Security Digest: July 22, 2026 - 194 Critical Vulnerabilities

Today’s alert is dominated by a massive Oracle patch wave: dozens of critical flaws in Fusion Middleware, WebLogic, Coherence, WebCenter, Access Manager, Unified Directory, Identity Manager, and related products are exposed to network-based attack, often with no authentication required. Several issues also affect Oracle Retail, JD Edwards, Enterprise Manager, MySQL, and third-party tools, creating a broad enterprise risk profile.

· 9 min read

Executive Summary

Today’s alert is dominated by a massive Oracle patch wave: dozens of critical flaws in Fusion Middleware, WebLogic, Coherence, WebCenter, Access Manager, Unified Directory, Identity Manager, and related products are exposed to network-based attack, often with no authentication required. Several issues also affect Oracle Retail, JD Edwards, Enterprise Manager, MySQL, and third-party tools, creating a broad enterprise risk profile.

Act now: prioritize internet-facing Oracle services first, then internal middleware and identity systems. If you run any affected Oracle stack, treat this as an emergency patch cycle and assume exposed services are targetable immediately.

Critical Vulnerabilities

  • CVE-2026-60358: Oracle Access Manager auth engine takeover
    • Impact: Unauthenticated remote compromise over HTTP; full takeover possible.
    • Affected Systems: Oracle Fusion Middleware Access Manager 12.2.1.4.0, 14.1.2.1.0.
    • Immediate Action: Patch immediately and restrict HTTP exposure to trusted management networks.
    • Mitigation: Apply Oracle’s fix; if patching is delayed, remove external access and monitor authentication endpoints.
  • CVE-2026-60360: Oracle Unified Directory compromise over LDAP
    • Impact: Unauthenticated LDAP attacker can take over OUD.
    • Affected Systems: 12.2.1.4.0, 14.1.2.1.0.
    • Immediate Action: Patch now; isolate LDAP listeners.
    • Mitigation: Update immediately and limit LDAP exposure to approved clients.
  • CVE-2026-60365: WebLogic proxy plug-in compromise
    • Impact: Remote compromise via HTTP; sensitive data access and modification.
    • Affected Systems: WebLogic Server Proxy Plug-In 15.1.1.0.0.
    • Immediate Action: Patch and review any third-party web server integrations.
    • Mitigation: Deploy Oracle fix; remove unnecessary proxy plug-in exposure.
  • CVE-2026-47056: Oracle Data Integrator REST service takeover
    • Impact: Unauthenticated HTTP attacker can compromise ODI.
    • Affected Systems: 12.2.1.4.0, 14.1.2.0.0.
    • Immediate Action: Patch and disable public access to REST services.
    • Mitigation: Apply vendor update; restrict network reachability.
  • CVE-2026-60644: WebCenter Content Web Content Management takeover
    • Impact: Remote compromise over HTTP.
    • Affected Systems: 12.2.1.4.0, 14.1.2.0.0.
    • Immediate Action: Patch immediately and verify exposure.
    • Mitigation: Apply Oracle patch; block direct internet access.
  • CVE-2026-60389 / CVE-2026-60379: Service Delivery Platform compromise
    • Impact: Remote takeover via HTTP or SOAP.
    • Affected Systems: 12.2.1.4.0, 14.1.2.0.0.
    • Immediate Action: Patch all SDP instances and segment T3/SOAP traffic.
    • Mitigation: Apply fixes; restrict legacy middleware ports.
  • CVE-2026-60217: Oracle Coherence core takeover
    • Impact: Unauthenticated TCP attacker can compromise Coherence and adjacent systems.
    • Affected Systems: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0.
    • Immediate Action: Patch and isolate cluster traffic.
    • Mitigation: Update immediately; restrict Coherence ports to trusted nodes only.
  • CVE-2026-60429: Oracle Unified Directory low-privilege LDAP takeover
    • Impact: Low-privileged attacker can take over OUD.
    • Affected Systems: 12.2.1.4.0, 14.1.2.1.0.
    • Immediate Action: Patch and audit LDAP access.
    • Mitigation: Apply Oracle fix; tighten authentication and network ACLs.
  • CVE-2026-60627: JD Edwards EnterpriseOne Tools compromise
    • Impact: Low-privileged HTTP attacker can take over the product.
    • Affected Systems: 9.2.26.3.
    • Immediate Action: Patch urgently and restrict admin interfaces.
    • Mitigation: Apply vendor update; verify no public exposure.
  • CVE-2026-60377 / CVE-2026-60381 / CVE-2026-60375: SDP T3/IIOP takeover
    • Impact: Low-privileged remote compromise; one variant can cause partial DoS.
    • Affected Systems: 12.2.1.4.0, 14.1.2.0.0.
    • Immediate Action: Patch and block legacy middleware protocols.
    • Mitigation: Update immediately; restrict T3/IIOP to internal trust zones.
  • CVE-2026-60457 / CVE-2026-60459 / CVE-2026-60461: WebCenter Enterprise Capture compromise
    • Impact: Remote takeover via T3/IIOP or HTTP.
    • Affected Systems: 12.2.1.4.0, 14.1.2.0.0.
    • Immediate Action: Patch all capture services now.
    • Mitigation: Apply Oracle fixes and remove unnecessary listener exposure.

Additional high-risk items: Oracle WebCenter Portal, WebCenter Sites, SOA Suite, BI Publisher, HTTP Server, Identity Manager Connector, Access Manager, WebLogic Server, TimesTen Kubernetes Operator, Oracle Retail Integration Bus, Enterprise Manager Base Platform, Oracle Database Net Services, MySQL Connectors/Router/Server, and several third-party products all have critical or high-severity issues that should be queued immediately after the most exposed middleware.

Previously Alerted

What to Do Now

  1. Patch Oracle internet-facing systems first: Access Manager, WebLogic, Coherence, Unified Directory, WebCenter, SDP, ODI, Identity Manager, and HTTP/SOAP/T3/IIOP-exposed services.
  2. Shut down or firewall exposed middleware ports until fixes are applied. Treat LDAP, HTTP, HTTPS, SOAP, T3, IIOP, TCP, and HTTP/2 services as attack surface.
  3. Verify versions against Oracle advisories and confirm which instances are actually reachable from untrusted networks.
  4. Look for signs of compromise: new admin accounts, unexpected config changes, strange LDAP/SOAP/T3 traffic, and unexplained service crashes.
  5. Prioritize identity and directory systems because compromise there can cascade into multiple products.

Verification steps: inventory all Oracle Fusion Middleware, MySQL, JD Edwards, Enterprise Manager, and Retail deployments; map exposed ports; confirm patch status; and validate that compensating controls are active.

Monitoring recommendations: alert on authentication anomalies, unusual outbound LDAP/HTTP traffic, repeated SOAP/T3/IIOP requests, and changes to middleware configs, users, or certificates.

Related Resources

  • Internal: Upcoming deep-dive on Oracle Fusion Middleware emergency response and exposure reduction.
  • Official vendor advisories: Oracle Critical Patch Update and product-specific security alerts for Fusion Middleware, WebLogic, Coherence, MySQL, JD Edwards, and Enterprise Manager.

Keep reading