PatchSiren

Oracle Corporation CVE debriefs · Page 24

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61194

A medium severity vulnerability was found in Oracle Agile Engineering Data Management, specifically in the Core component, version 6.2.1. The vulnerability has a CVSS score of 6.5 and can be exploited by a low privileged attacker with network access via TCP, potentially leading to a hang or frequently repeatable crash of the affected system. This type of vulnerability typically allows attackers to cause d [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61188

A high-severity vulnerability was discovered in Oracle Agile Product Lifecycle Management for Process. This vulnerability, tracked as CVE-2026-61188, has a CVSS score of 7.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the affected system. The vulnerability is difficult to exploit and is located in the Installation component. Organiza [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61185

A high-severity vulnerability was discovered in Oracle Agile Product Lifecycle Management for Process. This vulnerability, tracked as CVE-2026-61185, has a CVSS score of 7.4 and allows unauthenticated attackers with access to the physical communication segment to compromise the product and access critical data. The vulnerability is in the Installation component and affects version 6.2.4. The CVSS Vector i [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61184

A critical vulnerability was discovered in Oracle Agile Product Lifecycle Management for Process. This vulnerability, tracked as CVE-2026-61184, has a CVSS score of 9.1 and can allow unauthenticated attackers with network access via HTTP to compromise the product, leading to unauthorized creation, deletion, or modification of critical data. The vulnerability affects version 6.2.4 of the product and has a [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61183

A critical vulnerability was identified in Oracle Agile Product Lifecycle Management for Process, specifically in the Reporting component. The vulnerability, tracked as CVE-2026-61183, has a CVSS score of 9.8 and allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to a takeover. This vulnerability affects version 6.2.4 of the product and has a high [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61182

The CVE-2026-61182 vulnerability affects Oracle Agile Product Lifecycle Management for Process, version 6.2.4. This vulnerability is classified as a high-privileged attacker with logon access issue, potentially leading to system takeover. The CVSS score is 6.7, indicating medium severity. System administrators and security teams should prioritize patching to prevent potential security breaches. The CVE re [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61181

PatchSiren debrief of CVE-2026-61181, a high-severity vulnerability in Oracle Agile Product Lifecycle Management for Process. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all Oracle [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61180

CVE-2026-61180 is a high-severity vulnerability in Oracle Agile Product Lifecycle Management for Process 6.2.4. The vulnerability allows low-privileged attackers with network access via HTTP to easily exploit the product, potentially leading to a complete takeover. Organizations should be concerned about the ease of exploitation and high impact on confidentiality, integrity, and availability. The CVSS 3.1 [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61179

The CVE-2026-61179 vulnerability affects Oracle Agile Product Lifecycle Management for Process version 6.2.4, allowing low-privileged attackers with network access via HTTP to compromise the product. This easily exploitable vulnerability can result in a takeover of Oracle Agile Product Lifecycle Management for Process. The CVSS 3.1 Base Score is 8.8, indicating high severity. Organizations should review t [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61178

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:49.523Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This critical vulnerability in Oracle Agile Product Lifecycle Management for Process 6.2.4 allows unauthenticated attackers with network access via TCP to compromise the system, potentially leading [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61173

A high-severity vulnerability was discovered in Oracle Agile PLM, specifically in the Security component. The vulnerability, tracked as CVE-2026-61173, has a CVSS score of 7.4 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all acce [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61172

A security vulnerability was discovered in Oracle Agile PLM, specifically in the Security component of version 9.3.6. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM, potentially leading to unauthorized access to critical data. The vulnerability has a CVSS 3.1 Base Score of 7.5, indicating a high severity level. The CVSS Vector is (CVSS:3.1 [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61171

A critical vulnerability was discovered in Oracle Agile PLM, allowing unauthenticated attackers to compromise the system and access critical data. The vulnerability, CVE-2026-61171, is a security issue in Oracle Agile PLM that allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to c [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61170

A high-severity vulnerability was discovered in Oracle Agile PLM, specifically in the Security component. The vulnerability, tracked as CVE-2026-61170, has a CVSS score of 8.1 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to a takeover of the Oracle Agile PLM system. The vulnerability affects Oracle Agile PLM version 9.3.6. The CVSS vector is CVSS:3.1/ [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61169

A medium-severity vulnerability was found in Oracle Agile PLM, specifically in the Security component. The vulnerability, CVE-2026-61169, has a CVSS score of 6.5 and allows a low-privileged attacker with logon access to compromise the system. This could potentially impact additional products and lead to unauthorized access to critical data. The supported version affected is 9.3.6. The vulnerability is eas [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61168

A high-severity vulnerability was found in Oracle Agile PLM, specifically in the Security component. The vulnerability, tracked as CVE-2026-61168, has a CVSS score of 8.8 and can be easily exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of the Oracle Agile PLM system. This vulnerability affects Oracle Agile PLM version 9.3.6. The CVSS 3.1 Base Score is [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61167

A critical vulnerability was discovered in Oracle Agile PLM version 9.3.6. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Agile PLM, potentially leading to a complete takeover of the system. The vulnerability is located in the Security component of Oracle Agile PLM. The CVSS 3.1 Base Score is 9.8, indicating a high impact on confide [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61166

A high-severity vulnerability, tracked as CVE-2026-61166, was discovered in Oracle Agile PLM, specifically in the User and User Group component. The vulnerability has a CVSS score of 8.8 and can be easily exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of the Oracle Agile PLM system. The vulnerability's impact on confidentiality, integrity, and availab [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61144

A vulnerability was found in MySQL Server and MySQL Cluster products of Oracle MySQL. The vulnerability is located in the Server: Optimizer component and affects versions 9.7.0-9.7.1 of both products. A high privileged attacker with network access via multiple protocols can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server and MySQL Cluster. The CVSS [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61141

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:45.420Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This high-severity vulnerability in Oracle Advanced Benefits, with a CVSS score of 7.5, allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading t [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61140

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:45.300Z and has not been modified since then. The CVE-2026-61140 vulnerability affects Oracle WebCenter Sites version 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTP to compromise the site, potentially leading to site takeover. The CVSS 3.1 Base Score is 9.8, ind [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61128

A vulnerability was discovered in the MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: Optimizer component. The affected versions are MySQL Server: 9.7.0-9.7.1 and MySQL Cluster: 9.7.0-9.7.1. This vulnerability allows a high-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster, potentially leading to a hang or frequ [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61127

CVE-2026-61127 is a high-severity vulnerability in Oracle Communications Service Catalog and Design, affecting versions 8.0.0.7.0-8.3.0.2.0. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to takeover. The CVSS 3.1 Base Score is 8.8, indicating high confidentiality, integrity, and availability impacts. Oracle Communications Serv [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61126

The CVE-2026-61126 vulnerability is in the Oracle Communications Billing and Revenue Management product, specifically in the Platform component. Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0 and 15.1.0.0.0-15.2.0.0.0. The vulnerability allows low-privileged attackers with logon to the infrastructure to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 7.8, [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61125

The CVE-2026-61125 vulnerability affects the Oracle Configure to Order product within Oracle E-Business Suite, specifically the Supply to Order Workbench component. This vulnerability is classified as easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Configure to Order. The potential impact is significant, with successful attacks possibly resulting in [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61110

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:42.260Z and has not been modified since then. The CVE-2026-61110 vulnerability is an easily exploitable issue in Oracle Applications DBA, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The affected versions are 12.2. [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61109

A vulnerability exists in MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: JSON component. The affected versions are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. This vulnerability allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful att [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61108

A vulnerability was discovered in the MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: GIS component. The affected versions are MySQL Server 9.7.0-9.7.1 and MySQL Cluster 9.7.0-9.7.1. This vulnerability allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server and MySQL Cluster. Successful attacks can result in unauthorized a [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61107

The CVE-2026-61107 vulnerability affects Oracle Applications DBA, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise Oracle Applications DBA, potentially leading to takeover. The affected versions are 12.2.3-12.2.15, and the CVSS score is 7.2, indicating high severity. Oracle Applicat [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61106

A high-severity vulnerability was discovered in Oracle GoldenGate, a comprehensive data integration and replication solution. This vulnerability, tracked as CVE-2026-61106, has a CVSS 3.1 Base Score of 8.1, indicating a high level of risk. The vulnerability affects versions 23.4 through 23.26.2 of Oracle GoldenGate. It is located in the Config Service Executable component and is difficult to exploit, requ [truncated]