Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On January 20, 2026, Oracle released its Critical Patch Update (CPU) for January 2026, addressing 337 security vulnerabilities across 122 products. This update includes fixes for 158 unique CVEs, with 27 patches classified as critical, impacting various Oracle product families such as databases and...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw allows unauthenticated remote code execution and has a CVSS score of 9.8, indicating...
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively exploited in attacks, prompting warnings from CISA for government agencies to apply the p...