DIRAS TAKE
Urgent: this is a remote, unauthenticated flaw that allows full server compromise, so prioritize mitigations now because the vulnerability is easily exploitable without credentials. If you cannot immediately apply vendor guidance, restrict or block T3/IIOP exposure and increase monitoring for suspicious activity.
What is CVE-2026-70757?
Unauthenticated attackers can remotely compromise Oracle WebLogic Server and gain full control; this is tracked as CVE-2026-70757. Affected releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The flaw can be reached over the network using the T3 or IIOP protocols and does not require valid credentials, enabling confidentiality, integrity and availability impacts consistent with a critical 9.8 CVSS rating. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Oracle Oracle WebLogic Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 12.x | 12.2.1.4.0 | |
| 14.x | 14.1.1.0.0 | |
| 14.x | 14.1.2.0.0 | |
| 15.x | 15.1.1.0.0 |
Is CVE-2026-70757 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-70757
- Apply Oracle’s advisory and vendor guidance as soon as a patch is released.
- Immediately restrict or block T3 and IIOP access from untrusted networks and internet-facing interfaces.
- Improve monitoring and logging for WebLogic processes and unusual administrative activity.
- Prepare to deploy vendor patches and test updates in a controlled environment before wide rollout.
Frequently asked questions
Is CVE-2026-70757 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Oracle WebLogic Server versions are affected by CVE-2026-70757?
Oracle WebLogic Server versions affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Is there a patch for CVE-2026-70757?
No fixed versions are listed in the available facts; follow Oracle’s advisory and plan to apply vendor patches when they are released.
Does CVE-2026-70757 require authentication?
No; the vulnerability can be exploited without valid credentials over the network using T3 or IIOP.
References
- nvd.nist.gov/vuln/detail/CVE-2026-70757
- cve.org/CVERecord?id=CVE-2026-70757
- oracle.com/security-alerts/cspusep2026.html
- All Oracle CVEs on CVE Radar
- CVEs published in September 2026