Junglewise Threat Intelligence

CVE-2026-60537: Oracle Managed File Transfer compromise in MFT Runtime Server

CVE-2026-60537 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Managed File Transfer, a system used by organizations to securely move and manage large volumes of data, contains a critical security flaw in its Runtime Server component. An attacker with low-level access to the network can exploit this vulnerability to take complete control of the system. Because this tool often connects to many other internal systems, a successful attack could allow an intruder to move beyond the file transfer server and impact other parts of the corporate network.

Technical details

A critical vulnerability exists in the MFT Runtime Server component of Oracle Managed File Transfer (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized by a CVSS 3.1 score of 9.9, indicating a high impact on confidentiality, integrity, and availability. The attack vector is network-based via HTTP and requires only low-privileged credentials with no user interaction. Notably, the vulnerability involves a scope change (S:C), meaning an exploit can impact resources beyond the security scope of the Managed File Transfer product itself. Successful exploitation can result in a complete takeover of the affected server.

Affected products

  • Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update
  • 2026-07-21: disclosed

References