Oracle HTTP Server is a technology platform tracked across 5 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed January 21, 2026; most recent activity July 23, 2026.
Oracle HTTP Server (OHS) is Oracle’s web server offering built on the Apache HTTP Server stack with Oracle-specific modules, used to deliver Oracle Fusion Middleware, E-Business Suite, and other Oracle applications. In cybersecurity, it represents a web-facing surface whose security posture depends on timely patching of OHS and underlying components (e.g., Apache Tika), as evidenced by recent critical vulnerabilities and large patch releases affecting Oracle products.
Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially…
On January 20, 2026, Oracle released its Critical Patch Update (CPU) for January 2026, addressing 337 security vulnerabilities across 122 products. This update includes fixes for 158 unique CVEs, with 27 patches…
A critical vulnerability (CVE-2026-21962) has been identified in Oracle HTTP Server and WebLogic Server Proxy Plug-in, allowing unauthenticated attackers to create, delete, or modify critical data. Oracle has released…
Recent advisories detail multiple vulnerabilities affecting various software products. CVE-2026-21509, published on January 26, 2026, is under active exploitation and could allow unauthenticated remote code execution.…
CVE-2026 was assigned to address a vulnerability in Chromium, which is utilized by Microsoft Edge (Chromium-based). This vulnerability affects users of Microsoft Edge as it ingests the Chromium codebase. For further…