SYS::ONLINE
Wasteland.
Briefs1498
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60369 2026-07-22

CVE-2026-60369: Critical Scope-Changing Flaw in Oracle Platform Security for Java

"A critical (CVSS 9.9) vulnerability in Oracle Platform Security for Java lets a low-privileged, network-based attacker take over the component and impact other products through a scope change."

A critical (CVSS 9.9) vulnerability in Oracle Platform Security for Java lets a low-privileged, network-based attacker take over the component and impact other products through a scope change.

What Is It

CVE-2026-60369 is a vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware, specifically the Centralized Thirdparty Jars component. Per Oracle's advisory, it is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks can result in a complete takeover of the component. It carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

Why It Matters

The score reflects a serious risk profile: network attack vector, low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability. Critically, the scope is changed (S:C), while the vulnerability resides in Oracle Platform Security for Java, Oracle notes that attacks "may significantly impact additional products." This means a successful compromise can extend beyond the vulnerable component to other systems that depend on it. The only barrier to exploitation is a low level of privilege on the target.

What's Vulnerable

According to the NVD record, the affected supported versions of Oracle Platform Security for Java are:

Patch Status

This CVE was published on 2026-07-22 and appears in Oracle's July 2026 Critical Patch Update (CPU). Administrators running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources