SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60541 2026-07-21

CVE-2026-60541: Critical Unauthenticated Takeover Flaw in Oracle SOA Suite

"A critical, easily exploitable vulnerability in Oracle SOA Suite lets an unauthenticated attacker fully compromise the product over the network, earning a maximum-severity CVSS score of 9.8."

Here is the article:


CVE-2026-60541: Critical Unauthenticated Takeover Flaw in Oracle SOA Suite

A critical, easily exploitable vulnerability in Oracle SOA Suite lets an unauthenticated attacker fully compromise the product over the network, earning a maximum-severity CVSS score of 9.8.

What Is It

CVE-2026-60541 is a critical vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware, specifically in the Enterprise Scheduling System component. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful exploitation can result in complete takeover of the product.

The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

This vulnerability combines the worst-case attributes for defenders: it is remotely reachable over HTTP, requires no authentication, no user interaction, and results in full takeover of the affected system. With an exploitability sub-score of 3.9 (the maximum) and full compromise of confidentiality, integrity, and availability, any exposed instance is at severe risk. Oracle SOA Suite is often deployed as middleware integrating business-critical systems, amplifying the potential blast radius of a successful attack.

What's Vulnerable

The following supported versions of Oracle SOA Suite (Oracle Corporation) are affected:

The affected component is the Enterprise Scheduling System within Oracle Fusion Middleware.

Patch Status

Oracle addresses this vulnerability in its July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory and apply the relevant fixes for the affected versions. No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the source material at this time.

Sources