SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60555 2026-07-21

CVE-2026-60555: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites

"A critical, easily exploitable vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker to fully compromise affected systems over the network, earning a CVSS score of 9.8."

Here is the article:

CVE-2026-60555: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites

A critical, easily exploitable vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker to fully compromise affected systems over the network, earning a CVSS score of 9.8.

What Is It

CVE-2026-60555 is a critical vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). According to Oracle, the flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in a complete takeover of the product.

The vulnerability carries a CVSS 3.1 Base Score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

This is about as severe as vulnerabilities get. The combination of network reachability over HTTP, no authentication requirement, low attack complexity, and full compromise of the target makes it a prime candidate for opportunistic exploitation. A successful attack results in takeover of Oracle WebCenter Sites, giving an attacker high impact across all three security pillars; confidentiality, integrity, and availability.

What's Vulnerable

The following supported versions of Oracle WebCenter Sites (Oracle Corporation) are affected:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running affected versions should apply the fixes referenced in the Oracle Critical Patch Update advisory (cpujul2026). No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the source material at this time.

Sources