CVE-2026-60547
Oracle · Managed File Transfer
A critical vulnerability in Oracle Managed File Transfer allows low privileged attackers to compromise the system via HTTP.
Executive summary
A critical, remotely exploitable vulnerability in Oracle Managed File Transfer permits full system takeover by authenticated attackers.
Vulnerability
This vulnerability resides in the MFT Runtime Server component and allows an attacker with low-level privileges to perform remote attacks via HTTP. The flaw supports scope changes, which may lead to the compromise of additional interconnected software components within the environment.
Business impact
With a CVSS score of 9.9, this vulnerability poses an extreme threat to data integrity and system availability. Since Managed File Transfer handles sensitive data movement, a successful takeover could allow attackers to intercept, modify, or delete critical business information, leading to significant reputational and operational damage.
Remediation
Immediate Action: Update Oracle Managed File Transfer to the versions specified in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Review HTTP access logs for suspicious request patterns and monitor system performance for anomalies indicative of unauthorized process execution.
Compensating Controls: Deploy a Web Application Firewall to filter malicious HTTP requests and enforce strict access controls for all users of the MFT Runtime Server.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate patching. Security teams should treat this as a high priority item and ensure that all affected Oracle Managed File Transfer deployments are upgraded to the latest secure version without delay.