External risk intelligence

Oracle Weblogic Server Proxy Plug-in Integrity Compromise

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60364

The vulnerability affects a WebLogic Server Proxy Plug-in, which is designed to sit at the network edge to facilitate communication between third-party web servers and Oracle Fusion Middleware. As an internet-facing gateway component, this plug-in is routinely exposed to the public internet to process HTTP traffic in standard deployment patterns.

Oracle Http Server

12.2.1.4.014.1.2.0.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Oracle's WebLogic Server Proxy Plug-in, a component used to manage traffic between web servers and Oracle Fusion Middleware. Its position at the network edge means it's accessible via the internet, and an attacker could potentially alter or delete critical data.

  • Unauthenticated attackers can alter or delete critical data.
  • This plug-in is often internet-facing, increasing exposure.
  • Confirm if this plug-in is in use and assess relevance.

Attack Path

How an attacker could exploit the issue

An attacker can target the Oracle WebLogic Server Proxy Plug-in by sending malicious HTTP requests over the network. This plug-in, often exposed at the network's edge, handles incoming traffic for Oracle Fusion Middleware. If successful, the attacker can gain control over critical data within the plug-in's scope.

  • Network access required.
  • Vulnerable proxy plug-in component.
  • Unauthorized data modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to modify or delete critical data within the Oracle WebLogic Server Proxy Plug-in. The attacker could achieve this by exploiting an easily exploitable weakness through HTTP, potentially impacting the integrity of data managed by the plug-in.

  • Critical data integrity.
  • Network access via HTTP.
  • Unauthorized data modification or deletion.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners and Infrastructure teams are most likely responsible for addressing this vulnerability, given its impact on the Oracle Weblogic Server Proxy Plug-in. The immediate first step should be to inventory all instances of the affected plug-in, assess their exposure to external networks, and identify business-critical systems that rely on them. This will allow for a risk-based prioritization of remediation efforts.

  • Infrastructure and Platform teams own the issue.
  • Verify external accessibility and business criticality.
  • Plan and execute remediation in maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Weblogic Server Proxy Plug-in?

This component acts as a bridge between third-party web servers and Oracle Fusion Middleware. It is installed on web servers to manage and route incoming traffic to the backend middleware, essentially functioning as a gateway to ensure smooth communication between external requests and internal Oracle services.

How does CVE-2026-60364 impact data?

This vulnerability represents an integrity-focused weakness. It allows an unauthorized actor to bypass security controls to modify, delete, or create critical data managed by the proxy plug-in. Rather than stealing information, the flaw enables the manipulation of data handled by the component, which could disrupt the accuracy or availability of business information.

Do I need to be logged in to trigger this bug?

No. The vulnerability is triggered by an unauthenticated attacker sending specifically crafted HTTP requests over the network. This means no user credentials or prior account access are required to attempt the attack. It is not triggered by internal administrative actions or local software operations, but rather by external network interaction.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this plug-in is often deployed at the network edge to handle public HTTP traffic, making it highly likely to be internet-facing. If your instance is exposed to the internet, it is a primary candidate for this type of attack, as it sits in the path where external traffic enters your infrastructure.

How should I respond to this vulnerability?

Start by identifying all servers running the Oracle Weblogic Server Proxy Plug-in in your environment. Determine which of these instances are accessible from the internet versus those on internal networks. Prioritize securing any internet-facing gateways first, and coordinate with your infrastructure team to plan a maintenance window for applying the necessary updates from Oracle.

References