A critical security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The affected versions of this software are 12.2.1.4.0 and 14.1.2.0.0. This flaw is easy to exploit, and requires no login credentials or special access for an attacker to use it. Anyone who can send standard web (HTTP) requests to the affected server can leverage this vulnerability to compromise the system. A successful attack would let an attacker take full control of the affected Oracle HTTP Server instance. The vulnerability has a very high severity rating of 9.8 out of 10, as it can impact all three core areas of server security: the confidentiality of data stored on or passing through the server, the integrity and trustworthiness of that data, and the server’s ability to operate normally.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363