External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60375

The vulnerability affects a Service Delivery Platform component reachable via T3 and IIOP protocols. Middleware platforms serving messaging and integration services are frequently deployed as network-accessible components within enterprise infrastructure to facilitate communication between distributed services, making them a common target for network-based access.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Fusion Middleware's Service Delivery Platform, affecting its messaging capabilities. This issue could allow an unauthenticated attacker with network access to gain complete control over the platform, potentially impacting critical business operations.

  • Unauthenticated network access can lead to full platform compromise.
  • This impacts core service delivery and integration functions.
  • Confirm relevance and exposure of affected platforms.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by reaching the Messaging Enabler component within Oracle Fusion Middleware's Service Delivery Platform over the network. No authentication is required, and the attacker can use protocols like T3 or IIOP to interact with the vulnerable component. Successful exploitation allows the attacker to take control of the Service Delivery Platform, impacting its confidentiality, integrity, and availability.

  • Network access is required.
  • Interaction with the Messaging Enabler triggers it.
  • Complete takeover of the platform is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to take over the Service Delivery Platform. Such an attack could impact the platform's availability, integrity, and confidentiality, potentially disrupting services that rely on it.

  • Service Delivery Platform could be compromised.
  • Attacker could gain network access.
  • Service disruption and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle Fusion Middleware's Service Delivery Platform component requires a coordinated response, likely involving infrastructure and platform teams responsible for Oracle environments. The initial focus should be on identifying all instances of the affected Service Delivery Platform, assessing their network exposure and business criticality, and pinpointing the accountable system owner. This groundwork will inform a risk-based remediation plan, potentially including coordination with Oracle for patches or configuration adjustments.

  • Platform and infrastructure teams own the resolution.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Fusion Middleware Service Delivery Platform?

It is a specialized software layer used by organizations to facilitate communication between distributed applications. The Messaging Enabler component specifically handles data exchange and integration tasks. Because it manages high-volume messaging services, it is often a central hub for backend infrastructure, meaning that any disruption to this platform can directly impact the core operational functions of an enterprise.

What does CVE-2026-60375 mean for system security?

This CVE identifies a critical weakness in the Messaging Enabler component. It allows an attacker to bypass authentication entirely to gain control of the platform. By exploiting this flaw, an unauthorized actor could potentially read sensitive data, modify system configurations, or render the platform unavailable, effectively compromising the integrity and operation of the Service Delivery Platform.

How can an attacker trigger this vulnerability?

An attacker initiates the attack by sending malicious requests to the Messaging Enabler using specific network protocols like T3 or IIOP. Crucially, the attacker does not need a valid username or password to interact with these protocols. This issue is not triggered by internal administrative actions or local software operations, but specifically by network-based communication targeting these messaging ports.

Is my instance affected by this CVE?

Halo Surface Signal indicates that because this platform relies on T3 and IIOP protocols for integration, it is frequently configured for network reachability. If your instance is accessible via the network, it is at higher risk. You should prioritize checking if your deployment is reachable from outside your immediate internal network, as this connectivity is the primary factor in how this vulnerability is accessed.

What should I do if I run this software?

Begin by identifying every instance of Oracle Fusion Middleware Service Delivery Platform within your infrastructure. Once identified, map out which systems are network-accessible and determine the business criticality of each. Coordinate with your infrastructure and platform teams to review official security updates from Oracle and plan a path forward for patching or configuration adjustments based on your risk assessment.

References