A low-privileged, network-based attacker can fully compromise Oracle Managed File Transfer through its MFT Runtime Server component, with impact extending beyond the product itself.
What Is It
CVE-2026-60537 is a critical vulnerability in the Oracle Managed File Transfer (MFT) product, part of Oracle Fusion Middleware. The flaw resides in the MFT Runtime Server component. Oracle rates it a CVSS 3.1 base score of 9.9 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
The vulnerability is easily exploitable: an attacker needs only low privileges and network access via HTTP, and no user interaction is required. Successful exploitation can result in complete takeover of Oracle Managed File Transfer.
Why It Matters
The near-maximum severity score reflects full compromise of confidentiality, integrity, and availability. Critically, the scope is changed (S:C), while the flaw lives in Oracle MFT, Oracle notes that attacks "may significantly impact additional products." This means a successful attack can extend beyond MFT into adjacent systems, raising the blast radius well past a single product boundary. The low attack complexity and low privilege requirement make it an attractive target for opportunistic exploitation.
What's Vulnerable
The affected product is Oracle Managed File Transfer (Oracle Fusion Middleware). Supported versions confirmed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is the MFT Runtime Server, reachable over HTTP.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running the affected versions should apply the fixes referenced in the Oracle security alert without delay. This CVE does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation in the provided source material at this time.