Summary
CVE-2026-60365 is a critical, unauthenticated network-exploitable vulnerability affecting Oracle HTTP Server (versions 12.2.1.4.0 and 14.1.2.0.0) and the Oracle WebLogic Server Proxy Plug-in (version 15.1.1.0.0). Described by Oracle as "easily exploitable," it allows a remote, unauthenticated attacker with HTTP network access to achieve complete unauthorized access to all data and unauthorized creation, deletion, or modification of critical data across affected systems. It was disclosed on July 21, 2026, as part of Oracle’s July 2026 Critical Patch Update (CPU), and carries a CVSS v3.1 base score of 10.0 (CRITICAL).
Technical details
- Root cause: The specific CWE has not been assigned in the NVD record at time of publication; Oracle classifies the vulnerability as "easily exploitable" with no mitigating preconditions.
- Trigger conditions: An unauthenticated attacker with network access via HTTP can directly trigger the vulnerability — no credentials, no user interaction, and no special configuration are required.
- Attack vector: Remote, over the network (AV:N), with low attack complexity (AC:L), requiring no privileges (PR:N) and no user interaction (UI:N).
- Scope change: The vulnerability carries a Changed scope (S:C), meaning successful exploitation can impact resources and components beyond the directly vulnerable Oracle HTTP Server process itself.
- Impact: High confidentiality impact (C:H) — complete unauthorized read access to all accessible data; High integrity impact (I:H) — unauthorized creation, deletion, and modification of critical data. Availability is not impacted (A:N).
Affected software
- Oracle HTTP Server 12.2.1.4.0
- Oracle HTTP Server 14.1.2.0.0
- Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0
Severity
CVSS v3.1 Base Score: 10.0 (CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate action: Apply Oracle’s July 2026 Critical Patch Update (CPU), which contains the official fix for CVE-2026-60365. Oracle patch availability details for Fusion Middleware (including Oracle HTTP Server) are published in the "Affected Products and Patch Information" table of the official advisory at oracle.com/security-alerts/cpujul2026.html.
- If patching cannot be applied immediately: Restrict network access to Oracle HTTP Server instances at the perimeter — ensure they are not directly reachable from untrusted networks or the public internet. Apply egress and ingress controls to limit HTTP exposure to authorized source IP ranges only.
- Prioritize externally exposed instances: Given the zero-authentication requirement and network attack vector, any Oracle HTTP Server instance accessible from the internet should be treated as highest priority for patching.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

