Oracle's July 2026 Critical Patch Update discloses CVE-2026-60547, a CVSS 9.9 vulnerability in Oracle Managed File Transfer that lets a low-privileged network attacker fully compromise the product and impact adjacent systems.
What Is It
CVE-2026-60547 is a critical vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware, specifically in the MFT Runtime Server component. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks can result in complete takeover of the product. Notably, the flaw carries a scope change: while the vulnerability resides in Oracle Managed File Transfer, attacks may significantly impact additional products.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Attacks are network-based, low in complexity, require no user interaction, and need only low privileges. The combination of high confidentiality, integrity, and availability impacts, plus the scope change to additional products, makes this a high-priority patching target. Managed file transfer systems frequently broker sensitive data across organizational boundaries, raising the stakes of a full takeover.
What's Vulnerable
The affected supported versions of Oracle Managed File Transfer are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is the MFT Runtime Server, reachable over HTTP.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Organizations running the affected versions should apply the fixes documented in the Oracle July 2026 security alert as a matter of priority. This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied source material, so active exploitation is not confirmed here.