Junglewise Threat Intelligence

CVE-2026-60367: Oracle Platform Security for Java remote compromise in Centralized Thirdparty Jars

CVE-2026-60367 · Severity: critical · CVSS 9.8 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used to manage security policies and identities, contains a critical vulnerability in its third-party library components. An unauthenticated attacker can exploit this over the network via HTTP to gain full control over the affected system. This could lead to the complete compromise of sensitive data, unauthorized access to enterprise applications, and disruption of business operations.

Technical details

A critical vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the environment. Successful exploitation can result in a complete takeover of the Oracle Platform Security for Java instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. While specific CWE details were not provided in the advisory, the CVSS score of 9.8 reflects the severity of remote unauthenticated code execution or similar high-impact flaws. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory: Published by Oracle and NVD

References

Related threats