External risk intelligence

Oracle Managed File Transfer MFT Runtime Server Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60547

Oracle Managed File Transfer is designed to facilitate data exchange across network boundaries. As an integration and transfer service, it is commonly deployed in roles that require network-accessible endpoints for file transmission, making it a likely candidate for exposure in enterprise network architectures.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Oracle Managed File Transfer, a product used for exchanging files across networks. While the issue is within this specific product, a successful attack could potentially impact other connected systems. The vulnerability is considered critical due to its potential for a complete takeover of the affected service.

  • An attacker can take over a file transfer system.
  • High impact to connected systems is possible.
  • Confirm if this system is in use.

Attack Path

How an attacker could exploit the issue

An attacker with network access could target the Oracle Managed File Transfer's MFT Runtime Server component. This vulnerability, accessible via HTTP and requiring only low privileges, could lead to a complete takeover of the Oracle Managed File Transfer system, potentially impacting other integrated products.

  • Network access required, low privileges sufficient.
  • HTTP accessible MFT Runtime Server component.
  • Full takeover of file transfer system.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Oracle Managed File Transfer could allow a low-privileged attacker with network access to take over the service. Successful exploitation could lead to significant impacts on additional products due to the service's role in data exchange across network boundaries.

  • Oracle Managed File Transfer service.
  • Network access via HTTP.
  • Takeover of the service.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle Managed File Transfer product is likely managed by the application owner, with infrastructure and security teams involved in securing its network access. The first step is to locate all instances of Oracle Managed File Transfer, assess their network exposure, and identify the business-critical systems and their accountable owners to prioritize remediation efforts.

  • Application owners should own the issue.
  • Verify network exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Managed File Transfer?

Oracle Managed File Transfer (MFT) is a specialized component within Oracle Fusion Middleware designed to automate, secure, and monitor the exchange of files between different enterprise applications and systems. It acts as a central integration hub for data movement across an organization's network, ensuring that files are transmitted reliably between endpoints.

What does CVE-2026-60547 mean for the MFT Runtime Server?

This vulnerability is a critical weakness that allows an unauthorized user to gain complete control over the MFT Runtime Server. In security terms, this is a high-severity flaw that compromises the confidentiality, integrity, and availability of the service. Because it allows a full system takeover, an attacker could potentially manipulate or steal the sensitive data being processed by the transfer service.

How is this vulnerability triggered by an attacker?

An attacker triggers this bug by sending specific requests over HTTP to the MFT Runtime Server. The vulnerability is exploitable by someone with low-level access to the network; it does not require administrative privileges to initiate the attack. However, simply having network access is not enough if the service is not reachable; the vulnerability is only relevant when the server is configured to accept HTTP traffic from the network path used by the attacker.

Is my Oracle Managed File Transfer instance at risk?

According to Halo Surface Signal, Oracle Managed File Transfer is frequently deployed as an integration service with network-accessible endpoints, making it a likely candidate for external exposure. You should consider your instance at risk if it is configured to accept HTTP connections across network boundaries. Systems that are reachable from the internet or other untrusted network segments are at the highest level of concern.

How do I respond to this threat?

Begin by creating an inventory of all Oracle Managed File Transfer instances currently running in your environment. Confirm which versions you are using, as 12.2.1.4.0 and 14.1.2.0.0 are affected. Once located, work with your infrastructure teams to restrict network access to these servers where possible and coordinate with the accountable application owners to prioritize applying the official security updates provided by Oracle.

References