CVE-2026-60363 (matched: apache http server)

  • Wednesday, 22nd July, 2026
  • 16:04pm

A serious security flaw has been identified in the Oracle HTTP Server, part of Oracle Fusion Middleware, specifically within its Apache Plugin component. The affected versions of this software are 12.2.1.4.0 and 14.1.2.0.0. This vulnerability is very easy to exploit: an attacker does not need any login credentials, only network access to the server via HTTP, to carry out an attack. If an attack is successful, it can result in full takeover of the affected Oracle HTTP Server. The flaw has a CVSS 3.1 severity score of 9.8 out of 10, an extremely high rating that indicates the vulnerability impacts the server's confidentiality, integrity, and availability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363

« Back