PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60335 Oracle Corporation CVE debrief

The CVE-2026-60335 vulnerability affects Oracle WebCenter Content, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This is an easily exploitable vulnerability that allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 7.2, indicating high severity. Users and administrators should prioritize patching and assess exposure. The NVD entry is currently Undergoing Analysis, and evidence is limited to vendor statements.

Vendor
Oracle Corporation
Product
Oracle WebCenter Content
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-28
Advisory published
2026-07-21
Advisory updated
2026-07-28

Who should care

Users of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching. Security teams and administrators managing Oracle products must assess exposure and apply mitigations. Vulnerability management and incident response teams should monitor for potential exploitation attempts. Operators of affected systems should review the official advisory and take necessary actions to protect their environments.

Technical summary

The vulnerability in Oracle WebCenter Content allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. The CVSS 3.1 Base Score is 7.2, with impacts on Confidentiality, Integrity, and Availability. Defenders should verify system configurations and apply patches when available.

Defensive priority

High privileged attackers with network access via HTTP can compromise Oracle WebCenter Content, potentially leading to takeover.

Recommended defensive actions

  • Inventory and verify Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are not in use
  • Apply vendor remediation when available
  • Monitor for suspicious activity
  • Implement compensating controls
  • Exception tracking and retest
  • Review relevant logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE is based on information from Oracle's security alert for July 2026. The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. Evidence is limited to vendor statements and may not reflect real-world attacks or exploits. Defenders should verify system configurations and apply patches when available. Additional information may be found in Oracle's official advisory.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.587Z and has not been modified since then.