External risk intelligence

Oracle Fusion Middleware Service Delivery Platform Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60387

The vulnerability affects a Service Delivery Platform, which is typically deployed as a centralized infrastructure component. It is reachable via T3 and IIOP protocols, which are standard for middleware communication in networked environments, making it a common target for external network access in enterprise service architectures.

Missing Authentication

Oracle Service Delivery Platform

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Fusion Middleware's Service Delivery Platform, potentially allowing attackers to completely take over the system through network access.

  • Unauthenticated attackers could control the platform.
  • This affects core service delivery infrastructure.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can compromise the Service Delivery Platform by accessing it over the network using T3 or IIOP protocols. This vulnerability in Oracle Fusion Middleware's Messaging Enabler component can lead to a complete takeover of the platform.

  • Network access required.
  • Vulnerable messaging component.
  • Full platform takeover risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Fusion Middleware's Service Delivery Platform could allow an attacker to completely take over the platform when supported. This could impact the availability and integrity of services managed by the platform.

  • Service Delivery Platform takeover.
  • Exploited via network access to T3/IIOP.
  • Compromises service availability and integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Fusion Middleware Service Delivery Platform is likely owned by platform or infrastructure teams responsible for core middleware services. The first step is to inventory all instances of this platform, confirm network exposure, and identify the specific application or service owners accountable for each instance. Remediation planning should then prioritize based on business criticality and exposure.

  • Platform/Infrastructure teams own this.
  • Verify all Service Delivery Platform instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Oracle Fusion Middleware Service Delivery Platform?

It is a specialized infrastructure component within the Oracle Fusion Middleware suite designed to facilitate communication and data exchange between different services. The affected component, Messaging Enabler, manages message processing within this platform. Organizations rely on this software to orchestrate service delivery and enable interoperability across complex, enterprise-grade application environments.

What does CVE-2026-60387 mean for system security?

This vulnerability represents a critical flaw that allows an unauthorized party to gain full control over the Messaging Enabler component. When exploited, the attacker can compromise the confidentiality, integrity, and availability of the platform. Essentially, this creates a path for a complete system takeover, meaning the platform can no longer be trusted to handle data or service requests securely.

How is this vulnerability triggered?

An attacker triggers this bug by sending specially crafted network requests to the Messaging Enabler component using the T3 or IIOP protocols. Crucially, the attacker does not need a username or password to initiate this process. The vulnerability is not triggered by local user actions, nor is it dependent on specific user permissions; it is strictly an issue of remote network interaction.

Is my instance of this software at risk?

According to Halo Surface Signal, this software is often deployed as a centralized infrastructure component, making it a high-value target. Because it is reachable via T3 and IIOP protocols—standard communication methods in many networked environments—it is categorized as having an external attack surface. If your installation allows network-level access, it should be treated as potentially reachable by outside threats.

How should I respond to CVE-2026-60387?

Begin by auditing your environment to locate all running instances of the affected Service Delivery Platform versions. Coordinate with your platform and infrastructure teams to map these instances to their respective service owners. Once identified, evaluate the network accessibility of each deployment and prioritize your patching or mitigation efforts based on the criticality of the services the platform supports.

References