SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
CVE · Critical CVE-2026-60381 2026-07-21

Oracle Service Delivery Platform Hit by Critical CVE-2026-60381 (CVSS 9.9)

"Oracle has disclosed a critical, easily exploitable flaw in the Service Delivery Platform product of Oracle Fusion Middleware that can lead to full system takeover."

Oracle has disclosed a critical, easily exploitable flaw in the Service Delivery Platform product of Oracle Fusion Middleware that can lead to full system takeover.

What Is It

CVE-2026-60381 is a critical vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically the Messaging Enabler component. It carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is remotely reachable over the network via the T3 and IIOP protocols and requires only low privileges and no user interaction. Because the scope is changed, a successful attack can significantly impact additional products beyond Service Delivery Platform itself.

Why It Matters

Oracle describes the vulnerability as "easily exploitable," allowing a low-privileged attacker with network access to compromise the platform. Successful exploitation can result in a complete takeover of Service Delivery Platform, with high impact to confidentiality, integrity, and availability. The scope change (S:C) means the blast radius may extend to other connected products, raising the stakes for any environment exposing T3 or IIOP interfaces to attackers.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running the affected versions (12.2.1.4.0 and 14.1.2.0.0) should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. This CVE record does not indicate confirmation of active exploitation.

Sources