A critical security vulnerability has been identified in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically in its Apache Plugin module. This issue affects versions 12.2.1.4.0 and 14.1.2.0.0, and has a severity rating of 9.8 out of 10 on the standard CVSS security scale. This flaw is easily exploitable: an attacker does not need any login credentials to launch an attack, as long as they can send standard web (HTTP) requests to the affected server. If successfully exploited, an attacker can take full control of the Oracle HTTP Server, which can lead to severe disruptions, unauthorized access to data, and loss of service availability for any websites or services relying on it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363