A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets unauthenticated attackers take over the product over the network via T3 or IIOP.
What Is It
CVE-2026-60385 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. According to Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. A successful attack can result in full takeover of the platform.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It requires no privileges, no user interaction, and low attack complexity, and it is reachable over the network. The impact is high across all three dimensions, confidentiality, integrity, and availability, meaning a successful exploit can lead to complete compromise of the affected system.
What's Vulnerable
The affected product is Oracle Service Delivery Platform (Oracle Corporation), component Messaging Enabler. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Exposure to attacks over the T3 and IIOP protocols is central to the risk, as these are the network vectors named in the description.
Patch Status
Oracle addressed this vulnerability as part of its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory. The NVD record lists a status of "Received" as of publication on 2026-07-21.
Note: The supplied CISA KEV data contains no entry for this CVE, so there is no confirmation of active exploitation in the provided source material.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60385: https://nvd.nist.gov/vuln/detail/CVE-2026-60385