SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60458 2026-07-21

CVE-2026-60458: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60458, a CVSS 9.9 vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker take over the product and impact adjacent…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60458, a CVSS 9.9 vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker take over the product and impact adjacent systems.

What Is It

CVE-2026-60458 is a critical vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. The flaw is easily exploitable, allowing a low-privileged attacker with network access over the T3 or IIOP protocols to compromise the product. Oracle rates it CVSS 3.1 Base Score 9.9 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Successful exploitation can result in complete takeover of Oracle WebCenter Enterprise Capture.

Why It Matters

The vulnerability carries high impacts to confidentiality, integrity, and availability. Critically, the CVSS scope is Changed (S:C): while the flaw resides in WebCenter Enterprise Capture, attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, no user interaction, and only low privileges required, this makes the flaw a strong candidate for rapid weaponization. Note: the supplied CISA KEV entry is empty, so there is no confirmation of active exploitation in the provided source material.

What's Vulnerable

The affected product is Oracle WebCenter Enterprise Capture (vendor: Oracle Corporation). The supported versions listed as affected are:

Exposure is via the network using the T3 and IIOP protocols.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes provided in that update. No separate CISA required-action or due-date data was supplied, as the KEV entry is empty.

Sources