A critical remote code execution vulnerability (CVE-2026-60365) has been disclosed in the Oracle WebLogic Server Proxy Plug-in component of Oracle Fusion Middleware. The flaw exists in version 15.1.1.0.0 and allows unauthenticated attackers to exploit the vulnerability over HTTP without requiring user interaction. Successful exploitation could enable attackers to create, delete, or modify data, potentially leading to full system compromise. The vulnerability’s scope extends beyond the proxy plug-in, impacting associated products due to its integration within the Oracle WebLogic Server ecosystem. Given its CVSS score of 10.0, this vulnerability is classified as 'Critical' due to its ease of exploitation and severe impact. Organizations operating affected versions are strongly advised to apply vendor-released patches immediately. Until patched, network-level mitigations such as restricting HTTP access to trusted sources and monitoring for anomalous traffic patterns are recommended. This vulnerability underscores the importance of timely updates for enterprise-grade middleware components.
CRITICAL
CVSS 10.0
CVE-2026-60365
2026-08-13
Critical Remote Code Execution Vulnerability in Oracle WebLogic Server Proxy Plug-in (CVE-2026-60365)
A critical vulnerability in Oracle WebLogic Server Proxy Plug-in allows unauthenticated attackers to execute arbitrary code remotely. Affects versions 15.1.1.0.0. Immediate patching is required to mitigate exploitation risks.