SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60441 2026-07-21

CVE-2026-60441: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker with network access fully compromise the product via the T3 or IIOP protocols."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker with network access fully compromise the product via the T3 or IIOP protocols.

What Is It

CVE-2026-60441 is a vulnerability in the Messaging Enabler component of Oracle's Service Delivery Platform, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via T3 or IIOP to compromise the platform. A successful attack can result in complete takeover of the Service Delivery Platform.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It requires no privileges, no user interaction, and low attack complexity, and it is exploitable over the network. Oracle rates the impact as high across confidentiality, integrity, and availability; meaning a successful attacker can read data, modify it, and disrupt availability, culminating in full takeover of the affected product.

What's Vulnerable

The affected product is Oracle Service Delivery Platform (Oracle Corporation), specifically the Messaging Enabler component. Per the NVD record, the supported versions affected are:

Exposure is tied to reachability of the T3 and IIOP protocols on affected instances.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). At the time of this record, the NVD entry lists a vulnerability status of "Received," and there is no CISA KEV entry confirming active exploitation in the supplied source material.

Sources