A critical, easily exploitable flaw (CVSS 9.8) in Oracle Platform Security for Java lets an unauthenticated remote attacker fully compromise the product over HTTP.
What Is It
CVE-2026-60372 is a vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware, specifically within the Centralized Thirdparty Jars component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the product. A successful attack can result in a complete takeover of Oracle Platform Security for Java.
The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.
Why It Matters
This vulnerability combines the worst set of characteristics for defenders: network-reachable, low attack complexity, no privileges required, and no user interaction. Because exploitation requires only HTTP access and no authentication, exposed instances can be attacked directly by anyone who can reach them. The outcome, full takeover of the affected product, means an attacker gains high impact across confidentiality, integrity, and availability.
What's Vulnerable
The affected product is Oracle Platform Security for Java (Oracle Corporation), part of Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is identified as Centralized Thirdparty Jars.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (July 2026) and apply the relevant fixes to affected versions. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.