Wednesday , September 9 2026
943

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems in its business software. The update contains important Oracle WebLogic Server problems. These issues can let a remote attacker, who is not logged in, gain full control of the affected servers.

The update from August 18 talks about Oracle Database, Fusion Middleware, E-Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, Communications products, and more.

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Oracle strongly advised customers to update right away, saying that attackers have used known weaknesses when companies did not fix them.

Oracle Releases 943 Security Patches

The biggest fixes are for Oracle WebLogic Server, an application server used by big organizations to run important apps. Oracle fixed several serious problems that could be exploited from afar, with a high severity score of 9.8 out of 10.

The flaws include CVE-2026-60698, CVE-2026-60672, and CVE-2026-60696. They affect the WebLogic Server Core using the IIOP and T3 protocols.

These flaws are very risky because they can be used from afar without needing a password and can harm privacy, data correctness, and access.

A successful attacker can take unauthorized actions, steal sensitive data, change app content, disrupt business services, or gain full control of a weak WebLogic system.

Critical WebLogic vulnerabilities

CVE AFFECTED COMPONENT PROTOCOL CVSS 3.1
CVE-2026-60698 WebLogic Server Core IIOP 9.8
CVE-2026-60672 WebLogic Server Core T3, IIOP 9.8
CVE-2026-60696 WebLogic Server Core T3, IIOP 9.8
CVE-2026-60977 WebLogic Server WLS Core Components RMI 9.8
CVE-2026-60702 WebLogic Server Core T3, IIOP 9.9

Oracle fixed CVE-2026-60977, a serious RMI issue in WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. All of these problems got a CVSS score of 9.8.

Another serious WebLogic problem, CVE-2026-60702, has a CVSS score of 9.9. It impacts the WebLogic Core part and uses T3 or IIOP for the attack. Unlike the 9.8-rated issues, this one needs a low-level user who is logged in.

Successful exploitation could still greatly affect the system. It might lead to serious problems with data confidentiality, integrity, and availability. Oracle Fusion Middleware got 262 new security updates. 182 of these problems can be used by attackers from afar without needing permission.

This makes Fusion Middleware a very important product group in the August update. The advisory also has a serious CVSS 10.0 flaw, CVE-2026-61241, in the LDAP Server part of Oracle Internet Directory.

Oracle also fixed serious problems in other products. Oracle Commerce got 66 updates, including some that could be attacked from a distance with a CVSS score of 9.8.

Oracle E-Business Suite got 120 updates, while Oracle Database Products got 17 security fixes. Major problems were also fixed in Oracle Essbase, Enterprise Manager, Financial Services apps, and Oracle Hospitality Simphony.

Organizations should focus on WebLogic servers that are connected to the internet, especially those with T3, IIOP, or RMI services open to untrusted networks.

Security teams need to find the affected versions, get the right updates from Oracle’s Patch Availability Documents, test the updates in safe environments, and roll them out quickly when it’s workable.

Where quick fixes are not possible, admins should block access to open protocols and reduce unnecessary network reach. But Oracle warns that these workarounds do not solve the main problems.

Check Also

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates …