Junglewise Threat Intelligence

CVE-2026-60376: Oracle Service Delivery Platform remote takeover in Messaging Enabler

CVE-2026-60376 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Service Delivery Platform. Vendors: Oracle, Oracle Corporation.

Executive brief

Oracle Service Delivery Platform, a component of Fusion Middleware used for managing telecommunications and messaging services, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the network without needing any login credentials. This could lead to a total loss of service, theft of sensitive data, and complete compromise of the platform's operations.

Technical details

A critical vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows for a complete compromise of the Service Delivery Platform, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats