Oracle July 2026 CPU: pre-auth 10.0 RCE in WebLogic + more Suriq / 1d Strip it down to the software people actually self-host, and a much smaller set demands attention this week, a cluster of flaws an unauthenticated attacker can trigger over the network for full remote code execution, several scored a perfect CVSS 10.0. Any WebLogic Server, Oracle HTTP Server or Coherence instance reachable from the internet or an untrusted network, patched first, since these carry the unauthenticated 10.0 and