Cookie Consent by Free Privacy Policy Generator

Critical Oracle vulnerability exploited despite comprehensive patching

The Register reports that a perfect-10 CVSS vulnerability in Oracle Fusion Middleware is being actively exploited in the wild, prompting CISA to add it to its Known Exploited Vulnerabilities catalogue and mandate US federal agencies patch within three days. The flaw, CVE-2026-60004, was disclosed in January and allows unauthenticated remote code execution on Oracle WebLogic Server. What makes this particularly concerning is that organisations could have applied all 1,449 Oracle patches released this year and still been vulnerable, because attackers are now exploiting how Oracle systems work by design rather than targeting traditional software bugs.

Why this matters for UK organisations

This represents a significant shift in how attackers approach enterprise infrastructure. Rather than waiting for new vulnerabilities to be disclosed, threat actors are increasingly studying how complex enterprise platforms are designed to operate and finding ways to abuse legitimate functionality. For UK organisations running Oracle WebLogic Server or other Fusion Middleware components, this is not just about applying a single patch but understanding whether your patching processes can keep pace with Oracle's quarterly critical patch updates, which often contain hundreds of fixes. The three-day deadline CISA has imposed reflects the severity of active exploitation and the speed at which attacks can spread once proof-of-concept code becomes available. Oracle WebLogic Server is widely deployed across financial services, healthcare, retail and government sectors in the UK, often running business-critical applications that cannot easily be taken offline for patching.

What to review

UK businesses running Oracle infrastructure should review whether their patching cadence for Oracle products is adequate and whether they have complete visibility of all Oracle components in their environment. Many organisations struggle with Oracle's complex licensing and deployment models, which can make it difficult to identify where WebLogic Server or other middleware components are running, particularly in development, testing or legacy environments that may not receive the same patching discipline as production systems. It is worth reviewing whether your organisation has a documented process for triaging Oracle critical patch updates, whether you can identify all Oracle components in your estate, and whether you have tested your ability to apply emergency patches to Oracle systems within a short timeframe. For organisations that cannot patch quickly due to application dependencies or change control requirements, consider whether compensating controls such as network segmentation, web application firewalls or increased monitoring can reduce risk until patching is complete.

Source: The Register

News and blog posts
Today's stories highlight the importance of understanding how attackers are...
The Register reports that a perfect-10 CVSS vulnerability in Oracle Fusion...
The Hacker News reports that security researchers at Oasis Security have...
Infosecurity Magazine reports that researchers have identified a...