Exploitable Vulnerability in Oracle Weblogic Server Proxy Plug-in
CVE-2026-60364
9.8CRITICAL
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-60364?
An exploitable vulnerability exists in the Oracle Weblogic Server Proxy Plug-in, specifically within the Oracle Fusion Middleware. This flaw allows unauthenticated attackers with network access via HTTP to compromise the plug-in, enabling unauthorized creation, deletion, or modification of critical data across the accessible systems. Supported versions affected include 12.2.1.4.0 and 14.1.2.0.0, posing a significant risk to organizations that rely on these versions for their web server integrations.
Affected Version(s)
Oracle HTTP Server 12.2.1.4.0
Oracle HTTP Server 14.1.2.0.0
Oracle Weblogic Server Proxy Plug-in 12.2.1.4.0