Skip to main content
← CVE Tracker

Vendor

Oracle

20 articles

DA
HIGH
Data Breach

Estée Lauder Data Breach: Oracle E-Business Suite Flaw Exploited

Estée Lauder discloses a data breach affecting HR systems due to an unpatched flaw in Oracle E-Business Suite. Customers notified of potential data exposure.

Runtime Rebel Intel
4 min read · Jul 21, 2026
TH
CRITICAL
Threat Intel

Oracle EBS: Over 900 Instances Exposed to Ongoing Attacks

Over 900 Oracle E-Business Suite (EBS) instances are exposed online, facing ongoing attacks targeting a critical flaw. Learn the risks and mitigation steps.

Runtime Rebel Intel
4 min read · Jul 1, 2026
DA
HIGH
Data Breach

ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen

ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.

Runtime Rebel Intel
3 min read · Jun 30, 2026
DA
HIGH
Data Breach

Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters

Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…

Runtime Rebel Intel
5 min read · Jun 30, 2026
VU
CRITICAL
Vulnerabilities

Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide

CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.

Runtime Rebel Intel
3 min read · Jun 13, 2026
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
CRITICAL
Vulnerabilities

ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed

ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.

Runtime Rebel Intel
4 min read · Jun 13, 2026
TH
HIGH
Threat Intel

CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters

Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.

Runtime Rebel Intel
6 min read · Jun 12, 2026
Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
HIGH
Vulnerabilities

Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide

ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.

Runtime Rebel Intel
3 min read · Jun 11, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters

Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.

Runtime Rebel Intel
4 min read · Jun 11, 2026
VU
HIGH
Vulnerabilities

CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation

CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.

Runtime Rebel Intel
4 min read · Jun 2, 2026
VU
HIGH
Vulnerabilities

Oracle January 2025 CSPU: Addressing 77 Security Vulnerabilities

Oracle transitions to monthly Critical Security Patch Updates, resolving 77 flaws including critical RCE vulnerabilities in Communications and Hospitality suites.

Runtime Rebel Intel
3 min read · Jun 2, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-21182: Oracle WebLogic Server Under Active Exploitation

CISA added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its KEV Catalog due to active exploitation. Immediate patching required.

Runtime Rebel Intel
5 min read · Jun 1, 2026
TH
MEDIUM
Threat Intel

Security Analysis of Prediction Market Oracle Manipulation on Polymarket

An investigation into the vulnerabilities of decentralized oracles, including physical sensor tampering and insider trading risks within Polymarket.

Runtime Rebel Intel
4 min read · May 4, 2026
Oracle Red Bull Racing: Securing F1 IP via Identity Automation
INFO
Identity & Access

Oracle Red Bull Racing: Securing F1 IP via Identity Automation

Discover how Oracle Red Bull Racing leverages identity governance automation to protect intellectual property and streamline security in high-stakes F1 environments.

Runtime Rebel Intel
4 min read · Apr 30, 2026
VU
HIGH
Vulnerabilities

Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws

Oracle's April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.

Runtime Rebel Intel
3 min read · Apr 22, 2026
VU
CRITICAL
Vulnerabilities

CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched

Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.

Runtime Rebel Intel
3 min read · Mar 23, 2026
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
HIGH
Vulnerabilities

Oracle Fusion Middleware RCE Flaw: Immediate Patch Required

A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.

Runtime Rebel Intel
4 min read · Mar 20, 2026
VU
HIGH
Vulnerabilities

Oracle Identity Manager RCE via CVE-2026-21992 — Patch Now

Oracle issued an emergency patch for CVE-2026-21992, a critical unauthenticated RCE flaw in Identity Manager and Web Services Manager. Immediate patching is required.

Runtime Rebel Intel
4 min read · Mar 20, 2026
Native Launches Multicloud Security Control Plane for Policy Enforcement
INFO
Cloud Security

Native Launches Multicloud Security Control Plane for Policy Enforcement

Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.

Runtime Rebel Intel
4 min read · Mar 20, 2026
TH
HIGH
Threat Intel

Oracle EBS Exploitation: Risks to Enterprise Financial Integrity

Analysis of the Oracle EBS hack affecting major corporations and the technical risks associated with unpatched ERP systems and financial data theft.

Runtime Rebel Intel
3 min read · Mar 16, 2026