Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 7 sources · 6 days · First seen · Last updated
Oracle software security vulnerabilities and patching
Overview
Oracle has implemented a monthly patching cadence to address a rise in AI-driven vulnerability identification. In August 2026, the company released 943 security patches to address 925 unique Common Vulnerabilities and Exposures (CVEs), including 154 critical updates. Oracle noted that some customers have been compromised through known vulnerabilities that remained unpatched.
Concurrently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities (KEV) Catalog. Identified as CVE-2026-21962, the flaw carries a maximum CVSS score of 10.0 and involves improper access control that allows unauthenticated attackers to bypass authorization. Although Oracle released patches for this specific flaw in January 2026, reports indicate it is being actively exploited in the wild, prompting a mandate for Federal Civilian Executive Branch agencies to address it.
Entities
Timeline
-
20 days ago
[TECHNOLOGY] 5 sourcesOracle HTTP Server vulnerability added to CISA's KEV CatalogCISA has added a critical Oracle HTTP Server and WebLogic vulnerability (CVE-2026-21962) to its KEV Catalog following evidence of active exploitation by unauthenticated attackers.
-
26 days ago
[TECHNOLOGY] 3 sourcesOracle releases 943 security patches to address critical vulnerabilitiesOracle released 943 security patches in August 2026 to fix 925 unique vulnerabilities, including 154 critical issues across 23 product families like Fusion Middleware and PeopleSoft.
Sources
cinemagia.wordpress.com · cybernoz.com · de.tenable.com · globalsecuritymag.fr · ictnews.ir · invitehealth.substack.com · thehackernews.com