Junglewise Threat Intelligence

CVE-2026-60374: Oracle Service Delivery Platform remote compromise in Messaging Enabler

CVE-2026-60374 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, a middleware solution used for managing telecommunications and enterprise services. An unauthorized attacker can remotely take full control of the platform over the network without needing any login credentials. This could lead to a complete service outage, theft of sensitive communications data, and unauthorized access to connected business systems.

Technical details

This vulnerability affects the Messaging Enabler component within Oracle Service Delivery Platform (Fusion Middleware). It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the environment. Successful exploitation grants the attacker full control over the Service Delivery Platform, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats