CVE-2026-60358
Oracle has fixed a large number of vulnerabilities in various Oracle middleware products, including Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler), and Oracle WebCenter Content. The total number of vulnerabilities fixed in these updates is 345. The most severe vulnerabilities, 9 in total, have the highest score of 10.0 and are found in various Oracle middleware components, allowing unauthenticated external attackers to achieve complete system compromise. Attackers can execute arbitrary code or gain full control over the system without authentication via HTTP, LDAP, SOAP, or other network interfaces. Some vulnerabilities can lead to unauthorized access, modification, or deletion of critical data. The impact may also extend to other Oracle products that depend on the affected middleware components. In addition to these 9 vulnerabilities with the highest score, another 145 vulnerabilities have been fixed with a CVSS score of 9 to 9.9. Many of these vulnerabilities can also be exploited remotely without prior authentication and can lead to arbitrary code execution, access to sensitive data, or complete system compromise. The remaining vulnerabilities have scores lower than 9. It is too extensive to include all detailed information in this advisory, and the NCSC therefore refers to the attached reference. Due to the large number and severity of these vulnerabilities, the NCSC considers it highly likely that widespread exploitation will occur in the short term. The NCSC therefore advises to carefully review the attached reference and urgently deploy the provided updates.
CSIRTS triage
- What
- A large number of vulnerabilities have been fixed, including those allowing complete system compromise.
- Who is affected
- Users of various Oracle middleware products.
- Urgency
- Remediation is critical due to the high severity of the vulnerabilities, with some scoring 10.0.
- Action
- Apply the latest updates provided by Oracle.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-60358
Get an email if CVE-2026-60358 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0252 [1.00] [H/H] Vulnerabilities fixed in Oracle Fusion middlewarencsc-nl · 2026-07-22
- criticalCVE-2026-60358: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Aut…nvd · 2026-07-21
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-60358)