite. This comprehensive update addresses vulnerabilities in key platforms, including Oracle Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, and Communications products.

Critical WebLogic Server Vulnerabilities

A significant focus of this update is on Oracle WebLogic Server, a widely utilized application server for hosting enterprise applications. The update rectifies multiple critical vulnerabilities within WebLogic Server’s Core component, particularly those associated with the IIOP and T3 protocols. Notable among these are CVE-2026-60698, CVE-2026-60672, and CVE-2026-60696, each carrying a CVSS severity score of 9.8 out of 10. These flaws are especially concerning as they can be exploited remotely without authentication, potentially allowing attackers to execute unauthorized actions, access sensitive data, alter application content, disrupt services, or gain full control over affected servers.

Another critical vulnerability, CVE-2026-60977, affects the WebLogic Server’s RMI component and also holds a CVSS score of 9.8. Additionally, CVE-2026-60702, with a CVSS score of 9.9, impacts the WebLogic Core component via the T3 or IIOP protocols. While this particular flaw requires a low-privileged authenticated user for exploitation, it can still lead to significant compromises in data confidentiality, integrity, and availability.

Broader Impact Across Oracle Products

Beyond WebLogic Server, the update addresses vulnerabilities across various Oracle products. Oracle Fusion Middleware received 262 new security patches, with 182 vulnerabilities identified as remotely exploitable without authentication. This includes a maximum-severity CVSS 10.0 flaw, CVE-2026-61241, in Oracle Internet Directory’s LDAP Server component.

Other notable updates include 66 patches for Oracle Commerce, several of which are remotely exploitable with a CVSS score of 9.8. Oracle E-Business Suite received 120 patches, while Oracle Database Products were updated with 17 security fixes. High-impact issues were also addressed in Oracle Essbase, Enterprise Manager, Financial Services applications, and Oracle Hospitality Simphony.

Organizations are strongly advised to prioritize the application of these patches, especially for internet-facing WebLogic servers with exposed T3, IIOP, or RMI services. Security teams should identify affected versions, obtain the relevant patches through Oracle’s Patch Availability Documents, test updates in non-production environments, and deploy them promptly. In cases where immediate patching isn’t feasible, administrators should restrict access to exposed protocols and limit unnecessary network reachability. However, it’s important to note that such workarounds do not resolve the underlying vulnerabilities.

Oracle’s proactive release of this extensive patch update underscores the critical importance of timely vulnerability management in safeguarding enterprise systems against potential exploits.