SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60386 2026-07-21

CVE-2026-60386: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker to fully compromise the product over the network via HTTP."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker to fully compromise the product over the network via HTTP.

What Is It

CVE-2026-60386 is a critical flaw in the Service Delivery Platform product of Oracle Fusion Middleware, specifically within the Messaging Enabler component. Oracle describes it as an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the Service Delivery Platform. A successful attack can result in a complete takeover of the platform.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

This vulnerability combines the worst-case exploitability and impact characteristics: it requires no authentication, no privileges, and no user interaction, and is reachable remotely over the network with low attack complexity. Because a successful attack results in full takeover of the Service Delivery Platform, with high confidentiality, integrity, and availability impact, an exposed instance represents a direct path to complete compromise. The 3.9 exploitability sub-score is the maximum possible, underscoring how easily this can be leveraged.

What's Vulnerable

The affected product is Oracle Corporation's Service Delivery Platform (Oracle Fusion Middleware), component Messaging Enabler. The supported versions confirmed affected are:

Patch Status

Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running the affected versions should consult Oracle's advisory and apply the corresponding Critical Patch Update fixes. No CISA KEV entry confirming active exploitation was supplied for this CVE at the time of writing.

Sources