A critical remote code execution vulnerability (CVE-2026-60358) has been disclosed in Oracle Access Manager, part of Oracle Fusion Middleware. The flaw exists in the Authentication Engine component and affects versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access can exploit this vulnerability over HTTP to achieve full system compromise. The CVSS 3.1 score of 10.0 reflects its ease of exploitation and complete impact on confidentiality, integrity, and availability. While the vulnerability resides in Oracle Access Manager, successful attacks may cascade to affect other products due to scope expansion. Organizations running affected versions are strongly advised to apply patches from Oracle’s latest security updates immediately. Until patched, restrict network access to affected systems and monitor for suspicious HTTP-based activity. This vulnerability underscores the urgency of prioritizing middleware security updates to prevent potential large-scale breaches.