Skip to content
Critical Vulnerabilities in Oracle Products Exposed

Critical Vulnerabilities in Oracle Products Exposed

First seen 19 Aug 2026, 20:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 20, 2026 at 19:59 UTC

Two critical vulnerabilities, CVE-2026-61295 and CVE-2026-70948, were published on August 18, 2026, affecting Oracle's WebCenter Content and Purchasing products, respectively. CVE-2026-61295 allows unauthenticated attackers to compromise Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 7.1. In contrast, CVE-2026-70948 affects Oracle Purchasing versions 12.2.3 to 12.2.15, enabling low-privileged attackers to take over the system, scoring 8.8 on the CVSS scale. Both vulnerabilities are easily exploitable, with the potential for unauthorized access to sensitive data. The impact of CVE-2026-70948 is particularly severe, affecting confidentiality, integrity, and availability. Organizations using these Oracle products are advised to take immediate action to mitigate risks. The vulnerabilities were first reported by the National Vulnerability Database (NVD).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 49d ago How this analysis works

Timeline

2026-08-18
CVE-2026-61295 published
A vulnerability in Oracle WebCenter Content allows unauthenticated access, impacting versions 12.2.1.4.0 and 14.1.2.0.0.
Feedly
2026-08-18
CVE-2026-70948 published
A vulnerability in Oracle Purchasing enables takeover by low-privileged attackers, affecting versions 12.2.3 to 12.2.15.
Feedly

More articles in this cluster (6)

Following this threat?

Track CVE-2026-61295 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed