SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60565 2026-07-21

CVE-2026-60565: Critical Oracle WebCenter Portal Takeover Flaw

"A critical (CVSS 9.9) vulnerability in Oracle WebCenter Portal lets a low-privileged network attacker fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.9) vulnerability in Oracle WebCenter Portal lets a low-privileged network attacker fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60565 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the product. Successful exploitation can result in a complete takeover of Oracle WebCenter Portal. The issue carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting full confidentiality, integrity, and availability impact.

Why It Matters

The vulnerability is notable for its scope change (S:C): while the flaw resides in Oracle WebCenter Portal, Oracle warns that attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, network reachability over HTTP, and no user interaction required, this makes for a highly attractive target. An attacker needs only low privileges to achieve a full takeover, so any exposed or loosely restricted WebCenter Portal instance represents serious risk to the broader environment.

What's Vulnerable

Per Oracle, the affected supported versions of Oracle WebCenter Portal are:

The vulnerable component is Runtime Tools within Oracle Fusion Middleware.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Organizations running the affected versions should apply the fixes from that advisory. This CVE was published on 2026-07-21 and, at the time of writing, is in "Received" status in NVD with the CVSS metrics supplied by Oracle. No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.

Sources