Multiples vulnérabilités dans Oracle Weblogic (16 septembre 2026)
Multiple vulnerabilities have been discovered in Oracle WebLogic Server, allowing attackers to execute arbitrary code remotely. These flaws could lead to significant system compromise. Oracle has released security alerts and patches to address these issues.
Oracle WebLogic Server is experiencing a security vulnerability affecting multiple versions. These vulnerabilities enable remote code execution, potentially allowing an attacker to gain control of affected systems. The CERT-FR report highlights several CVEs associated with this issue.
What happened
Several vulnerabilities exist within Oracle WebLogic Server, presenting a serious risk to organizations utilizing this software. The vulnerabilities allow for remote code execution, potentially leading to complete system takeover. The CERT-FR report details specific CVE identifiers linked to these flaws.
Technical details
- Affected Products: Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
- CVE Identifiers: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038.
Impact
Organizations running vulnerable versions of Oracle WebLogic Server are at risk of unauthorized code execution and potential system compromise. Successful exploitation could lead to data breaches, system disruption, and further attacks.
What to do
- Refer to the Oracle WebLogic Security Bulletin CSPUSEP2026 (https://www.oracle.com/security-alerts/cspusep2026.html) for detailed information and available patches.
Why it matters
This vulnerability represents a significant threat to organizations relying on Oracle WebLogic Server, demanding immediate attention and remediation to prevent exploitation and minimize potential damage.