A critical (CVSS 9.8) vulnerability in Oracle Platform Security for Java lets an unauthenticated attacker take full control of the product over the network via HTTP.
What Is It
CVE-2026-60367 is a vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware, specifically in the "Centralized Thirdparty Jars" component. Oracle describes it as easily exploitable: an unauthenticated attacker with network access via HTTP can compromise the product. Successful attacks can result in a complete takeover of Oracle Platform Security for Java. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The vulnerability scores at the top of the severity scale because it combines the worst-case exploitability and impact factors. It requires no privileges, no user interaction, and low attack complexity, and it is reachable over the network. A successful attack yields high impact to confidentiality, integrity, and availability; effectively a full takeover of the affected component. Because Oracle Platform Security for Java underpins security services across Fusion Middleware deployments, compromise of this layer is significant.
What's Vulnerable
Per Oracle and the NVD record, the affected supported versions are:
- Oracle Platform Security for Java 12.2.1.4.0
- Oracle Platform Security for Java 14.1.2.0.0
The vulnerable component is "Centralized Thirdparty Jars." The vendor is Oracle Corporation.
Patch Status
The vulnerability was disclosed by Oracle and is addressed in the Oracle Critical Patch Update of July 2026. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory and apply the associated fixes. No CISA KEV entry accompanies this record, so active exploitation is not confirmed in the supplied source material.