CVE-2026-60365
Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-60365 is a critical unauthenticated remote vulnerability in the Oracle WebLogic Server Proxy Plug-In for Third-Party Web Servers, a component of Oracle Fusion Middleware. The affected version is Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0; Oracle HTTP Server versions 12.2.1.4.0 and 14.1.2.0.0 are also listed as affected products. The vulnerability was published on July 21, 2026, as part of Oracle's July 2026 Critical Patch Update (CPU). It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its network-accessible, zero-authentication, low-complexity attack profile with a scope change (Oracle CPU Jul 2026, EUVD).

Technical details

The vulnerability resides in the WebLogic Server Proxy Plug-In component used with third-party web servers (e.g., Apache HTTP Server or Oracle HTTP Server), which acts as a reverse proxy forwarding requests to WebLogic backends. The root cause is not fully disclosed by Oracle, but the vulnerability is classified as easily exploitable via HTTP with no authentication or user interaction required (CWE details not yet published). The scope change (S:C) in the CVSS vector indicates that a successful attack on the plug-in can cascade to impact additional products beyond the plug-in itself — likely the backend WebLogic Server or connected application tiers. No public technical write-up or proof-of-concept code has been identified at this time (Oracle CPU Jul 2026, Suriq Blog).

Impact

Successful exploitation allows an unauthenticated remote attacker to achieve unauthorized creation, deletion, or modification of critical data accessible to the proxy plug-in, as well as complete read access to all data handled by the component. The scope change means attacks can significantly impact additional connected products, such as backend WebLogic Server instances or downstream application data stores, enabling potential lateral movement within the environment. Confidentiality and integrity are both rated High; availability is not directly impacted by this vulnerability (Oracle CPU Jul 2026).

Mitigation and workarounds

Oracle has addressed this vulnerability in the July 2026 Critical Patch Update. Organizations should apply the CPU patches immediately for Oracle WebLogic Server Proxy Plug-in 15.1.1.0.0, Oracle HTTP Server 12.2.1.4.0, and 14.1.2.0.0. As a temporary workaround prior to patching, Oracle recommends blocking network access to the affected proxy plug-in endpoints at the network perimeter, restricting HTTP access to trusted IP ranges only, and implementing network segmentation to limit exposure. Oracle strongly cautions that workarounds do not correct the underlying vulnerability and patching remains the only definitive remediation (Oracle CPU Jul 2026).

Community reactions

The Suriq security blog highlighted CVE-2026-60365 in the context of Oracle's July 2026 CPU, noting it as one of the most severe unauthenticated remote vulnerabilities in the release alongside similar issues in Oracle Coherence (Suriq Blog). The broader security community has noted the significance of the CVSS 10.0 score and the scope change, which indicates risk to systems beyond the directly affected component. No major vendor statements beyond Oracle's advisory or notable researcher attribution have been published at this time.

Additional resources


SourceThis report was generated using AI

Related Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60365CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2026-21962CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJan 20, 2026
CVE-2026-60364CRITICAL9.8
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2020-35169CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022
CVE-2020-35168CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management