THREAT OPS › Threat News
Threat Intelligence News
11757 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-70955 (HIGH 7.5) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segnvd · 2026-08-18
- [NVD] CVE-2026-70954 (CRITICAL 9.8) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracnvd · 2026-08-18
- [NVD] CVE-2026-70953 (CRITICAL 9.8) — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oraclnvd · 2026-08-18
- [NVD] CVE-2026-70944 (HIGH 8.8) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70943 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segmennvd · 2026-08-18
- [NVD] CVE-2026-70942 (HIGH 7.7) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70941 (HIGH 8.8) — Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payrollnvd · 2026-08-18
- [NVD] CVE-2026-70940 (HIGH 8.8) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70939 (HIGH 7.2) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oraclnvd · 2026-08-18
- [NVD] CVE-2026-70938 (MEDIUM 6.5) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70937 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracnvd · 2026-08-18
- [NVD] CVE-2026-70936 (HIGH 7.1) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hypnvd · 2026-08-18
- [NVD] CVE-2026-70932 (HIGH 7.2) — Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure whenvd · 2026-08-18
- [NVD] CVE-2026-70931 (HIGH 8.1) — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise nvd · 2026-08-18
- [NVD] CVE-2026-70930 (HIGH 7.5) — Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to comprnvd · 2026-08-18
- [NVD] CVE-2026-70929 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70928 (HIGH 8.8) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70927 (HIGH 7.5) — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromisenvd · 2026-08-18
- [NVD] CVE-2026-70926 (CRITICAL 9.8) — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromisenvd · 2026-08-18
- [NVD] CVE-2026-70925 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70924 (HIGH 8.1) — Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access vinvd · 2026-08-18
- [NVD] CVE-2026-70923 (MEDIUM 6.1) — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successfunvd · 2026-08-18
- [NVD] CVE-2026-70922 (HIGH 8.8) — Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with nnvd · 2026-08-18
- [NVD] CVE-2026-70921 (CRITICAL 10.0) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oraclenvd · 2026-08-18
- [NVD] CVE-2026-70920 (CRITICAL 9.9) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70919 (LOW 2.5) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70918 (HIGH 8.8) — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Produnvd · 2026-08-18
- [NVD] CVE-2026-70917 (MEDIUM 4.0) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hynvd · 2026-08-18
- [NVD] CVE-2026-70916 (MEDIUM 4.0) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hynvd · 2026-08-18
- [NVD] CVE-2026-70914 (HIGH 7.0) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle nvd · 2026-08-18
- [NVD] CVE-2026-70912 (MEDIUM 5.3) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hnvd · 2026-08-18
- [NVD] CVE-2026-70911 (MEDIUM 5.3) — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclnvd · 2026-08-18
- [NVD] CVE-2026-70910 (HIGH 7.5) — Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration. Sunvd · 2026-08-18
- [NVD] CVE-2026-70908 (HIGH 7.5) — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successfunvd · 2026-08-18
- [NVD] CVE-2026-70906 (HIGH 7.5) — Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attnvd · 2026-08-18
- [NVD] CVE-2026-70905 (CRITICAL 9.8) — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML tonvd · 2026-08-18
- [NVD] CVE-2026-70904 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical cnvd · 2026-08-18
- [NVD] CVE-2026-70903 (HIGH 8.7) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS nvd · 2026-08-18
- [NVD] CVE-2026-70902 (HIGH 7.1) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructunvd · 2026-08-18
- [NVD] CVE-2026-70901 (HIGH 8.1) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP nvd · 2026-08-18
- [NVD] CVE-2026-70900 (HIGH 8.7) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTnvd · 2026-08-18
- [NVD] CVE-2026-70899 (HIGH 8.8) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP tnvd · 2026-08-18
- [NVD] CVE-2026-70898 (HIGH 7.4) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTnvd · 2026-08-18
- [NVD] CVE-2026-70897 (HIGH 8.2) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPSnvd · 2026-08-18
- [NVD] CVE-2026-70896 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP nvd · 2026-08-18
- [NVD] CVE-2026-70895 (MEDIUM 6.5) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructunvd · 2026-08-18
- [NVD] CVE-2026-70894 (HIGH 7.7) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructnvd · 2026-08-18
- [NVD] CVE-2026-70893 (HIGH 8.2) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL nvd · 2026-08-18
- [NVD] CVE-2026-70892 (HIGH 8.2) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPnvd · 2026-08-18
- [NVD] CVE-2026-70891 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP nvd · 2026-08-18
- [NVD] CVE-2026-70890 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP nvd · 2026-08-18
- [NVD] CVE-2026-70889 (HIGH 7.5) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP nvd · 2026-08-18
- [NVD] CVE-2026-70888 (MEDIUM 6.6) — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTnvd · 2026-08-18
- [NVD] CVE-2026-70852 (HIGH 8.2) — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oraclnvd · 2026-08-18
- [NVD] CVE-2026-70846 (CRITICAL 9.6) — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oraclenvd · 2026-08-18
- [GHSA] GHSA-hfg8-hc9c-6c3h (high) — moby/go-archive: Crafted tar archive can write outside the extraction directorygithub_advisories · 2026-08-18
- [NVD] CVE-2026-70737 (HIGH 8.8) — Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with nenvd · 2026-08-18
- [GHSA] GHSA-7gww-x7fh-jf9j (high) — LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig pagegithub_advisories · 2026-08-18
- [GHSA] GHSA-7cj5-v4pp-v632 (medium) — LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated usersgithub_advisories · 2026-08-18
- [NVD] CVE-2026-62988 (CRITICAL 9.0) — Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and lib/Froxlornvd · 2026-08-18
- [GHSA] GHSA-jf24-8g2h-2wg7 (medium) — LibreNMS Vulnerable to Remote Code Execution via AboutControllergithub_advisories · 2026-08-18
- [NVD] CVE-2026-61308 (MEDIUM 6.8) — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17nvd · 2026-08-18
- [NVD] CVE-2026-61268 (HIGH 8.1) — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compnvd · 2026-08-18
- [NVD] CVE-2026-61206 (CRITICAL 9.9) — Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle nvd · 2026-08-18
- [NVD] CVE-2026-61198 (MEDIUM 6.5) — Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comprominvd · 2026-08-18
- [NVD] CVE-2026-61034 (CRITICAL 9.1) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to comnvd · 2026-08-18
- [NVD] CVE-2026-61032 (HIGH 8.8) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compnvd · 2026-08-18
- [NVD] CVE-2026-61029 (CRITICAL 9.0) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to cnvd · 2026-08-18
- [NVD] CVE-2026-61022 (HIGH 8.8) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compnvd · 2026-08-18
- [NVD] CVE-2026-61021 (CRITICAL 9.9) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compnvd · 2026-08-18
- [NVD] CVE-2026-61018 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comnvd · 2026-08-18
- [NVD] CVE-2026-61017 (HIGH 8.8) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compnvd · 2026-08-18
- [NVD] CVE-2026-61008 (CRITICAL 9.1) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comnvd · 2026-08-18
- [NVD] CVE-2026-61007 (HIGH 7.5) — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comnvd · 2026-08-18
- [NVD] CVE-2026-60995 (CRITICAL 9.9) — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to comprnvd · 2026-08-18
- [NVD] CVE-2026-60977 (CRITICAL 9.8) — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network accessnvd · 2026-08-18
- [NVD] CVE-2026-60970 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60969 (HIGH 7.7) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromisnvd · 2026-08-18
- [NVD] CVE-2026-60958 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60947 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60946 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60921 (CRITICAL 9.8) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60916 (CRITICAL 9.9) — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via nvd · 2026-08-18
- [NVD] CVE-2026-60914 (HIGH 7.5) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to comprominvd · 2026-08-18
- [NVD] CVE-2026-60895 (MEDIUM 6.8) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromnvd · 2026-08-18
- [NVD] CVE-2026-60866 (MEDIUM 6.5) — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Snvd · 2026-08-18
- [NVD] CVE-2026-60865 (MEDIUM 6.8) — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP tnvd · 2026-08-18
- [NVD] CVE-2026-60861 (CRITICAL 9.6) — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle nvd · 2026-08-18
- [NVD] CVE-2026-60860 (HIGH 8.7) — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP nvd · 2026-08-18
- [NVD] CVE-2026-60853 (LOW 3.7) — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successnvd · 2026-08-18
- [NVD] CVE-2026-60850 (HIGH 7.5) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to comprominvd · 2026-08-18
- [NVD] CVE-2026-60841 (HIGH 8.5) — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromnvd · 2026-08-18
- [NVD] CVE-2026-60830 (MEDIUM 6.5) — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Sunvd · 2026-08-18
- [NVD] CVE-2026-60822 (HIGH 7.8) — Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastrunvd · 2026-08-18
- [NVD] CVE-2026-60808 (HIGH 7.5) — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Marknvd · 2026-08-18
- [NVD] CVE-2026-60803 (HIGH 7.4) — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Markenvd · 2026-08-18
- [NVD] CVE-2026-60769 (HIGH 7.5) — Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Onvd · 2026-08-18
- [NVD] CVE-2026-60753 (HIGH 7.8) — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment exenvd · 2026-08-18
- [NVD] CVE-2026-60720 (CRITICAL 9.9) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to comprnvd · 2026-08-18
- [NVD] CVE-2026-60707 (HIGH 8.7) — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromisnvd · 2026-08-18