SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60375 2026-07-21

Oracle Service Delivery Platform Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60375)

"A critical, easily exploitable vulnerability in Oracle's Service Delivery Platform lets an unauthenticated attacker with network access fully take over the product."

A critical, easily exploitable vulnerability in Oracle's Service Delivery Platform lets an unauthenticated attacker with network access fully take over the product.

What Is It

CVE-2026-60375 is a critical vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. A successful attack can result in complete takeover of the platform.

It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, low attack complexity, and network reachability makes this flaw straightforward to weaponize. Because a successful attack results in full takeover of the Service Delivery Platform, an attacker gains high impact across confidentiality, integrity, and availability. The reliance on the T3 and IIOP protocols, commonly exposed in Oracle middleware deployments, broadens the potential attack surface.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running the affected versions (12.2.1.4.0 and 14.1.2.0.0) should apply the fixes documented in the Oracle Critical Patch Update Advisory for July 2026. There is no indication in the supplied source material that this CVE is listed in the CISA Known Exploited Vulnerabilities catalog, and no confirmation of active exploitation was provided.

Sources