Oracle ships 673 patches, including an unauthenticated WebLogic takeover over T3 and IIOP
On September 15, 2026, Oracle released its September Critical Security Patch Update with 673 fixes across 17 product families, including several unauthenticated remote takeovers of WebLogic Server. Inventory every exposed WebLogic instance and cut T3/IIOP before a diffable exploit turns your servers into a target.