External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60374

The vulnerability affects a Service Delivery Platform component reachable via T3 and IIOP protocols. These protocols are commonly used for remote communication in middleware environments, and such platforms are frequently deployed as internet-facing or edge services to facilitate connectivity, making network exposure a common deployment characteristic.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts Oracle Fusion Middleware's Service Delivery Platform, potentially allowing an attacker to completely take over the system. The core concern is the ease of exploitation and the severe consequences, including full system compromise.

  • An unauthenticated attacker can gain full control.
  • It affects a critical platform used for service delivery.
  • Confirming exposure is the primary leadership action.

Attack Path

How an attacker could exploit the issue

An attacker could compromise the Service Delivery Platform by exploiting a vulnerability in its messaging component. This attack requires only network access, as the vulnerability can be triggered without any authentication. Successful exploitation allows the attacker to take complete control of the platform, impacting confidentiality, integrity, and availability.

  • Unauthenticated network access required.
  • Vulnerability in the messaging component.
  • Full platform takeover possible.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could potentially compromise the Service Delivery Platform, leading to a complete takeover. This vulnerability impacts confidentiality, integrity, and availability of the platform.

  • Service Delivery Platform data and functions.
  • Attacker exploits network access via T3, IIOP.
  • Complete takeover of the platform.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform requires immediate attention from infrastructure and platform teams, who are likely responsible for its management. The first practical step is to confirm the presence and business criticality of the affected technology, identify the accountable owner, and then plan remediation based on the identified risk.

  • Infrastructure and platform teams own this.
  • Verify network reachability and business criticality.
  • Plan coordinated remediation and vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Fusion Middleware Service Delivery Platform?

It is a specialized middleware component designed to handle complex messaging and service communication. Organizations use it to manage, route, and deliver data across distributed software environments, acting as a central hub for backend systems to exchange information reliably.

How should I understand the security weakness in CVE-2026-60374?

This vulnerability is a flaw in the system's messaging component that lacks proper authorization checks. In technical terms, it allows an unauthenticated party to interact with the platform as if they were a trusted administrator, granting them full control over the software's operations, data, and underlying functions.

Do I need to worry if my system is not exposed to the internet?

While the vulnerability specifically requires network access via the T3 or IIOP protocols, internal network reachability is often enough for an attacker. It is not limited to internet-facing systems; anyone with access to your internal network who can communicate with these specific protocols can trigger the issue.

Why is this CVE considered relevant to my network perimeter?

According to Halo Surface Signal, this vulnerability is particularly significant because the affected Messaging Enabler component relies on T3 and IIOP protocols. These are often used for broad remote communication, and because such platforms are frequently placed at the edge of a network to bridge services, they are often reachable from wider network segments.

When should I take action on CVE-2026-60374?

You should prioritize assessing this immediately, as the potential impact includes a complete system takeover. First, locate where your organization runs Oracle Fusion Middleware 12.2.1.4.0 or 14.1.2.0.0. Once identified, coordinate with your infrastructure team to verify the platform's network visibility and prepare for vendor-supplied updates.

References