Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-60537: Oracle Managed File Transfer takeover via HTTP

CVE-2026-60537
Summary

The Oracle Managed File Transfer product in Oracle Fusion Middleware has a security weakness that could allow an attacker to take control of the system. This is a serious issue because it could impact not just this product, but potentially others as well. To protect your systems, update to a fixed version of Oracle Managed File Transfer as soon as possible.

Original title
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily e...
Original description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 9.9
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026