Executive brief
Oracle HTTP Server, a web server component used to deliver web applications and services, contains a critical security vulnerability in its Apache Plugin. An unauthorized attacker can exploit this over the network to gain full control of the server. This could lead to the theft of sensitive data, disruption of business operations, and unauthorized access to internal systems.
Technical details
A critical vulnerability exists in the Apache Plugin component of Oracle HTTP Server (part of Oracle Fusion Middleware). The flaw is categorized as easily exploitable, requiring no authentication or user interaction. An attacker can exploit this vulnerability via HTTP over the network to achieve a complete takeover of the Oracle HTTP Server instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Oracle HTTP Server 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD