A critical remote code execution vulnerability (CVE-2026-60366) has been disclosed in Oracle Platform Security for Java, a component of Oracle Fusion Middleware. The flaw exists in the 'Centralized Thirdparty Jars' module and impacts versions 12.2.1.4.0 and 14.1.2.0.0. Exploitation requires no authentication and can be initiated over HTTP, enabling attackers to fully compromise affected systems. The vulnerability's scope extends beyond the immediate component, potentially impacting interconnected systems. With a CVSS score of 10.0, this represents a severe risk requiring immediate remediation. Organizations utilizing the affected versions should apply Oracle's latest security patches without delay. Until patched, systems remain exposed to exploitation attempts that could lead to full infrastructure compromise. Monitor Oracle's official security advisories for detailed mitigation guidance and confirm deployment of fixes in all environments containing the vulnerable configurations.
CRITICAL
CVSS 10.0
CVE-2026-60366
2026-08-13
Critical Remote Code Execution Vulnerability in Oracle Platform Security for Java (CVE-2026-60366)
A critical vulnerability in Oracle Platform Security for Java allows unauthenticated attackers to execute arbitrary code remotely. Affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware. Immediate patching is required to prevent system compromise.