A critical (CVSS 9.9) vulnerability in Oracle Platform Security for Java lets a low-privileged, network-based attacker take over the component and impact other products through a scope change.
What Is It
CVE-2026-60369 is a vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware, specifically the Centralized Thirdparty Jars component. Per Oracle's advisory, it is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks can result in a complete takeover of the component. It carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The score reflects a serious risk profile: network attack vector, low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability. Critically, the scope is changed (S:C), while the vulnerability resides in Oracle Platform Security for Java, Oracle notes that attacks "may significantly impact additional products." This means a successful compromise can extend beyond the vulnerable component to other systems that depend on it. The only barrier to exploitation is a low level of privilege on the target.
What's Vulnerable
According to the NVD record, the affected supported versions of Oracle Platform Security for Java are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
This CVE was published on 2026-07-22 and appears in Oracle's July 2026 Critical Patch Update (CPU). Administrators running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.