A serious security vulnerability has been found in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The only confirmed affected versions are 12.2.1.4.0 and 14.1.2.0.0.
This flaw is very easy for attackers to exploit, and does not require any login credentials or prior access to your server. Any unauthenticated person who can reach the affected server over the internet via standard web traffic can take full control of the Oracle HTTP Server if they carry out a successful attack.
The vulnerability has been given a maximum severity rating of 9.8 out of 10 on the standard cybersecurity risk scale, as successful exploitation can lead to total loss of control over the server’s data, settings, and ability to stay online. The flaw impacts all three core areas of server security: the confidentiality of data stored on the server, the integrity of its content and configurations, and its availability to legitimate users.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363