SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60442 2026-07-21

CVE-2026-60442: Critical Unauthenticated Takeover in Oracle Service Delivery Platform

"A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated, network-based attacker fully compromise the product via the T3 or IIOP protocols."

A critical (CVSS 9.8) vulnerability in Oracle Fusion Middleware's Service Delivery Platform lets an unauthenticated, network-based attacker fully compromise the product via the T3 or IIOP protocols.

What Is It

CVE-2026-60442 is a critical flaw in the Messaging Enabler component of Oracle's Service Delivery Platform, part of Oracle Fusion Middleware. Per Oracle's advisory, the vulnerability is "easily exploitable" and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the platform. Successful exploitation can result in complete takeover of the Service Delivery Platform.

The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, no authentication, no user interaction, and low attack complexity, with high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network-reachable exploitation, no required privileges, no user interaction, and full compromise makes this among the most severe classes of vulnerability. An attacker who can reach the T3 or IIOP listener can take over the platform outright, gaining high impact across all three security properties. Because Service Delivery Platform underpins service orchestration in affected environments, a takeover exposes downstream systems and data handled by the platform.

What's Vulnerable

Patch Status

The vulnerability is addressed in Oracle's July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory without delay, given the critical severity and unauthenticated, network-based attack vector.

Note: The supplied source material contains no CISA KEV entry for this CVE, so active exploitation is not confirmed in the provided data.

Sources