SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60374 2026-07-21

CVE-2026-60374: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated network attacker fully take over the product via T3 or IIOP."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated network attacker fully take over the product via T3 or IIOP.

What Is It

CVE-2026-60374 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. Oracle rates it CVSS 3.1 Base Score 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is easily exploitable: an unauthenticated attacker with network access via the T3 or IIOP protocols can compromise the platform. A successful attack can result in complete takeover of the Service Delivery Platform.

Why It Matters

The vulnerability requires no authentication, no privileges, and no user interaction, and it is remotely exploitable over the network. It carries HIGH impact across all three dimensions, confidentiality, integrity, and availability, with an exploitability sub-score of 3.9 (the maximum). Because successful exploitation yields full takeover of the affected product, any exposed instance reachable over T3 or IIOP is at severe risk.

What's Vulnerable

Exploitation occurs over the T3 and IIOP network protocols.

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update of July 2026. Affected organizations should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources