Junglewise Threat Intelligence

CVE-2026-60530: Oracle HTTP Server compromise in mod_http2.so

CVE-2026-60530 · Severity: high · CVSS 7.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle HTTP Server, a web server component used within the Oracle Fusion Middleware suite. An attacker who already has basic access to the underlying server hardware can exploit this flaw to take full control of the web server. This could lead to the theft of sensitive data, unauthorized modification of web content, or a complete shutdown of web services.

Technical details

This vulnerability is located in the mod_http2.so component of Oracle HTTP Server version 14.1.2.0.0. It is classified as a local exploit, requiring the attacker to have existing logon credentials to the infrastructure where the server is executing. The flaw is described as easily exploitable and does not require user interaction. A successful exploit results in a complete compromise of the Oracle HTTP Server process, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Oracle HTTP Server 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References