A security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The supported versions confirmed to be affected are 12.2.1.4.0 and 14.1.2.0.0.
This flaw is easily exploitable: an attacker does not need any login credentials to carry out an attack, as long as they can send standard HTTP requests to the affected server. If an attack is successful, the attacker can take full control of the Oracle HTTP Server. This could allow them to access, modify, or disrupt the content and services of any websites hosted on that server. The vulnerability has a critical overall risk score of 9.8 out of 10, indicating severe potential impacts to the privacy, accuracy, and availability of affected systems and their hosted content.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363