Critical Vulnerabilities in Oracle Products Exposed
Article Content
- •CVE-2026-61295 affects Oracle WebCenter Content, allowing unauthorized access.
- •CVE-2026-70948 impacts Oracle Purchasing, enabling system takeover by low-privileged attackers.
- •Both vulnerabilities were published on August 18, 2026, and require immediate attention.
Two critical vulnerabilities, CVE-2026-61295 and CVE-2026-70948, were published on August 18, 2026, affecting Oracle's WebCenter Content and Purchasing products, respectively. CVE-2026-61295 allows unauthenticated attackers to compromise Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 7.1. In contrast, CVE-2026-70948 affects Oracle Purchasing versions 12.2.3 to 12.2.15, enabling low-privileged attackers to take over the system, scoring 8.8 on the CVSS scale. Both vulnerabilities are easily exploitable, with the potential for unauthorized access to sensitive data. The impact of CVE-2026-70948 is particularly severe, affecting confidentiality, integrity, and availability. Organizations using these Oracle products are advised to take immediate action to mitigate risks. The vulnerabilities were first reported by the National Vulnerability Database (NVD).
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-61295 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…