A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated attacker with network access fully compromise the product via the T3 or IIOP protocols.
What Is It
CVE-2026-60441 is a vulnerability in the Messaging Enabler component of Oracle's Service Delivery Platform, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via T3 or IIOP to compromise the platform. A successful attack can result in complete takeover of the Service Delivery Platform.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It requires no privileges, no user interaction, and low attack complexity, and it is exploitable over the network. Oracle rates the impact as high across confidentiality, integrity, and availability; meaning a successful attacker can read data, modify it, and disrupt availability, culminating in full takeover of the affected product.
What's Vulnerable
The affected product is Oracle Service Delivery Platform (Oracle Corporation), specifically the Messaging Enabler component. Per the NVD record, the supported versions affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Exposure is tied to reachability of the T3 and IIOP protocols on affected instances.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory (July 2026). At the time of this record, the NVD entry lists a vulnerability status of "Received," and there is no CISA KEV entry confirming active exploitation in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60441, https://nvd.nist.gov/vuln/detail/CVE-2026-60441