CVE-2026-60373
Oracle · Oracle Platform Security for Java
A vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows a low privileged attacker to compromise the platform via HTTP requests.
Executive summary
An authenticated network vulnerability in Oracle Platform Security for Java allows low privileged attackers to achieve full system takeover via HTTP.
Vulnerability
The flaw resides in the Centralized Thirdparty Jars component and is easily exploitable by a low privileged attacker with network access via the HTTP protocol, resulting in potential platform takeover.
Business impact
The ability to compromise the Oracle Platform Security for Java product via standard HTTP traffic presents a significant risk to enterprise middleware infrastructure. With a CVSS score of 8.8, successful exploitation could lead to unauthorized administrative control and severe impacts on the security posture of the entire application environment.
Remediation
Immediate Action: Apply the July 2026 Oracle Critical Patch Update to secure the affected Fusion Middleware components.
Proactive Monitoring: Monitor web application logs for suspicious HTTP requests and patterns indicative of exploitation attempts against the platform.
Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect and filter incoming HTTP traffic for malicious payloads targeting the middleware.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Immediate application of the vendor-supplied security patches is required to protect against this vulnerability. Administrators should prioritize identifying and patching all affected Oracle Fusion Middleware instances across the network.