CVE-2026-60366: Critical severity Oracle Oracle Platform Security for Java vulnerability
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60366?
CVE-2026-60366 has a critical severity rating of 10.
How do I fix CVE-2026-60366?
To fix CVE-2026-60366, update to the latest supported versions of Oracle Platform Security for Java.
What types of attacks can exploit CVE-2026-60366?
CVE-2026-60366 can be exploited by unauthenticated attackers with network access via HTTP.
Which versions of Oracle Platform Security for Java are affected by CVE-2026-60366?
Affected versions include Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0.
What components are involved in CVE-2026-60366?
CVE-2026-60366 involves vulnerabilities in the Centralized Thirdparty Jars component of Oracle Platform Security for Java.