DIRAS TAKE
Urgent: this allows unauthenticated remote compromise via T3/IIOP, so immediately reduce exposure of WebLogic management interfaces and apply vendor guidance as soon as patches are released.
What is CVE-2026-70756?
An unauthenticated remote attacker can fully compromise Oracle WebLogic Server over network-accessible management protocols; this is tracked as CVE-2026-70756. Affected releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The flaw requires only network access to T3 or IIOP services and no valid credentials or user interaction. Successful exploitation can lead to complete takeover of the WebLogic Server, impacting confidentiality, integrity, and availability of hosted applications. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Oracle Oracle WebLogic Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 12.x | 12.2.1.4.0 | |
| 14.x | 14.1.1.0.0 | |
| 14.x | 14.1.2.0.0 | |
| 15.x | 15.1.1.0.0 |
Is CVE-2026-70756 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-70756
- Restrict or block external access to T3 and IIOP ports at network perimeter and firewalls
- Disable or restrict WebLogic administration interfaces to trusted networks where possible
- Monitor WebLogic logs and network traffic for unexpected connections on T3/IIOP and signs of unauthorized activity
- Follow Oracle advisories and apply vendor patches or configuration fixes when Oracle publishes them
Frequently asked questions
Is CVE-2026-70756 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Oracle WebLogic Server versions are affected by CVE-2026-70756?
Affected releases listed are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Is there a patch for CVE-2026-70756?
Oracle has not listed fixed versions for this issue; follow Oracle advisories for patch availability and apply them when released.
Does CVE-2026-70756 require authentication?
No, exploitation does not require authentication; an attacker only needs network access to T3 or IIOP services.
References
- nvd.nist.gov/vuln/detail/CVE-2026-70756
- cve.org/CVERecord?id=CVE-2026-70756
- oracle.com/security-alerts/cspusep2026.html
- All Oracle CVEs on CVE Radar
- CVEs published in September 2026