Security Advisories
150 advisoriesCVE-2026-35280
2026-08-28
Critical Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-35280)
A critical vulnerability (CVE-2026-35280) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware platforms.
Read full advisory →CVE-2026-35313
2026-08-28
Critical Vulnerability in Oracle Access Manager (CVE-2026-35313)
A critical vulnerability in Oracle Access Manager allows low-privileged attackers to take over the system via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. CVSS score 9.9, requiring immediate mitigation.
Read full advisory →CVE-2026-81096
2026-08-28
Critical Vulnerability in ToolUniverse Allows Remote Code Execution (CVE-2026-81096)
A critical vulnerability in ToolUniverse's python_executor_tool allows unauthenticated remote code execution. Attackers can exploit this to execute arbitrary code on the server, posing a severe security risk.
Read full advisory →CVE-2026-81735
2026-08-28
Critical Vulnerability in MCP HTTP Server Allows Unauthenticated Access (CVE-2026-81735)
A critical vulnerability in multiple UI-TARS components allows unauthenticated access to sensitive functions. Affected software includes mcp-http-server, ui-tars-desktop, and related libraries. Immediate patching is required to prevent exploitation.
Read full advisory →CVE-2026-22306
2026-08-28
Critical Vulnerability in Ozols Grupa OZOLS (CVE-2026-22306)
A critical vulnerability (CVE-2026-22306) allows attackers to execute arbitrary code via untrusted updates in Ozols Grupa OZOLS, affecting versions before 1.1.1233. CVSS score: 10.0.
Read full advisory →CVE-2026-35283
2026-08-26
Critical Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-35283)
A critical vulnerability (CVE-2026-35283) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0 of the Oracle Fusion Middleware platform.
Read full advisory →CVE-2026-35285
2026-08-26
Critical Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-35285)
A critical vulnerability (CVE-2026-35285) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. CVSS score: 9.9.
Read full advisory →CVE-2026-35316
2026-08-26
Critical Vulnerability in Oracle WebCenter Content (CVE-2026-35316)
A critical vulnerability in Oracle WebCenter Content allows low-privileged attackers to take over the system via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. CVSS score 9.9 indicates high risk.
Read full advisory →CVE-2026-46765
2026-08-26
Critical Vulnerability in Oracle WebCenter Portal (CVE-2026-46765)
A critical vulnerability (CVE-2026-46765) allows low-privileged attackers to take over Oracle WebCenter Portal via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. CVSS score 9.9, requiring immediate mitigation.
Read full advisory →CVE-2026-46779
2026-08-26
Critical Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-46779)
A critical vulnerability (CVE-2026-46779) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Immediate patching is required to prevent exploitation.
Read full advisory →CVE-2026-46802
2026-08-25
Critical Vulnerability in Oracle WebCenter Portal (CVE-2026-46802)
A critical vulnerability (CVE-2026-46802) allows low-privileged attackers to take over Oracle WebCenter Portal via HTTP. Affects versions 12.2.1.4.0 and 14.1.2.0.0. CVSS 9.9. Immediate patching required.
Read full advisory →CVE-2026-46814
2026-08-25
Critical Vulnerability in Oracle WebCenter Portal (CVE-2026-46814)
A critical vulnerability in Oracle WebCenter Portal allows low-privileged attackers to take over the system via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Immediate mitigation is required to prevent unauthorized access and system compromise.
Read full advisory →Get These Delivered to Your Inbox
Subscribe to receive advisories as soon as they are published — filtered to your environment.