CVE-2026-60358 – Oracle
“Twelve doors, one master key: when every lock reads 9.9 or higher, the enterprise isn't choosing whether to patch, only how fast.”
Oracle has released fixes for twelve critical vulnerabilities spanning its product line, all requiring urgent attention. Nine carry the maximum CVSS score of 10.0, Critical severity: CVE-2026-47056 (Oracle Data Integrator), CVE-2026-60217 (Oracle Coherence), CVE-2026-60358 (Oracle Access Manager), CVE-2026-60360 (Oracle Unified Directory), CVE-2026-60365 (Oracle HTTP Server), CVE-2026-60366 (Oracle Platform Security for Java), CVE-2026-60379 and CVE-2026-60389 (Service Delivery Platform), and CVE-2026-60644 (Oracle WebCenter Content). Three more carry a CVSS score of 9.9, Critical severity: CVE-2026-61211 (Oracle Database Server), CVE-2026-60402 (TimesTen In-Memory Database), and CVE-2026-61146 (Oracle Commerce Guided Search / Oracle Commerce Experience Manager).
The breadth of affected products, from identity and directory services to databases and content management, means this update touches core enterprise infrastructure. Teams running any of these Oracle products should prioritize patching without delay.
Key Details
- Affected Product
- Oracle Access Manager
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-284