CVE-2026-60365
Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-60365 is a critical missing authentication vulnerability in the Oracle WebLogic Server Proxy Plug-in (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers), part of Oracle Fusion Middleware. The vulnerability affects version 15.1.1.0.0 of the Oracle WebLogic Server Proxy Plug-in, as well as Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0. It was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update, which addressed 1,449 security patches across 334 products. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its unauthenticated, network-exploitable, scope-changing nature (Oracle CPU Jul 2026, Feedly).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function), meaning the WebLogic Server Proxy Plug-in exposes critical functionality over HTTP without requiring any authentication. An unauthenticated remote attacker with network access can send crafted HTTP requests to exploit this flaw, requiring no user interaction and no special privileges. The vulnerability has a changed scope, indicating that successful exploitation can affect components beyond the plug-in itself — such as backend WebLogic servers or other connected Oracle Fusion Middleware products. No detailed technical write-up or public proof-of-concept code has been identified at this time (Oracle CPU Jul 2026, Feedly).

Impact

Successful exploitation allows an unauthenticated attacker to perform unauthorized creation, deletion, or modification of critical data accessible to the Oracle WebLogic Server Proxy Plug-in, as well as gain complete read access to all data accessible through the plug-in. The changed scope means attacks can significantly impact additional products beyond the plug-in itself, potentially enabling lateral movement to backend WebLogic application servers and other connected Oracle Fusion Middleware components. Confidentiality and integrity impacts are both rated High; availability is not directly impacted by this vulnerability (Oracle CPU Jul 2026, Feedly).

Exploitability

The vulnerability is rated as "easily exploitable" by Oracle, requiring no authentication, no user interaction, and only network access via HTTP. As of the time of reporting, there is no evidence of a public proof-of-concept or active in-the-wild exploitation; the NVD SSVC assessment also indicates exploitation status as "none" (Feedly). The EPSS score is approximately 0.398%, reflecting a currently low but non-trivial probability of exploitation in the near term. The vulnerability has been detected by Tenable Nessus plugins 329199 and 329200, and it does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Oracle CPU Jul 2026, Feedly).

Mitigation and workarounds

Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update (CPU). Organizations should apply the relevant patches for Oracle WebLogic Server Proxy Plug-in version 15.1.1.0.0 and Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0 immediately. As a temporary workaround prior to patching, Oracle recommends restricting network access to the affected plug-in to only trusted sources, implementing network segmentation, and deploying WAF rules to limit exposure to HTTP-based attacks. Oracle strongly advises against relying on network-level mitigations as a long-term solution and urges customers to apply patches without delay (Oracle CPU Jul 2026, Feedly).

Community reactions

Oracle's July 2026 CPU was widely noted in the security community as a record-breaking patch release, containing 1,449 patches across 334 products. CVE-2026-60365 was highlighted by multiple threat intelligence outlets due to its perfect CVSS 10.0 score and unauthenticated exploitability. Coverage appeared in sources including SOCRadar, SecurityOnline, The Hacker News weekly recap, Suriq.io, BeyondMachines, and Indusface, all emphasizing the severity of the unauthenticated RCE-class vulnerabilities in Oracle Fusion Middleware products released in this CPU (SOCRadar, Suriq.io, The Hacker News).

Additional resources


SourceThis report was generated using AI

Related Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60365CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2026-21962CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
YesNoJan 20, 2026
CVE-2026-60364CRITICAL9.8
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoYesJul 21, 2026
CVE-2020-35169CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022
CVE-2020-35168CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management