A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated network attacker fully take over the product via T3 or IIOP.
What Is It
CVE-2026-60374 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. Oracle rates it CVSS 3.1 Base Score 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is easily exploitable: an unauthenticated attacker with network access via the T3 or IIOP protocols can compromise the platform. A successful attack can result in complete takeover of the Service Delivery Platform.
Why It Matters
The vulnerability requires no authentication, no privileges, and no user interaction, and it is remotely exploitable over the network. It carries HIGH impact across all three dimensions, confidentiality, integrity, and availability, with an exploitability sub-score of 3.9 (the maximum). Because successful exploitation yields full takeover of the affected product, any exposed instance reachable over T3 or IIOP is at severe risk.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Service Delivery Platform (Oracle Fusion Middleware)
- Component: Messaging Enabler
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Exploitation occurs over the T3 and IIOP network protocols.
Patch Status
The vulnerability is addressed in Oracle's Critical Patch Update of July 2026. Affected organizations should consult the Oracle Critical Patch Update advisory and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60374, https://nvd.nist.gov/vuln/detail/CVE-2026-60374