CVE-2026-60365
Oracle · Oracle HTTP Server
A critical, unauthenticated remote code execution vulnerability exists in the Oracle WebLogic Server Proxy Plug-in for third-party web servers.
Executive summary
A critical, unauthenticated vulnerability in the Oracle WebLogic Server Proxy Plug-in allows attackers to compromise sensitive data and manipulate web server operations.
Vulnerability
This is an easily exploitable, unauthenticated vulnerability allowing remote attackers to send malicious HTTP requests to the proxy plug-in. This flaw enables unauthorized access to critical data and the ability to modify or delete sensitive information.
Business impact
This vulnerability holds a CVSS score of 10.0, signifying the maximum level of severity. An unauthenticated attacker can achieve full access to data managed by the proxy, potentially leading to massive data breaches, service disruption, and compromise of the entire web application architecture.
Remediation
Immediate Action: Update the Oracle HTTP Server and WebLogic Server Proxy Plug-in to the versions specified in the July 2026 Oracle Critical Patch Update. Verify the deployment of these patches across all affected web server instances.
Proactive Monitoring: Monitor web server logs for suspicious HTTP requests, specifically those targeting the proxy configuration or unusual patterns that suggest injection attempts. Alert on unauthorized modifications to the web server environment.
Compensating Controls: Deploy a WAF with strict input validation rules to inspect and filter traffic destined for the WebLogic Proxy Plug-in. Ensure that the web server is configured with the principle of least privilege to limit the impact of a potential breach.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the critical severity and unauthenticated nature of this flaw, immediate patching is required. Security teams should treat this as a high-urgency task to protect the integrity of the web-facing infrastructure and the data contained within.