SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60385 2026-07-21

CVE-2026-60385: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets unauthenticated attackers take over the product over the network via T3 or IIOP."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets unauthenticated attackers take over the product over the network via T3 or IIOP.

What Is It

CVE-2026-60385 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically in the Messaging Enabler component. According to Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. A successful attack can result in full takeover of the platform.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It requires no privileges, no user interaction, and low attack complexity, and it is reachable over the network. The impact is high across all three dimensions, confidentiality, integrity, and availability, meaning a successful exploit can lead to complete compromise of the affected system.

What's Vulnerable

The affected product is Oracle Service Delivery Platform (Oracle Corporation), component Messaging Enabler. The supported versions listed as affected are:

Exposure to attacks over the T3 and IIOP protocols is central to the risk, as these are the network vectors named in the description.

Patch Status

Oracle addressed this vulnerability as part of its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory. The NVD record lists a status of "Received" as of publication on 2026-07-21.

Note: The supplied CISA KEV data contains no entry for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources