PatchSiren cyber security CVE debrief
CVE-2026-60335 Oracle Corporation CVE debrief
The CVE-2026-60335 vulnerability affects Oracle WebCenter Content, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This is an easily exploitable vulnerability that allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 7.2, indicating high severity. Users and administrators should prioritize patching and assess exposure. The NVD entry is currently Undergoing Analysis, and evidence is limited to vendor statements.
- Vendor
- Oracle Corporation
- Product
- Oracle WebCenter Content
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
Users of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching. Security teams and administrators managing Oracle products must assess exposure and apply mitigations. Vulnerability management and incident response teams should monitor for potential exploitation attempts. Operators of affected systems should review the official advisory and take necessary actions to protect their environments.
Technical summary
The vulnerability in Oracle WebCenter Content allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. The CVSS 3.1 Base Score is 7.2, with impacts on Confidentiality, Integrity, and Availability. Defenders should verify system configurations and apply patches when available.
Defensive priority
High privileged attackers with network access via HTTP can compromise Oracle WebCenter Content, potentially leading to takeover.
Recommended defensive actions
- Inventory and verify Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are not in use
- Apply vendor remediation when available
- Monitor for suspicious activity
- Implement compensating controls
- Exception tracking and retest
- Review relevant logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE is based on information from Oracle's security alert for July 2026. The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. Evidence is limited to vendor statements and may not reflect real-world attacks or exploits. Defenders should verify system configurations and apply patches when available. Additional information may be found in Oracle's official advisory.
Official resources
-
CVE-2026-60335 CVE record
CVE.org
-
CVE-2026-60335 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.587Z and has not been modified since then.