Junglewise Threat Intelligence

CVE-2026-60441: Oracle Service Delivery Platform remote takeover in Messaging Enabler

CVE-2026-60441 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Executive brief

A critical vulnerability has been identified in Oracle's Service Delivery Platform, a middleware component used for managing communications and messaging services. An unauthorized attacker can remotely take full control of the system over the network without needing any login credentials. This could lead to a complete service outage, theft of sensitive data, and total compromise of the platform's operations.

Technical details

A critical vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows for a complete compromise of the Service Delivery Platform, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60441 was published to the NVD.

References

Related threats