CVE-2026-60363 (matched: apache http server)

  • Wednesday, 22nd July, 2026
  • 22:04pm

A critical security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, which is part of Oracle Fusion Middleware. The versions confirmed to be affected by this flaw are 12.2.1.4.0 and 14.1.2.0.0.

This issue is easy to exploit, and does not require an attacker to have any login credentials or pre-existing access to a server. Any unauthenticated user who can send standard HTTP web traffic to an affected server can launch an attack against it.

If an attack is successful, the attacker can take full unauthorized control of the affected Oracle HTTP Server. This vulnerability has a maximum-severity rating, as a successful exploit could impact the confidentiality, integrity, and availability of the server and any services it hosts.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363

« Back