A critical remote code execution vulnerability (CVE-2026-60360) has been disclosed in Oracle Unified Directory, a component of Oracle Fusion Middleware. The flaw exists in the OUD Core module and impacts versions 12.2.1.4.0 and 14.1.2.1.0. Attackers can exploit this vulnerability without authentication by leveraging LDAP protocol interactions, potentially leading to full system compromise. The CVSS 3.1 score of 10.0 reflects the ease of exploitation and severe consequences, including unauthorized data access, service disruption, and lateral movement within networks. Organizations utilizing the affected software versions are strongly urged to apply security patches from Oracle’s official channels. This vulnerability underscores the importance of timely updates to mitigate risks of exploitation by malicious actors. Failure to address this issue could result in widespread operational disruption and data breaches. Users should review Oracle’s security advisories for detailed remediation steps and version-specific guidance.