CVE-2026-60537
Oracle · Managed File Transfer
A critical vulnerability in Oracle Managed File Transfer allows a low privileged, network-based attacker to fully compromise the system and impact other products via scope change.
Executive summary
A critical vulnerability in Oracle Managed File Transfer allows low privileged attackers to achieve full system takeover, posing a severe risk to sensitive data transmission and enterprise middleware.
Vulnerability
The vulnerability exists within the MFT Runtime Server component, allowing a low privileged authenticated attacker with network access via HTTP to perform a full system takeover. This flaw involves a scope change, meaning successful exploitation can compromise additional products beyond the immediate target.
Business impact
Successful exploitation leads to a complete system takeover, resulting in the total loss of confidentiality, integrity, and availability for file transfer operations. Given the CVSS score of 9.9, this vulnerability represents an extreme risk that could lead to the unauthorized interception or manipulation of critical business data.
Remediation
Immediate Action: Apply the relevant security patches provided in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Monitor logs for unauthorized access or unusual file transfer activity originating from low privileged user accounts.
Compensating Controls: Deploy WAF rules to inspect HTTP traffic and block suspicious payloads targeting the MFT Runtime Server.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Because Oracle Managed File Transfer often handles sensitive organizational data, this vulnerability poses a significant risk to data integrity. Organizations must prioritize the immediate application of the July 2026 security patches to ensure the security of their file transfer operations and the underlying infrastructure.