CVE-2026-60368
Oracle · Oracle Platform Security for Java
A vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows a low privileged attacker to compromise the platform via SOAP requests.
Executive summary
An authenticated network vulnerability in Oracle Platform Security for Java allows low privileged attackers to achieve full system takeover.
Vulnerability
This flaw exists in the Centralized Thirdparty Jars component and is easily exploitable by an attacker with low privileges who has network access to the target via the SOAP protocol.
Business impact
A successful exploit allows for the complete takeover of the Oracle Platform Security for Java environment. With a CVSS score of 8.8, this vulnerability poses a severe risk to the confidentiality, integrity, and availability of critical middleware services, potentially leading to unauthorized data access or service disruption.
Remediation
Immediate Action: Apply the latest Oracle Critical Patch Update for July 2026 to address the identified vulnerability in the middleware stack.
Proactive Monitoring: Monitor network traffic for anomalous SOAP requests and review server access logs for unauthorized attempts to interact with the security platform.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the affected middleware components to authorized personnel only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system takeover, organizations running Oracle Fusion Middleware should treat this update as a high priority. Ensure the latest Oracle security patches are applied in accordance with vendor guidelines to mitigate this risk.