A low-privileged, network-based attacker can fully compromise Oracle's Service Delivery Platform and pivot to additional products, earning this Oracle Fusion Middleware flaw a near-maximum CVSS score of 9.9.
What Is It
CVE-2026-60377 is a critical vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via the T3 or IIOP protocols to compromise the platform. It carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L.
Why It Matters
The vulnerability's scope is "changed," meaning that while the flaw resides in the Service Delivery Platform, successful attacks may significantly impact additional products beyond the initial target. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, or all Service Delivery Platform accessible data, as well as unauthorized read access to critical data and the ability to cause a partial denial of service (partial DOS). The combination of low attack complexity, low required privileges, no user interaction, and high confidentiality and integrity impact makes this an attractive target.
What's Vulnerable
The affected product is Oracle Service Delivery Platform (Oracle Corporation). The supported versions confirmed affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Exploitation requires network access via the T3 or IIOP protocols.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the relevant fixes. The NVD record is currently in "Received" status (published 2026-07-21) and does not list active exploitation. This CVE does not appear in the supplied CISA KEV data, so no confirmed in-the-wild exploitation is indicated at this time.