SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60663 2026-07-21

Oracle WebCenter Content Hit by Critical CVSS 9.9 Takeover Flaw (CVE-2026-60663)

"A low-privileged, network-based flaw in Oracle WebCenter Content allows full takeover of the product and can spill over to impact additional systems, earning a near-maximum CVSS 3.1 base score of 9.9."

A low-privileged, network-based flaw in Oracle WebCenter Content allows full takeover of the product and can spill over to impact additional systems, earning a near-maximum CVSS 3.1 base score of 9.9.

What Is It

CVE-2026-60663 is a critical vulnerability in the Web Content Management component of Oracle WebCenter Content, part of Oracle Fusion Middleware. Oracle describes it as an "easily exploitable" flaw that lets a low-privileged attacker with network access over HTTP compromise WebCenter Content. Successful attacks can result in complete takeover of the product. Notably, the vulnerability carries a scope change: while it resides in WebCenter Content, attacks may significantly impact additional products beyond the vulnerable component.

Why It Matters

The vulnerability rates CVSS 3.1 Base Score 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination, network attack vector, low complexity, only low privileges required, and no user interaction, makes it highly practical to exploit. Impacts to confidentiality, integrity, and availability are all rated HIGH, and the changed scope means the blast radius can extend past the initially targeted system. Given full-takeover potential with minimal attacker prerequisites, exposed WebCenter Content instances represent a high-value target.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes from the Oracle Critical Patch Update Advisory. No CISA KEV entry was supplied, so active exploitation is not confirmed in the provided source material.

Sources