Summary
A critical vulnerability, CVE-2026-60363, has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to achieve complete compromise of the affected server, resulting in full impact to confidentiality, integrity, and availability. It was disclosed as part of Oracle’s July 2026 Critical Patch Update and carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: An exploitable flaw in Oracle HTTP Server’s Apache Plugin component that can be triggered remotely without any credentials or prior access.
- Trigger conditions: The attacker requires only network-level reachability to the Oracle HTTP Server instance over HTTP; no authentication, no special configuration, and no user interaction are needed.
- Attack vector: Network-accessible; Oracle HTTP Server is an internet-facing web server commonly deployed at the network perimeter as a reverse proxy in front of Oracle WebLogic and Oracle E-Business Suite environments. The server is identifiable from the internet via its
ServerHTTP response header. - Impact: Successful exploitation results in complete compromise of the Oracle HTTP Server instance — full loss of confidentiality, integrity, and availability — enabling an attacker to read, modify, or destroy data and disrupt availability of the affected system.
Affected software
- Oracle HTTP Server 12.2.1.4.0
- Oracle HTTP Server 14.1.2.0.0
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Apply the patches provided in Oracle’s July 2026 Critical Patch Update. Oracle directs Fusion Middleware customers to the Fusion Middleware patch availability document (CPU211) for specific patch bundles and installation instructions applicable to versions 12.2.1.4.0 and 14.1.2.0.0.
- Network mitigation (if patching cannot be applied immediately): Restrict external network access to Oracle HTTP Server instances. Where Oracle HTTP Server is deployed as a reverse proxy, ensure it is not directly reachable from untrusted networks without additional access controls such as firewall rules limiting inbound HTTP access to trusted IP ranges.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

