<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Oracle</title><description>Vulnerabilities and patches across Oracle&apos;s enterprise stack — E-Business Suite (including Payments), Fusion Middleware, WebLogic Server, Database, and Java — driven by the January, April, July, and October Critical Patch Update cycle. Combined article + CVE feed for the Oracle beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2008-3431 — Oracle VirtualBox Insufficient Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2008-3431/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2008-3431/</guid><description>An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2010-0840 — Oracle JRE Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2010-0840/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-0840/</guid><description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2011-3544 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2011-3544/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2011-3544/</guid><description>An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle&apos;s Java Runtime Environment allows an attacker to remotely execute arbitrary code.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-0507 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-0507/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-0507/</guid><description>An incorrect type vulnerability exists in the Concurrency component of Oracle&apos;s Java Runtime Environment allows an attacker to remotely execute arbitrary code.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-0518 — Oracle Fusion Middleware Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2012-0518/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-0518/</guid><description>Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>medium</category><category>cve</category></item><item><title>CVE-2012-1710 — Oracle Fusion Middleware Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2012-1710/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-1710/</guid><description>Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-1723 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-1723/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-1723/</guid><description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-3152 — Oracle Fusion Middleware Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2012-3152/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-3152/</guid><description>Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-4681 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2012-4681/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-4681/</guid><description>The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2012-5076 — Oracle Java SE Sandbox Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2012-5076/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2012-5076/</guid><description>The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2013-0422 — Oracle JRE Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2013-0422/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-0422/</guid><description>A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2013-0431 — Oracle JRE Sandbox Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2013-0431/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-0431/</guid><description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>medium</category><category>cve</category></item><item><title>CVE-2013-2423 — Oracle JRE Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2013-2423/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-2423/</guid><description>Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>low</category><category>cve</category></item><item><title>CVE-2013-2465 — Oracle Java SE Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2013-2465/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-2465/</guid><description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2015-2590 — Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2590/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2590/</guid><description>An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2015-4852 — Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2015-4852/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-4852/</guid><description>Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2015-4902 — Oracle Java SE Integrity Check Vulnerability</title><link>https://0daynews.com/cve/cve-2015-4902/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-4902/</guid><description>Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>medium</category><category>cve</category></item><item><title>CVE-2016-3427 — Oracle Java SE and JRockit Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3427/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3427/</guid><description>Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-10271 — Oracle Corporation WebLogic Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-10271/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-10271/</guid><description>Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2017-3506 — Oracle WebLogic Server OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2017-3506/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-3506/</guid><description>Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2018-2628 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2018-2628/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-2628/</guid><description>Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-2616 — Oracle BI Publisher Unauthorized Access Vulnerability</title><link>https://0daynews.com/cve/cve-2019-2616/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-2616/</guid><description>Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2019-2725 — Oracle WebLogic Server, Injection</title><link>https://0daynews.com/cve/cve-2019-2725/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-2725/</guid><description>Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-3010 — Oracle Solaris Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-3010/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-3010/</guid><description>Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2020-14644 — Oracle WebLogic Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-14644/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14644/</guid><description>Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-14750 — Oracle WebLogic Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-14750/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14750/</guid><description>Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-14864 — Oracle Business Intelligence Enterprise Edition Path Transversal</title><link>https://0daynews.com/cve/cve-2020-14864/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14864/</guid><description>Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2020-14871 — Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2020-14871/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14871/</guid><description>Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-14882 — Oracle WebLogic Server Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-14882/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14882/</guid><description>Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-14883 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2020-14883/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-14883/</guid><description>Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2020-2551 — Oracle Fusion Middleware Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2020-2551/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-2551/</guid><description>Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-2555 — Oracle Multiple Products Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-2555/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-2555/</guid><description>Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-2883 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2020-2883/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-2883/</guid><description>Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-35587 — Oracle Fusion Middleware Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2021-35587/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-35587/</guid><description>Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-21445 — Oracle ADF Faces Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21445/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21445/</guid><description>Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-21587 — Oracle E-Business Suite Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2022-21587/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-21587/</guid><description>Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-21839 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2023-21839/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-21839/</guid><description>Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2024-20953 — Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20953/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20953/</guid><description>Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21182/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21182/</guid><description>Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2024-21287 — Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2024-21287/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-21287/</guid><description>Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2025-61757 — Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability</title><link>https://0daynews.com/cve/cve-2025-61757/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-61757/</guid><description>Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-61882 — Oracle E-Business Suite BI Publisher Integration unauth RCE</title><link>https://0daynews.com/cve/cve-2025-61882/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-61882/</guid><description>A critical authentication-bypass and remote-code-execution flaw in the BI Publisher Integration component of Oracle E-Business Suite (versions 12.2.3–12.2.14). Exploited in the wild by Cl0p since August 2025; linked to the Estée Lauder HR-system breach disclosed July 20, 2026.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2025-61884/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-61884/</guid><description>Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>high</category><category>cve</category></item><item><title>CVE-2026-21962 — Oracle WebLogic/HTTP Server unauthenticated data access via HTTP</title><link>https://0daynews.com/cve/cve-2026-21962/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-21962/</guid><description>Unauthenticated HTTP access exposes critical data on Oracle HTTP Server and WebLogic Server. CVSS 10.0. CISA added to KEV August 25, 2026; active exploitation confirmed.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability</title><link>https://0daynews.com/cve/cve-2026-35273/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-35273/</guid><description>Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-46817 — Oracle E-Business Suite Payments improper privilege management (unauth RCE)</title><link>https://0daynews.com/cve/cve-2026-46817/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-46817/</guid><description>A critical improper-privilege-management flaw in the Oracle Payments component of Oracle E-Business Suite (File Transmission) that lets an unauthenticated network attacker take over Oracle Payments. Patched in Oracle&apos;s May 2026 Critical Patch Update; added to CISA KEV on July 15, 2026.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>critical</category><category>cve</category></item><item><title>Oracle WebLogic CVE-2026-21962 Added to CISA KEV</title><link>https://0daynews.com/articles/2026-08-25-oracle-weblogic-cve-2026-21962-kev/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-25-oracle-weblogic-cve-2026-21962-kev/</guid><description>CISA added CVE-2026-21962 to KEV on August 25. CVSS 10.0. Unauthenticated HTTP access to Oracle WebLogic and HTTP Server. Active exploitation confirmed.</description><pubDate>Tue, 25 Aug 2026 12:30:00 GMT</pubDate><category>Oracle</category><category>article</category></item><item><title>Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell</title><link>https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell/</guid><description>Estée Lauder&apos;s July 20 letter says Cl0p breached its Oracle E-Business Suite HR system on August 9, 2025 via CVE-2025-61882. Dwell: 11 months.</description><pubDate>Tue, 21 Jul 2026 00:20:00 GMT</pubDate><category>Oracle</category><category>article</category></item><item><title>CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands</title><link>https://0daynews.com/articles/2026-07-15-cisa-kev-oracle-ebs-cve-2026-46817-payments-file-transmission/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-cisa-kev-oracle-ebs-cve-2026-46817-payments-file-transmission/</guid><description>CISA added CVE-2026-46817 to KEV on Wednesday: unauthenticated CVSS 9.8 takeover of Oracle E-Business Suite Payments. Oracle&apos;s May 2026 CPU already has the fix.</description><pubDate>Wed, 15 Jul 2026 23:20:00 GMT</pubDate><category>Oracle</category><category>article</category></item></channel></rss>