Summary
CVE-2026-60364 is a critical, unauthenticated vulnerability in the Oracle WebLogic Server Proxy Plug-in component of Oracle HTTP Server, disclosed on July 21, 2026 as part of Oracle’s July 2026 Critical Patch Update. The flaw is network-exploitable with no authentication and no user interaction required, and results in full compromise of confidentiality, integrity, and availability of data handled by the affected component. It carries a CVSS 3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The vulnerability exists in the Oracle WebLogic Server Proxy Plug-in component bundled within Oracle HTTP Server. Oracle’s advisory describes it as an easily exploitable flaw — the precise technical root cause has not been publicly disclosed by Oracle.
- Trigger conditions: An unauthenticated attacker with network access via HTTP can trigger the vulnerability without any user interaction or special configuration. Attack complexity is low.
- Attack vector: Remotely exploitable over the network (AV:N), no authentication required (PR:N), no user interaction needed (UI:N), low attack complexity (AC:L).
- Impact: Successful exploitation allows unauthorized creation, deletion, or modification of critical data accessible through the proxy plug-in, unauthorized read access to all accessible data, and the ability to cause a complete and repeatable denial of service (crash/hang) of the Oracle WebLogic Server Proxy Plug-in.
Affected software
- Oracle HTTP Server 12.2.1.4.0 (WebLogic Server Proxy Plug-in component)
- Oracle HTTP Server 14.1.2.0.0 (WebLogic Server Proxy Plug-in component)
Severity
CVSS v3.1 Base Score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply Oracle’s July 2026 Critical Patch Update (CPU), which contains the official fix for CVE-2026-60364. Oracle HTTP Server customers running versions 12.2.1.4.0 or 14.1.2.0.0 should patch immediately per Oracle’s advisory at https://www.oracle.com/security-alerts/cpujul2026.html.
- If patching is not immediately feasible: Restrict network access to Oracle HTTP Server instances so that only trusted sources can reach the HTTP listener. Ensure Oracle HTTP Server is not directly internet-exposed until the patch is applied. Monitor proxy plug-in access logs for anomalous unauthenticated requests.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

