SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60566 2026-07-21

Oracle WebCenter Portal Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60566)

"A critical vulnerability in Oracle WebCenter Portal lets an unauthenticated attacker take over the product over the network with no user interaction, carrying a CVSS score of 9.8."

A critical vulnerability in Oracle WebCenter Portal lets an unauthenticated attacker take over the product over the network with no user interaction, carrying a CVSS score of 9.8.

What Is It

CVE-2026-60566 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful exploitation can result in a complete takeover of Oracle WebCenter Portal. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

The scoring reflects a worst-case profile: the attack vector is the network, attack complexity is low, no privileges are required, and no user interaction is needed. Impacts to confidentiality, integrity, and availability are all rated HIGH. In practice, that means an attacker who can reach an exposed WebCenter Portal instance over HTTP could seize full control of it without credentials; the kind of flaw that is straightforward to weaponize once details circulate.

What's Vulnerable

The affected product is Oracle WebCenter Portal (Oracle Fusion Middleware), component Runtime Tools. The supported versions listed as affected are:

Patch Status

The CVE record references Oracle's July 2026 Critical Patch Update advisory, which is the source of the disclosure and the vehicle for remediation. Organizations running the affected versions should apply the fixes from that Critical Patch Update. As of this writing, there is no CISA KEV entry accompanying this record, so active exploitation is not confirmed in the supplied source material; the record's vulnerability status is "Received."

Sources