A critical security vulnerability, identified as CVE-2026-60363, has been discovered in the Apache Plugin component of Oracle HTTP Server, which is part of Oracle Fusion Middleware. The affected software versions are 12.2.1.4.0 and 14.1.2.0.0.
This flaw is simple to exploit and does not require an attacker to have valid login credentials for your server. Any unauthorized user who can send standard HTTP web requests to the affected server can use this vulnerability to take full, unapproved control of the Oracle HTTP Server instance.
A successful attack would allow the attacker to access all data stored on or sent through the server, change server content and settings, and disrupt or completely take offline any services running on the affected server. This vulnerability has a critical severity rating of 9.8 out of 10, as it impacts all three core areas of server security: data confidentiality, data integrity, and service availability.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363