A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated, network-based attacker to fully take over affected systems.
What Is It
CVE-2026-60376 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. A successful attack can result in complete takeover of the platform.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This reflects the worst-case profile: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with high impacts to confidentiality, integrity, and availability. Because exploitation requires no authentication and can be carried out remotely, any exposed instance is at serious risk of full compromise.
What's Vulnerable
The affected product is Oracle Service Delivery Platform (Oracle Corporation), component Messaging Enabler. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Exploitation occurs over the T3 and IIOP network protocols.
Patch Status
Oracle addressed this issue in its Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update Advisory (July 2026) and apply the relevant fixes for the affected Service Delivery Platform versions. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.