PatchSiren cyber security CVE debrief
CVE-2026-60566 Oracle Corporation CVE debrief
A critical vulnerability was discovered in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal, potentially leading to a complete takeover of the system. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Administrators and security teams should be aware of this critical vulnerability and take immediate action to mitigate the risk.
- Vendor
- Oracle Corporation
- Product
- Oracle WebCenter Portal
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Administrators and security teams responsible for Oracle WebCenter Portal installations should be aware of this critical vulnerability and take immediate action to mitigate the risk. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
The vulnerability, tracked as CVE-2026-60566, is located in the Runtime Tools component of Oracle WebCenter Portal. It has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks can result in takeover of Oracle WebCenter Portal.
Defensive priority
High
Recommended defensive actions
- Apply the latest security patches provided by Oracle.
- Restrict network access to Oracle WebCenter Portal.
- Monitor for suspicious activity.
- Perform regular vulnerability assessments.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-07-21T22:17:56.813Z and last modified on 2026-07-27T16:18:05.973Z. The NVD entry is currently Modified. This information is based on the supplied source corpus and may not reflect the current state of the vulnerability. Defenders should verify the affected scope and severity with the official advisory. The vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0.
Official resources
-
CVE-2026-60566 CVE record
CVE.org
-
CVE-2026-60566 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:56.813Z and has not been modified since then. The NVD entry is currently Modified.