THREAT OPS › Threat News › [NVD] CVE-2026-60363 (CRITICAL 9.8) — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromis
[NVD] CVE-2026-60363 (CRITICAL 9.8) — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromis
CVE-2026-60363 CVSS: 9.8 CRITICAL Published: 2026-07-21T22:17:39.633
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this
Indicators of compromise
- CVE-2026-60363cve
- 12.2.1.4ipv4
- 14.1.2.0ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60363