CTIPilot

Oracle WebLogic Server

product · product:oracle-weblogic-server

Coverage timeline
2
first 2026-08-05 → last 2026-08-20
Peak priority
high
2 high
Sources cited
7
6 hosts
Sections touched
2
active-threats, trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below

ATT&CK techniques

3 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/oracle-august-2026-cpu-three-unauthenticated-cvss-10 · 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Persistence TA0003

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Privilege Escalation TA0004

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Stealth TA0005

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Story timeline

  1. 2026-08-20Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory
    trending-vulnerabilities943 patches in a monthly release, and the ones that decide the sequencing are the three needing no credential and no user interaction at all
  2. 2026-08-05ByteToBreach hits Hungary's State Treasury after Romania's land registry; the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
    active-threatsThe actor who wiped Romania's cadastre reaches a second EU government body through legacy WebLogic

Where this entity is cited

  • active-threats1
  • trending-vulnerabilities1

Source distribution

  • telex.hu2 (29%)
  • kelacyber.com1 (14%)
  • news.risky.biz1 (14%)
  • oracle.com1 (14%)
  • security-hub.ncsc.admin.ch1 (14%)
  • securityweek.com1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Oracle WebLogic Server (2)

2026-08-20 · view entry permalink →

Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory

Oracle published its August 2026 Critical Security Patch Update on 2026-08-18, stating that it "contains 943 new security patches across the product families listed below" (Oracle, 2026-08-18); Switzerland's NCSC put it in front of its own constituency the next day (NCSC-CH, 2026-08-19). This is worth naming precisely, because the release type sets the patch window: a Critical Security Patch Update is Oracle's monthly release (the page states that security patches ship on the third Tuesday of each month and lists 15 September 2026 as the next one) and it is a distinct thing from the quarterly cumulative Critical Patch Update it complements, the next of which is 20 October 2026 (Oracle, 2026-08-18). An estate that treats this as the quarterly cycle will both misjudge how soon the next batch lands and, more importantly, wait a quarter for fixes that are already out. Most of a release this size is still routine maintenance; what takes a handful of items past routine is their own mechanics, and those are not in the families with the largest counts.

Three CVEs in the release carry a CVSS 3.1 base score of 10.0, and in Oracle's own risk matrices all three record Privileges Required as None, User Interaction as None, and Scope as Changed, an anonymous, single-request path to full compromise of the component and beyond it. CVE-2026-61241 is in the OID LDAP Server component of Oracle Internet Directory, reachable over LDAP, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The other two, CVE-2026-70880 and CVE-2026-70921, are in the Access and security component of Hyperion Data Relationship Management (reachable over TCP) and the Security component of Hyperion Financial Management (reachable over TLS), both at 11.2.25.0.000 (Oracle, 2026-08-18). The Internet Directory flaw is the one that should move first in a public-sector estate: an LDAP directory server is identity infrastructure, it is normally reachable from every application that authenticates against it, and a scope-changed compromise of it is not contained to the directory.

The concentration behind those three is what makes the sequencing work non-trivial. Oracle records 262 new patches for Fusion Middleware, of which it states 182 "may be remotely exploitable without authentication", and 120 for E-Business Suite, of which 27 may be; Hyperion carries 262 patches with 107 in that category (Oracle, 2026-08-18). Within E-Business Suite the two highest-scored unauthenticated flaws sit on inbound processing paths that an internet-facing deployment exposes by design, CVE-2026-60782 in the File Transmission component of Oracle Payments over HTTP, and CVE-2026-70926 in the Workflow Notification Mailer over SMTP, both 9.8. In Fusion Middleware, CVE-2026-60672 is an unauthenticated 9.8 in the WebLogic Server core reachable over T3 and IIOP, a protocol pair with a long history of public exploit work following Oracle releases.

No source fetched this run reports exploitation of any individual flaw in this cycle, and NCSC-CH's relay records exploitation status as unknown for the batch as a whole (NCSC-CH, 2026-08-19). Oracle's own advisory makes the point that matters more than any single score: it "continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches" (Oracle, 2026-08-18). For estates that cannot patch 943 items at once, the useful hardening step in the meantime is network placement rather than version: T3, IIOP, RMI, CORBA and LDAP listeners on middleware and directory hosts have no business being reachable from a general-purpose user network, and restricting them removes the reachability half of every unauthenticated flaw in this release regardless of which one is patched first.

This Critical Security Patch Update contains 943 new security patches across the product families listed below.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches.

Oracle 2026-08-18
vulnerability20 Aug 04:44Zmulti-sourceOpen finding ↗

2026-08-05 · view entry permalink →

HIGHNATOB2

ByteToBreach hits Hungary's State Treasury after Romania's land registry; the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle

Hungarian outlet Telex.hu reports that the Magyar Államkincstár (Hungary's State Treasury) was breached in late July 2026, with the intrusion confirmed by Treasury officials to Hungarian journalists over the weekend of 2026-08-01/02, and specifically affecting its Agricultural and Rural Development Office (MVH) (Telex.hu, 2026-08-03). Risky Bulletin frames the significance plainly: the same actor who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system (Risky Bulletin, 2026-08-05). That is the part which matters beyond Hungary; this is one financially-motivated operator, assessed by KELA as likely an individual, reaching two national government bodies of two EU member states inside roughly a month (KELA, 2026-07-17).

The reported entry point is the transferable part, and it is not a novel technique. Per cybersecurity experts Telex.hu consulted, who reviewed screenshots the attacker leaked, access came through an unpatched Oracle WebLogic Server, with the outlet linking to Oracle's October 2017 Critical Patch Update (Telex.hu, 2026-08-03). No source names a specific CVE, so none is recorded in this entry's metadata and none should be inferred from the patch-cycle reference. What the reporting does support is the shape: a public application server carrying fixes that shipped roughly nine years ago, still reachable, still in service at a national treasury.

From that foothold the attacker escalated to domain-administrator rights (Telex.hu's sources state the attackers obtained the highest-level administrative privileges in practically every critical system) and the same reporting puts the reach at 116 virtual machines and 229 TB of data, with ransomware encrypting files on employee workstations (Telex.hu, 2026-08-03). Those scope figures derive from the experts' reading of attacker-supplied screenshots rather than from an official statement, and should be held as a claim under review. Treasury officials state that customer and citizen data was not affected. On origin the two accounts diverge: Telex.hu reports the Treasury's own experts attributing the attack to Russian servers, while ByteToBreach disputes that characterisation, denies making a ransom demand and describes the motive as financial. Neither account is independently confirmed. Hungary's National Cybersecurity Institute is investigating and the affected servers were disconnected on discovery.

Triage: exploitation of a legacy application server looks in telemetry like the application server's own service account doing something new, a Java process spawning a command interpreter, outbound connections from a host that should only receive them, or an authentication from the server's account to a system it has never touched. On a host that has run unchanged for years, a first-of-its-kind child process or destination is a stronger signal than it would be anywhere else, precisely because the baseline is so static.

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

Risky Bulletin (Risky Business Media) 2026-08-05

A támadók gyakorlatilag minden kritikus rendszerben megszerezték a legmagasabb szintű rendszergazdai jogosultságokat

Telex.hu 2026-08-03

Builds on: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach

incident05 Aug 04:12Zmulti-sourceOpen finding ↗