Unauthenticated Remote Code Execution Flaw in Oracle HTTP Server by Oracle
CVE-2026-60363

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60363?

A vulnerability exists in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically affecting versions 12.2.1.4.0 and 14.1.2.0.0. This flaw enables an unauthenticated attacker with network access to exploit the server via HTTP requests. Such attacks can lead to complete server takeover, allowing unauthorized access to sensitive data and the potential manipulation of server functionalities. It is crucial for users of the affected versions to implement security updates provided by Oracle to mitigate this vulnerability.

Affected Version(s)

Oracle HTTP Server 12.2.1.4.0

Oracle HTTP Server 14.1.2.0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.