Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61038 – Unauthenticated Data Exposure & Modification – Oracle WebCenter Sites 12.2.1.4.0 /

CVE-2026-61038 is a high-severity vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware, that allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data over HTTP and to make limited unauthorized modifications. Oracle rates the flaw as "easily exploitable," and it carries a CVSS v3.1 base score of 8.2. The CVE was published on August 18, 2026, as part of Oracle's Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60992 – Unauthenticated Remote Compromise – Oracle Identity Manager Connector 12.2.1.4.0 /

CVE-2026-60992 is a vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware that allows an unauthenticated attacker with network access via TLS to compromise the product. Oracle rates this vulnerability as difficult to exploit, but successful exploitation results in a complete takeover of the Oracle Identity Manager Connector, impacting confidentiality, integrity, and availability. The flaw was disclosed as part of Oracle's August 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62618 – Unauthenticated Access to Data (Authentication Bypass) – Oracle Reports Developer 1

CVE-2026-62618 is an authentication bypass vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the Security and Authentication component, gaining unauthorized access to critical data and the ability to make limited unauthorized modifications. Oracle rates the vulnerability CRITICAL with a CVSS v3.1 base score of 9.3.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70872 – Unauthenticated Data Manipulation/Disclosure – Oracle Hyperion Data Relationship Ma

CVE-2026-70872 is a critical, unauthenticated vulnerability in the "Access and security" component of Oracle Hyperion Data Relationship Management (DRM). An attacker with only network access to the affected HTTP interface — no credentials or user interaction required — can exploit the flaw to read, create, delete, or modify critical data within the application. Oracle rates the issue 9.1 (Critical) on the CVSS v3.1 scale and disclosed it as part of its August 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61307 – Unauthenticated Remote Compromise – Oracle PeopleSoft Enterprise PeopleTools (CC Co

CVE-2026-61307 is a high-severity vulnerability in Oracle PeopleSoft Enterprise CC Common Application Objects, a component of PeopleSoft Enterprise PeopleTools. It allows an unauthenticated attacker with network access via Oracle Net to compromise the affected component, with Oracle stating successful exploitation can result in takeover of the product. Oracle rates the flaw as difficult to exploit, but the potential impact spans confidentiality, integrity, and availability, and it carries a CVSS v3.1 base score of 8.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70862 – Unauthenticated Data Compromise (RCE-level Impact) – Oracle Application Testing Sui

CVE-2026-70862 is a critical, remotely exploitable vulnerability in Oracle Application Testing Suite that allows a completely unauthenticated network attacker to compromise the confidentiality and integrity of the application. The flaw is exploitable over HTTP without any user interaction, and successful exploitation grants unauthorized creation, deletion, or modification of critical data, as well as read access to all data accessible to Oracle Application Testing Suite. Oracle disclosed the issue as part of its August 2026 Critical Security Patch Update, rating it 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61018 – Unauthenticated Remote Takeover (RCE) – Oracle WebCenter Sites 12.2.1.4.0 and 14.1.

CVE-2026-61018 is a critical, unauthenticated remote compromise vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The flaw allows an attacker with mere network access over HTTP — no credentials and no user interaction — to fully take over an affected WebCenter Sites instance. Oracle rates the issue 9.8 (Critical) on the CVSS v3.1 scale, its second-highest possible severity tier, reflecting complete loss of confidentiality, integrity, and availability.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61054 – Unauthenticated Data Exposure & Tampering – Oracle WebCenter Sites 12.2.1.4.0 / 14.

CVE-2026-61054 is a high-severity vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. Per Oracle's official advisory, the flaw is "easily exploitable," allowing an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites, resulting in unauthorized access to and disclosure of critical data as well as unauthorized update, insert, or delete operations on some accessible data. Oracle disclosed the issue on August 18, 2026, with a CVSS v3.1 base score of 8.2 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70722 – Unauthenticated Data Integrity Compromise & Partial DoS – Oracle E-Business Suite (

CVE-2026-70722 is a high-severity vulnerability affecting the Oracle Advanced Inbound Telephony product within Oracle E-Business Suite (component: Internal Operations). The flaw allows an unauthenticated, remote attacker with network access via HTTPS to compromise the affected component, resulting in unauthorized creation, deletion, or modification of critical data and a partial denial of service. Oracle rates this vulnerability as easily exploitable, and it carries a CVSS v3.1 base score of 8.2 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62531 – Unauthenticated Remote System Takeover – Oracle Hyperion Infrastructure Technology

CVE-2026-62531 is a high-severity vulnerability in Oracle Hyperion Infrastructure Technology's Lifecycle Management component that allows an unauthenticated attacker with network access via HTTP to achieve a full takeover of the affected system. Oracle rates this a difficult-to-exploit flaw, but successful exploitation results in complete loss of confidentiality, integrity, and availability. The issue was disclosed as part of Oracle's August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60946 – Unauthenticated RCE / System Takeover – Oracle WebCenter Enterprise Capture 12.2.1.

CVE-2026-60946 is a critical, unauthenticated remote code execution vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. The flaw is remotely exploitable over the network via the RMI protocol without requiring any credentials or user interaction, and successful exploitation can result in a complete compromise of the affected system's confidentiality, integrity, and availability. Oracle disclosed the issue in its August 2026 Critical Patch Update and rated it 9.8 (Critical) on the CVSS v3.1 scale.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70880 – Unauthenticated Remote Code Execution / Complete System Takeover – Oracle Hyperion

CVE-2026-70880 is a critical, easily exploitable vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management (DRM) that allows a completely unauthenticated, remote attacker with network access via TCP to fully compromise the affected system. Oracle disclosed the flaw in its August 2026 Critical Security Patch Update, and it carries the maximum CVSS v3.1 base score of 10.0 due to the combination of no authentication requirement, no user interaction, a changed scope, and complete loss of confidentiality, integrity, and availability.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61230 – Unauthenticated Data Exposure – Oracle WebCenter Portal 12.2.1.4.0 & 14.1.2.0.0

CVE-2026-61230 is a high-severity vulnerability in the Runtime Tools component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It allows an unauthenticated, remote attacker with network access via HTTP to compromise the application and gain unauthorized access to confidential data. Oracle rates this issue "easily exploitable" with a CVSS v3.1 base score of 8.6 (High).

Created Date
Source
CVE-2026-70873 – Unauthenticated RCE / Full System Compromise – Oracle Hyperion Data Relationship Ma

CVE-2026-70873 is a critical, unauthenticated remote code execution vulnerability in Oracle Hyperion Data Relationship Management (DRM), residing in the product's access and security component. The flaw is network-exploitable over TCP without any credentials or user interaction, and successful exploitation gives an attacker complete control of the underlying system. Oracle rates the issue 9.8 (Critical) on the CVSS v3.1 scale and disclosed it as part of the August 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70704 – Unauthenticated Takeover via Party Search UI – Oracle E-Business Suite (Trading Com

CVE-2026-70704 is a high-severity (CVSS 8.1) vulnerability in the Party Search UI component of Oracle Trading Community, a module within Oracle E-Business Suite. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community, with Oracle's advisory noting that successful exploitation "can result in takeover" of the affected component. Oracle rates this as difficult to exploit (high attack complexity) but requiring no credentials and no user interaction.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62621 – Unauthenticated RCE – Oracle Reports Developer 12.2.1.19.0

CVE-2026-62621 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker with network access to fully compromise the affected application, with high impact to confidentiality, integrity, and availability. Oracle disclosed the flaw in its August 2026 Critical Security Patch Update with a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62544 – Unauthenticated Remote Takeover – Oracle Hyperion Infrastructure Technology 11.2.25

CVE-2026-62544 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, affecting version 11.2.25.0.000. The flaw allows an unauthenticated, remote attacker with network access via HTTP to fully compromise the affected system, impacting confidentiality, integrity, and availability. Oracle rates this vulnerability as easily exploitable and disclosed it as part of its August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62626 – Unauthenticated Remote Compromise (RCE-class) – Oracle Reports Developer 12.2.1.19.

CVE-2026-62626 is a critical, unauthenticated remote code execution vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. It resides in the product's Security and Authentication component and allows a network attacker to fully compromise the affected system without credentials or user interaction. Oracle rates this vulnerability CRITICAL with a CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-61302 – Unauthenticated Data Exposure & Partial DoS – Oracle Business Intelligence Enterpri

CVE-2026-61302 is a vulnerability in the Pod Admin component of Oracle Business Intelligence Enterprise Edition that allows an unauthenticated, network-based attacker to gain unauthorized access to critical data and cause a partial denial of service. Oracle rates the flaw as "easily exploitable," and it carries a CVSS v3.1 base score of 8.2 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62610 – Unauthenticated Data Compromise / Unauthorized Access – Oracle Reports Developer 12

CVE-2026-62610 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to compromise the product, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible to Oracle Reports Developer. Oracle rates this as easily exploitable with a CVSS 3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70852 – Unauthenticated Data Exposure & Manipulation – Oracle Demand Planning (E-Business S

CVE-2026-70852 is a high-severity vulnerability in the Oracle Demand Planning module of Oracle E-Business Suite (component: Internal Operations). The flaw allows a remote, unauthenticated attacker with network access via HTTP to obtain complete read access to all data accessible to Oracle Demand Planning, along with the ability to insert, update, or delete a subset of that data. Oracle disclosed the issue as part of its August 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-70868 – Unauthenticated Remote Takeover – Oracle Application Testing Suite 13.3.0.1

CVE-2026-70868 is a high-severity vulnerability in Oracle Application Testing Suite that allows an unauthenticated attacker with network access via HTTP to compromise the affected component. Successful exploitation can result in complete takeover of Oracle Application Testing Suite, impacting the confidentiality, integrity, and availability of the system. Oracle rates the flaw 8.1 (HIGH) and classifies it as difficult to exploit, published as part of the August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60796 – Unauthenticated Data Exposure / Partial DoS – Oracle Siebel CRM Integration (REST)

CVE-2026-60796 is a high-severity vulnerability in the REST integration component of Oracle Siebel CRM. It allows an unauthenticated, network-based attacker to gain unauthorized access to sensitive data and cause a partial disruption of service. Oracle rates the flaw as "easily exploitable" and disclosed it in the August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62611 – Unauthenticated Remote Code Execution via IIOP – Oracle Reports Developer 12.2.1.19

CVE-2026-62611 is a critical vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware. It resides in the Security and Authentication component and allows an unauthenticated, network-based attacker to compromise the product via the IIOP protocol, resulting in a complete takeover of the affected system. Oracle rates this as CVSS 9.8 (Critical) in its August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62614 – Unauthenticated RCE (Critical) – Oracle Reports Developer 12.2.1.19.0

CVE-2026-62614 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer, with Oracle's advisory noting successful exploitation can result in complete takeover of the product. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60934 – Unauthorized Data Modification – Oracle WebCenter Content 12.2.1.4.0 / 14.1.2.0.0

CVE-2026-60934 is a high-severity vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise the application, potentially resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible through WebCenter Content. Oracle rates the flaw 8.7 (High) on CVSS 3.1, though it notes the vulnerability is difficult to exploit.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62539 – Unauthenticated Remote Compromise – Oracle Hyperion Infrastructure Technology 11.2.

CVE-2026-62539 is a critical, easily exploitable vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology. It allows an unauthenticated attacker with network access via HTTP to fully compromise the affected system, with Oracle stating that successful exploitation "can result in takeover" of Hyperion Infrastructure Technology. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and was disclosed as part of Oracle's August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62634 – Unauthenticated Remote Takeover (RCE-equivalent) – Oracle Reports Developer 14.1.2.

CVE-2026-62634 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via CORBA to fully compromise the affected system, and Oracle rates it as easily exploitable. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60903 – Unauthenticated Data Manipulation – Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.

CVE-2026-60903 is a vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) that allows an unauthenticated, network-based attacker to compromise the product over HTTP. Oracle rates it 8.7 (High) and notes it is difficult to exploit but that successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to data accessible to WebCenter Content. The CVSS "Scope: Changed" designation indicates the vulnerability in this component may significantly impact additional products.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60977 – Unauthenticated RCE via RMI – Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2

CVE-2026-60977 is a critical vulnerability in Oracle WebLogic Server's WLS Core Components that allows an unauthenticated attacker with network access via RMI to fully compromise the server. Oracle rates it CVSS 9.8 (Critical) and describes it as an easily exploitable flaw with no authentication or user interaction required. It was disclosed as part of Oracle's August 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-62543 – Unauthenticated RCE – Oracle Hyperion Infrastructure Technology 11.2.25.0.0

CVE-2026-62543 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology (part of Oracle Hyperion). It allows an unauthenticated, remote attacker with network access via HTTP to fully compromise and take over the affected system. Oracle rates it 9.8 (Critical) under CVSS v3.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60754 – Unauthenticated Data Exposure & DoS – Oracle Siebel CRM Marketing (versions 17.0–26

CVE-2026-60754 is a critical vulnerability in the Marketing component of Oracle Siebel CRM (Siebel Apps – Marketing) that allows a remote, unauthenticated attacker to compromise the application over HTTP. Successful exploitation results in unauthorized access to critical data and denial-of-service conditions, with no authentication or user interaction required. Oracle assigned this issue a CVSS v3.1 base score of 9.1 (Critical) and disclosed it in the August 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-60591 – Unauthenticated Data Tampering & DoS – Oracle Hospitality Simphony 19.8–19.10.1

CVE-2026-60591 is a critical, easily exploitable vulnerability in the POS component of Oracle Hospitality Simphony. It allows an unauthenticated attacker with network access via HTTP to compromise the system, enabling unauthorized creation, deletion, or modification of critical data as well as denial-of-service conditions. Oracle disclosed the flaw in its August 2026 Critical Security Patch Update with a CVSS v3.1 base score of 9.1 (Critical).

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge