SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60460 2026-07-21

CVE-2026-60460: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Enterprise Capture

"Oracle disclosed CVE-2026-60460, a critical (CVSS 9.8) vulnerability in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker fully compromise affected systems over the network."

Oracle disclosed CVE-2026-60460, a critical (CVSS 9.8) vulnerability in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker fully compromise affected systems over the network.

What Is It

CVE-2026-60460 is a critical vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via the T3 and IIOP protocols to compromise the product. A successful attack can result in a complete takeover of Oracle WebCenter Enterprise Capture.

Why It Matters

The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination, network attack vector, low complexity, no privileges, and no user interaction required, means an attacker needs nothing more than network reachability to exploit it. The impact is high across confidentiality, integrity, and availability, reflecting a full system takeover rather than a partial data exposure. No CISA KEV entry was supplied, so active exploitation is not confirmed in this source material.

What's Vulnerable

The affected product is Oracle WebCenter Enterprise Capture (vendor: Oracle Corporation). The supported versions listed as affected are:

Exposure is greatest where the T3 and IIOP protocols are reachable from untrusted networks.

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update for July 2026. Organizations running the affected versions should apply the fixes from that Critical Patch Update advisory. No CISA KEV-mandated remediation deadline was included in the supplied source material.

Sources