SYS::ONLINE
Wasteland.
Briefs1499
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60366 2026-07-22

CVE-2026-60366: Critical Unauthenticated Takeover in Oracle Platform Security for Java

"A maximum-severity flaw in Oracle Platform Security for Java lets an unauthenticated attacker take over the component over the network and pivot into other products."

A maximum-severity flaw in Oracle Platform Security for Java lets an unauthenticated attacker take over the component over the network and pivot into other products.

What Is It

CVE-2026-60366 is a vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware, specifically the Centralized Thirdparty Jars component. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks can result in complete takeover of the product.

The issue carries a CVSS 3.1 Base Score of 10.0 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, no privileges, no user interaction, and full confidentiality, integrity, and availability impact.

Why It Matters

The vector reflects the worst-case profile: network-reachable, low attack complexity, and no authentication required. Critically, the scope is Changed: while the vulnerability resides in Oracle Platform Security for Java, Oracle notes that attacks may significantly impact additional products beyond the vulnerable component. That scope change is what pushes the score to a perfect 10.0 and means a single compromise can cascade across a Fusion Middleware deployment.

At the time of this writing, the supplied source material does not confirm active exploitation.

What's Vulnerable

The affected supported versions of Oracle Platform Security for Java (Oracle Corporation) are:

Patch Status

Oracle addresses this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle security alert and apply the corresponding CPU fixes. No CISA KEV entry accompanies the supplied material, so no KEV-mandated remediation deadline is indicated.

Sources