CVE-2026-60363 (matched: apache http server)

  • Thursday, 23rd July, 2026
  • 10:05am

A critical security vulnerability has been identified in a component of Oracle’s Fusion Middleware called Oracle HTTP Server, specifically in its Apache Plugin module. Only versions 12.2.1.4.0 and 14.1.2.0.0 of this product are confirmed to be affected by this flaw.

This issue is very easy for attackers to exploit. An unauthenticated user (someone without valid login credentials for your server) with the ability to send HTTP traffic to your server over the internet can leverage this vulnerability to take full, unauthorized control of your Oracle HTTP Server instance.

The vulnerability has a critical severity score of 9.8 out of 10, as successful exploitation can impact all three core security priorities: attackers could access private, sensitive data handled by the server, modify server configurations or stored data, and even disrupt or take your hosted service offline completely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-60363

« Back