SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60364 2026-07-21

Oracle WebLogic Server Proxy Plug-in Flaw (CVE-2026-60364)

"A critical, easily exploitable vulnerability in Oracle's WebLogic Server Proxy Plug-in lets an unauthenticated attacker compromise the component over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch…"

A critical, easily exploitable vulnerability in Oracle's WebLogic Server Proxy Plug-in lets an unauthenticated attacker compromise the component over the network via HTTP, disclosed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60364 is a vulnerability in the Oracle WebLogic Server Proxy Plug-in, a component of Oracle Fusion Middleware (specifically the WebLogic Server Proxy Plug-In for Third-Party Web Servers). Per the NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the plug-in. The described consequence of a successful attack is limited to integrity impact: unauthorized creation, deletion, or modification access to critical data or all data accessible to the plug-in. The record does not describe loss of confidentiality (data disclosure) or availability (denial of service).

The structured NVD metrics assign a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, a rating that asserts high confidentiality, integrity, and availability impact. That rating is inconsistent with the described impact, which is integrity-only. The CVE description text instead cites a CVSS 3.1 base score of 7.5 with an integrity-only profile, which matches the stated consequences. Readers should treat the 9.8 full-CIA metric as questionable and weight the integrity-only 7.5 characterization as the one supported by the impact description; both values are reproduced here as supplied.

Why It Matters

The vulnerability requires no authentication, no privileges, and no user interaction, and is reachable over the network. That combination makes it attractive for opportunistic exploitation against internet-facing middleware, independent of the exact CVSS score. Because the proxy plug-in sits in front of web servers routing traffic to WebLogic, an attacker who can create, delete, or modify the data passing through it can tamper with request/response handling and the integrity of routed traffic. The supplied data does not substantiate data theft or service outage as outcomes, so impact assessment should center on integrity/tampering.

What's Vulnerable

Per the supplied data, the affected supported versions are:

Affected products listed in the record are the Oracle WebLogic Server Proxy Plug-in and Oracle HTTP Server (Oracle Corporation).

Patch Status

The vulnerability was published on 2026-07-21 with NVD status "Received." The sole reference points to Oracle's July 2026 Critical Patch Update advisory, where fixes are distributed. Administrators should apply the relevant Oracle CPU updates for the affected versions.

No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time, and no KEV-mandated remediation action applies.

Sources