Junglewise Threat Intelligence

CVE-2026-60370: Oracle Platform Security for Java compromise in Centralized Thirdparty Jars

CVE-2026-60370 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Oracle Platform Security for Java. Vendors: Oracle.

Executive brief

Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its third-party library components. An attacker with low-level access to the network could exploit this flaw to gain full control over the security platform. A successful attack could lead to a complete takeover of the affected system, potentially compromising sensitive data and service availability.

Technical details

This vulnerability exists within the Centralized Thirdparty Jars component of Oracle Platform Security for Java (Oracle Fusion Middleware). It is classified as difficult to exploit (High Attack Complexity) but allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation results in a complete loss of confidentiality, integrity, and availability (takeover of the product). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-22: advisory: Initial advisory published by Oracle and NVD.

References

Related threats