Oracle's July 2026 Critical Patch Update discloses CVE-2026-60365, a maximum-severity (CVSS 10.0) flaw allowing unauthenticated attackers to compromise the Oracle WebLogic Server Proxy Plug-in over HTTP.
What Is It
CVE-2026-60365 is a vulnerability in the Oracle WebLogic Server Proxy Plug-in, part of Oracle Fusion Middleware; specifically the WebLogic Server Proxy Plug-In for Third-Party Web Servers component. It is easily exploitable, allowing an unauthenticated attacker with network access via HTTP to compromise the plug-in. The issue carries a CVSS 3.1 base score of 10.0 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N.
Why It Matters
The scope is marked "Changed" (S:C), meaning that while the vulnerability resides in the WebLogic Server Proxy Plug-in, attacks may significantly impact additional products beyond the vulnerable component. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible to the plug-in; reflecting the High confidentiality and integrity impacts. With no privileges or user interaction required and low attack complexity, this is a straightforward remote attack.
What's Vulnerable
Per Oracle's advisory, the affected products and versions are:
- Oracle WebLogic Server Proxy Plug-in, version 15.1.1.0.0
- Oracle HTTP Server, versions 12.2.1.4.0 and 14.1.2.0.0
Patch Status
The fix is delivered through the Oracle Critical Patch Update of July 2026. Administrators should apply the corresponding CPU updates referenced in Oracle's July 2026 security advisory. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed by KEV at this time.