SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60363 2026-07-21

CVE-2026-60363: Critical Unauthenticated Takeover in Oracle HTTP Server

"A critical, easily exploitable flaw in Oracle HTTP Server's Apache Plugin lets an unauthenticated network attacker fully take over the server, carrying a CVSS 3.1 base score of 9.8."

Here is the article.

CVE-2026-60363: Critical Unauthenticated Takeover in Oracle HTTP Server

A critical, easily exploitable flaw in Oracle HTTP Server's Apache Plugin lets an unauthenticated network attacker fully take over the server, carrying a CVSS 3.1 base score of 9.8.

What Is It

CVE-2026-60363 is a vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware, specifically in the Apache Plugin component. It is described by Oracle as an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks can result in complete takeover of Oracle HTTP Server. The issue is rated CRITICAL with a CVSS 3.1 base score of 9.8 (vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

The vulnerability requires no authentication, no user interaction, and low attack complexity; an attacker only needs network access over HTTP. Because a successful attack results in full takeover of the server, exposed instances face a high risk of complete compromise. The maximum-tier impact scores across all three security properties (confidentiality, integrity, and availability) place this among the most severe class of remotely exploitable flaws.

What's Vulnerable

The affected product is Oracle HTTP Server (Oracle Corporation), part of Oracle Fusion Middleware. Per the source material, the affected supported versions are:

Patch Status

Oracle published this issue as part of its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory for July 2026 (linked below) and apply the corresponding fixes for the affected Oracle HTTP Server versions. No CISA KEV entry was supplied, so active exploitation is not confirmed in the provided source material.

Sources