SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60387 2026-07-21

CVE-2026-60387: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker with network access to fully compromise the product via T3 or IIOP protocols."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform allows an unauthenticated attacker with network access to fully compromise the product via T3 or IIOP protocols.

What Is It

CVE-2026-60387 is a vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware, specifically within the Messaging Enabler component. According to Oracle, the flaw is easily exploitable and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the Service Delivery Platform. Successful exploitation can result in a complete takeover of the product.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network-based attack vector, low attack complexity, and no required privileges or user interaction makes this vulnerability especially dangerous. An attacker needs no credentials and no victim interaction to achieve full takeover. Because the exploit path uses the T3 and IIOP protocols common to Oracle middleware deployments, any exposed instance is at significant risk.

What's Vulnerable

The affected product is Oracle Service Delivery Platform (Oracle Fusion Middleware), component Messaging Enabler. The following supported versions are affected:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update for July 2026. Organizations running affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026) as their required remediation.

Note: The supplied CISA KEV entry contained no data, so active exploitation is not confirmed in the provided source material.

Sources