There is a critical security vulnerability in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The affected software versions are 12.2.1.4.0 and 14.1.2.0.0.
This flaw is easily exploitable, and does not require an attacker to have any login credentials for the server. Any user with network access to the server via HTTP can attempt to carry out an attack.
A successful exploit can result in a full takeover of the affected Oracle HTTP Server. The vulnerability has a CVSS 3.1 base severity score of 9.8 out of 10, meaning it can impact the confidentiality, integrity, and availability of the server and the data it handles.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363