A critical remote code execution vulnerability (CVE-2026-60644) has been disclosed in Oracle WebCenter Content, part of Oracle Fusion Middleware. The flaw exists in the Web Content Management component and impacts versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability allows unauthenticated attackers with network access via HTTP to execute arbitrary code, leading to full system compromise. Due to scope changes, exploitation could also impact other interconnected systems. With a CVSS 3.1 score of 10.0, this vulnerability represents an immediate high-risk threat. Attackers require no prior authentication, making exploitation straightforward. Organizations operating affected versions are strongly advised to apply Oracle's official security patches immediately. Until patched, network-level mitigations such as restricting HTTP access to trusted sources should be implemented. This vulnerability underscores the urgency of prioritizing middleware security updates to prevent potential large-scale breaches.
CRITICAL
CVSS 10.0
CVE-2026-60644
2026-08-12
Critical Remote Code Execution Vulnerability in Oracle WebCenter Content (CVE-2026-60644)
A critical vulnerability in Oracle WebCenter Content allows unauthenticated attackers to achieve remote system takeover. Affects versions 12.2.1.4.0 and 14.1.2.0.0. Immediate patching required due to high exploitability and severe impact.