CVE-2026-60208: Oracle WebLogic Server Multiple Vulnerabilities (July 2026 CPU) (12.2.1.4.0 / 14.1.1.0.0 / 15.1.1.0.0)

Severity: Critical

CVSS Score: 4.3

The 12.2.1.4.0, 14.1.1.0.0, and 15.1.1.0.0 versions of WebLogic Server installed on the remote host are affected by multiple vulnerabilities as referenced in the July 2026 CPU advisory. - Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. (CVE-2026-60208) - Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core, a third-party component bundled with Oracle WebLogic Server. (CVE-2026-5598) Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.