Security Advisories
150 advisoriesCVE-2026-46893
2026-08-25
Critical Remote Code Execution Vulnerability in JD Edwards EnterpriseOne General Ledger (CVE-2026-46893)
A critical vulnerability (CVE-2026-46893) allows low-privileged attackers to take over JD Edwards EnterpriseOne General Ledger via SMB. CVSS 9.9. Affected versions: 9.2. Immediate patching required.
Read full advisory →CVE-2026-46963
2026-08-25
Critical Vulnerability in Oracle Universal Work Queue (CVE-2026-46963)
A critical vulnerability (CVE-2026-46963) affects Oracle Universal Work Queue and Oracle E-Business Suite, allowing low-privileged attackers to take over the system via HTTP. CVSS 9.9. Patch immediately.
Read full advisory →CVE-2026-44789
2026-08-25
Critical Vulnerability in n8n Allows Remote Code Execution via Prototype Pollution (CVE-2026-44789)
A critical vulnerability in n8n (CVE-2026-44789) allows authenticated users to achieve global prototype pollution through an unvalidated pagination parameter, potentially leading to RCE. Affected versions are prior to 1.123.43, 2.22.1, and 2.20.7.
Read full advisory →CVE-2026-35323
2026-08-24
Critical Vulnerability in Oracle WebCenter Content (CVE-2026-35323)
A critical vulnerability (CVE-2026-35323) allows low-privileged attackers to take over Oracle WebCenter Content via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. CVSS 9.9, requiring immediate patching.
Read full advisory →CVE-2026-46852
2026-08-24
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46852)
A critical vulnerability (CVE-2026-46852) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTPS. Affects versions 13.5 and 24.1 of the Metadata Plugin component.
Read full advisory →CVE-2026-46855
2026-08-24
Critical Vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46855)
A critical vulnerability (CVE-2026-46855) allows low-privileged attackers to take over Oracle Enterprise Manager Base Platform via HTTPS. Affects versions 13.5 and 24.1 of the Metadata Plugin component.
Read full advisory →CVE-2026-46901
2026-08-24
Critical Vulnerability in Oracle Enterprise Command Center Framework (CVE-2026-46901)
A critical vulnerability (CVE-2026-46901) allows low-privileged attackers to compromise Oracle Enterprise Command Center Framework via HTTP, impacting versions V15 and V16 with potential scope change to other products.
Read full advisory →CVE-2026-46895
2026-08-24
Critical Vulnerability in Oracle Enterprise Command Center Framework (CVE-2026-46895)
A critical vulnerability (CVE-2026-46895) allows low-privileged attackers to take over Oracle Enterprise Command Center Framework via HTTP. Affects versions V15 and V16. CVSS 9.9. Immediate patching advised.
Read full advisory →CVE-2026-61317
2026-08-23
Critical Vulnerability in Oracle Siebel CRM Cloud Manager (CVE-2026-61317)
A critical vulnerability (CVE-2026-61317) allows low-privileged attackers to take over Oracle Siebel CRM Cloud Applications via HTTP. Affected versions include 22.3-26.6. CVSS 9.9. Immediate patching is required to prevent unauthorized access and system compromise.
Read full advisory →CVE-2026-8709
2026-08-23
Critical Privilege Escalation Vulnerability in Progress MarkLogic Server (CVE-2026-8709)
A critical vulnerability in Progress MarkLogic Server allows low-privileged users to escalate privileges via the REST API document patch operation, impacting versions prior to 11.3.6 and 12.0.3.
Read full advisory →CVE-2026-72841
2026-08-23
Critical Vulnerability in OpenVPN Plugin Allows Remote Code Execution (CVE-2026-72841)
A critical vulnerability in luci-app-openvpn allows authenticated users to upload arbitrary files and execute code. Affected systems include OpenWRT and Luci platforms. CVSS score 9.9.
Read full advisory →CVE-2026-61076
2026-08-23
Critical Vulnerability in Oracle PeopleSoft Talent Acquisition Manager (CVE-2026-61076)
A critical vulnerability in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager allows low-privileged attackers to take over systems via HTTP. Affected versions include 9.2. Immediate patching is required to prevent exploitation.
Read full advisory →Get These Delivered to Your Inbox
Subscribe to receive advisories as soon as they are published — filtered to your environment.