THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-60438 (CRITICAL 9.1) — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Orac

[NVD] CVE-2026-60438 (CRITICAL 9.1) — Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Orac

mednvdPublished 2026-07-21

CVE-2026-60438 CVSS: 9.1 CRITICAL Published: 2026-07-21T22:17:46.283

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulner

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60438