
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60365 is a critical unauthenticated remote vulnerability in the Oracle WebLogic Server Proxy Plug-In for Third-Party Web Servers, a component of Oracle Fusion Middleware. The affected version is Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0; Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0 are also listed as affected products. The vulnerability was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update (CPU). It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its network-accessible, zero-authentication, low-complexity attack profile with a scope change (Oracle CPU Jul 2026, EUVD).
The vulnerability resides in the WebLogic Server Proxy Plug-In component used with third-party web servers (e.g., Apache HTTP Server or Oracle HTTP Server), which acts as a reverse proxy forwarding requests to WebLogic backends. The root cause is not fully disclosed by Oracle, but the vulnerability is classified as easily exploitable via HTTP with no authentication or user interaction required (CWE details not yet published). The scope change (S:C) in the CVSS vector indicates that a successful attack on the plug-in can cascade to impact additional products beyond the plug-in itself — likely the backend WebLogic Server or connected application tiers. No public technical write-up or proof-of-concept code has been identified at this time (Oracle CPU Jul 2026, Suriq Blog).
Successful exploitation allows an unauthenticated remote attacker to achieve unauthorized creation, deletion, or modification of critical data accessible to the proxy plug-in, as well as complete read access to all data handled by the component. The scope change means attacks can significantly impact additional connected products, such as backend WebLogic Server instances or downstream application data stores, enabling potential lateral movement within the environment. Confidentiality and integrity are both rated High; availability is not directly impacted by this vulnerability (Oracle CPU Jul 2026).
Oracle has addressed this vulnerability in the July 2026 Critical Patch Update. Organizations should apply the CPU patches immediately for Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0, Oracle HTTP Server 12.2.1.4.0, and 14.1.2.0.0. As a temporary workaround prior to patching, Oracle recommends blocking network access to the affected proxy plug-in endpoints at the network perimeter, restricting HTTP access to trusted IP ranges only, and implementing network segmentation to limit exposure. Oracle strongly cautions that workarounds do not correct the underlying vulnerability and patching remains the only definitive remediation (Oracle CPU Jul 2026).
The Suriq security blog highlighted CVE-2026-60365 in the context of Oracle's July 2026 CPU, noting it as one of the most severe unauthenticated remote vulnerabilities in the release alongside similar issues in Oracle Coherence (Suriq Blog). The broader security community has noted the significance of the CVSS 10.0 score and the scope change, which indicates risk to systems beyond the directly affected component. No major vendor statements beyond Oracle's advisory or notable researcher attribution have been published at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."