SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60438 2026-07-21

CVE-2026-60438: Critical Unauthenticated Flaw in Oracle HTTP Server mod_ssl

"A critical (CVSS 9.1) vulnerability in Oracle HTTP Server's mod_ssl component lets an unauthenticated attacker with network access compromise the confidentiality and integrity of all server-accessible data."

A critical (CVSS 9.1) vulnerability in Oracle HTTP Server's mod_ssl component lets an unauthenticated attacker with network access compromise the confidentiality and integrity of all server-accessible data.

What Is It

CVE-2026-60438 is a vulnerability in the mod_ssl component of Oracle HTTP Server, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access over HTTP to compromise the server. Successful attacks can result in unauthorized creation, deletion, or modification of critical data—up to and including all data accessible to the server—as well as unauthorized read access to that data.

The CVSS 3.1 base score is 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. This reflects network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality and integrity (no availability impact).

Why It Matters

The combination of network reachability, no authentication, and low complexity makes this flaw straightforward to exploit against exposed instances. Because Oracle HTTP Server commonly fronts Fusion Middleware deployments, a successful attack exposes and can alter critical application data. The high confidentiality and integrity impacts mean an attacker can both read and tamper with data across everything the server can reach.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle security alert for the affected supported versions. No CISA KEV entry confirming active exploitation was supplied with this record.

Sources