SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60384 2026-07-21

Oracle Service Delivery Platform Takeover — CVE-2026-60384

"A critical, unauthenticated flaw in Oracle Fusion Middleware's Service Delivery Platform lets remote attackers fully take over the product over the network."

A critical, unauthenticated flaw in Oracle Fusion Middleware's Service Delivery Platform lets remote attackers fully take over the product over the network.

What Is It

CVE-2026-60384 is a critical vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. Oracle rates it CVSS 3.1 base score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is described as easily exploitable: an unauthenticated attacker with network access via T3 or IIOP can compromise the platform. Successful exploitation results in complete takeover of the Service Delivery Platform.

Why It Matters

The vulnerability requires no authentication, no user interaction, and low attack complexity; an attacker only needs network reachability to the affected T3/IIOP interfaces. It carries high confidentiality, integrity, and availability impacts, meaning a successful attack can lead to full compromise of the affected system. With a 9.8 base score and an exploitability sub-score of 3.9 (the maximum), this is among the most severe classes of remotely exploitable flaws.

What's Vulnerable

Per Oracle, the affected supported versions of the Service Delivery Platform are:

The vulnerable component is the Messaging Enabler, exposed via the T3 and IIOP protocols. The vendor is Oracle Corporation.

Patch Status

This CVE was published as part of Oracle's Critical Patch Update for July 2026. Organizations running the affected versions should apply the fixes referenced in that advisory. Restricting network access to T3/IIOP interfaces reduces exposure where patching cannot be immediate; however, the authoritative remediation is the Oracle CPU. (No CISA KEV entry accompanied this data, so active exploitation is not confirmed by KEV at this time.)

Sources