CVE-2026-60363 (matched: apache http server)

  • Thursday, 23rd July, 2026
  • 16:05pm

A critical security vulnerability tracked as CVE-2026-60363 has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. Only versions 12.2.1.4.0 and 14.1.2.0.0 of this software are affected by the flaw, which carries a severity rating of 9.8 out of 10. The vulnerability is very easy to exploit: an attacker does not need any login credentials, account access, or special permissions to attempt an attack. Any unauthorized user who can send standard web (HTTP) traffic to an affected server can try to leverage this flaw. If an attacker successfully exploits this vulnerability, they can take full control of the affected Oracle HTTP Server instance. This could allow them to access, modify, or delete data stored on the server, or disrupt the normal operation of any website running on that server.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363

« Back