PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60566 Oracle Corporation CVE debrief

A critical vulnerability was discovered in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal, potentially leading to a complete takeover of the system. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Administrators and security teams should be aware of this critical vulnerability and take immediate action to mitigate the risk.

Vendor
Oracle Corporation
Product
Oracle WebCenter Portal
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Administrators and security teams responsible for Oracle WebCenter Portal installations should be aware of this critical vulnerability and take immediate action to mitigate the risk. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The vulnerability, tracked as CVE-2026-60566, is located in the Runtime Tools component of Oracle WebCenter Portal. It has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks can result in takeover of Oracle WebCenter Portal.

Defensive priority

High

Recommended defensive actions

  • Apply the latest security patches provided by Oracle.
  • Restrict network access to Oracle WebCenter Portal.
  • Monitor for suspicious activity.
  • Perform regular vulnerability assessments.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-07-21T22:17:56.813Z and last modified on 2026-07-27T16:18:05.973Z. The NVD entry is currently Modified. This information is based on the supplied source corpus and may not reflect the current state of the vulnerability. Defenders should verify the affected scope and severity with the official advisory. The vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:56.813Z and has not been modified since then. The NVD entry is currently Modified.