SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60537 2026-07-21

CVE-2026-60537: Critical Takeover Flaw in Oracle Managed File Transfer

"A low-privileged, network-based attacker can fully compromise Oracle Managed File Transfer through its MFT Runtime Server component, with impact extending beyond the product itself."

A low-privileged, network-based attacker can fully compromise Oracle Managed File Transfer through its MFT Runtime Server component, with impact extending beyond the product itself.

What Is It

CVE-2026-60537 is a critical vulnerability in the Oracle Managed File Transfer (MFT) product, part of Oracle Fusion Middleware. The flaw resides in the MFT Runtime Server component. Oracle rates it a CVSS 3.1 base score of 9.9 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.

The vulnerability is easily exploitable: an attacker needs only low privileges and network access via HTTP, and no user interaction is required. Successful exploitation can result in complete takeover of Oracle Managed File Transfer.

Why It Matters

The near-maximum severity score reflects full compromise of confidentiality, integrity, and availability. Critically, the scope is changed (S:C), while the flaw lives in Oracle MFT, Oracle notes that attacks "may significantly impact additional products." This means a successful attack can extend beyond MFT into adjacent systems, raising the blast radius well past a single product boundary. The low attack complexity and low privilege requirement make it an attractive target for opportunistic exploitation.

What's Vulnerable

The affected product is Oracle Managed File Transfer (Oracle Fusion Middleware). Supported versions confirmed as affected are:

The vulnerable component is the MFT Runtime Server, reachable over HTTP.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running the affected versions should apply the fixes referenced in the Oracle security alert without delay. This CVE does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation in the provided source material at this time.

Sources