Multiple software vulnerabilities disclosed across unrelated vendors

At least six separate CVEs were disclosed affecting Oracle products (WebLogic, Agile, Banking, WebCenter), OpenRemote, and GNU diffutils. Vulnerabilities range from authentication bypass to unauthorized data access, with Oracle WebLogic CVE-2026-60206 rated critical (CVSS 9.9) and publicly exploited.

20 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-61186: Oracle Agile Engineering Data Management 6.2.1 allows unauthorized data access

stream:bsky-jetstreamother68d ago kagi ↗

CVE-2026-61186 - oracle agile engineering data management An attacker can access sensitive data or cause Oracle Agile Engineering Data Management to crash. This affects version 6.2.1 of Oracle Agile… Too many irrelevant or confusing CVEs? Use stackflag.com #oraclecorporation #CVE #infosec An attacker can access sensitive data or cause Oracle Agile Engineering Data Management to crash.

CVE-2026-61097: Oracle Banking Trade Finance Process Management HTTP Vulnerability

stream:bsky-jetstreamother68d ago kagi ↗

CVE-2026-61097 - oracle banking trade finance process management The Oracle Banking Trade Finance Process Management software has a vulnerability that allows an attacker to access and modify sensitive data… Too many irrelevant or confusing CVEs? Use stackflag.com #oraclecorporation #CVE #infosec The Oracle Banking Trade Finance Process Management software has a vulnerability that allows an attacke

CVE-2026-61100: Oracle WebCenter Enterprise Capture Client Bundle takeover risk via HTTP

stream:bsky-jetstreamother68d ago kagi ↗

CVE-2026-61100 - oracle webcenter enterprise capture Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to a security risk. An attacker with network access can potentially… Too many irrelevant or confusing CVEs? Use stackflag.com #oraclecorporation #CVE #infosec Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to a security ri

CVE-2026-28698: Pronetiqs IntraVUE exposes sensitive system data

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-28698 Pronetiqs IntraVUE versions 3.2.1a14 and earlier allow unauthorized access to system files and data. This could lead to sensitive information being exposed, potentially compromising system security and… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec Pronetiqs IntraVUE versions 3.2.1a14 and earlier allow unauthorized access to system files and data.

CVE-2026-58275: Azure DNS Unauthorized Privilege Escalation

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-58275 - azure dns An attacker can gain elevated access to Azure DNS, compromising network security. This is a serious concern because it allows unauthorized access to sensitive information and… Too many irrelevant or confusing CVEs? Use stackflag.com #azuredns #microsoft #CVE #infosec An attacker can gain elevated access to Azure DNS, compromising network security.

CVE-2026-13072: MongoDB Compute Mode Memory Corruption in External Data

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-13072 - mongodb server MongoDB's compute mode can be vulnerable to memory corruption if it processes invalid data from external sources. This is a risk if you're using compute mode, but it's… Too many irrelevant or confusing CVEs? Use stackflag.com #mongodbserver #mongodb #CVE #infosec MongoDB's compute mode can be vulnerable to memory corruption if it processes invalid data from external

CVE-2026-15704: Eclipse BaSyx Go Components: Unauthorized Access via Trailing Slash

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-15704 - eclipse basyx go components A vulnerability in Eclipse BaSyx Go Components versions 1.0.0 and below allows unauthorized access to protected API routes. This can happen when an attacker adds… Too many irrelevant or confusing CVEs? Use stackflag.com #eclipsefoundation #CVE #infosec A vulnerability in Eclipse BaSyx Go Components versions 1.0.0 and below allows unauthorized access to

CVE-2026-24727: SUNNET Corporate Training Management System - Unrestricted File Upload Risk

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-24727 - corporate training management system An attacker with admin privileges can upload malicious files, potentially allowing them to execute arbitrary commands on the system. This could lead to… Too many irrelevant or confusing CVEs? Use stackflag.com #sunnet #CVE #infosec An attacker with admin privileges can upload malicious files, potentially allowing them to execute arbitrary comma

CVE-2026-58630: Azure App Service: Unauthorized Privilege Elevation Over Network

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-58630 An unauthorized attacker can gain elevated access to Azure App Service over a network. This is a security risk because an attacker could potentially make unauthorized changes to the service or access sensitive… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec An unauthorized attacker can gain elevated access to Azure App Service over a network.

CVE-2026-60999: Oracle Data Integrator 14.1.2.0.0 Rest Service Takeover Risk

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-60999 If an attacker can access your Oracle Data Integrator system over the internet, they may be able to take control of it. This is a serious risk because it could allow them to access sensitive information,… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec If an attacker can access your Oracle Data Integrator system over the internet, they may be able to take cont

CVE-2026-59860: Kiota: Malicious Code Injection through XML Comments

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-59860 - kiota Kiota's code generator can inject malicious code into C# clients if an attacker inserts newline characters into an OpenAPI description. This can happen when an attacker… Too many irrelevant or confusing CVEs? Use stackflag.com #kiota #microsoft #dotnet #CVE #infosec Kiota's code generator can inject malicious code into C# clients if an attacker inserts newline characters int

CVE-2026-60363: Oracle HTTP Server Takeover via HTTP (12.2.1.4.0 and 14.1.2.0.0)

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-60363 - oracle http server An attacker can take control of Oracle HTTP Server by sending malicious HTTP requests. This affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle HTTP Server. To protect… Too many irrelevant or confusing CVEs? Use stackflag.com #oraclecorporation #CVE #infosec An attacker can take control of Oracle HTTP Server by sending malicious HTTP requests. This affects vers

CVE-2026-60531: Oracle Identity Manager Connector: Unauthorized Access and Takeover

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-60531 - oracle identity manager connector A security weakness in Oracle Identity Manager Connector, part of Oracle Fusion Middleware, allows an attacker with some privileges and internet access to… Too many irrelevant or confusing CVEs? Use stackflag.com #oraclecorporation #CVE #infosec A security weakness in Oracle Identity Manager Connector, part of Oracle Fusion Middleware, allows an a

CVE-2026-52439: Arbitrary Code Execution in xiandafu beetl 3.20.2

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-52439 A remote attacker can execute malicious code on your system by exploiting a weakness in the xiandafu beetl version 3.20.2. This could allow them to access or manipulate sensitive data. To protect your system,… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec A remote attacker can execute malicious code on your system by exploiting a weakness in the xiandafu bee

CVE-2026-64873: Joomla Cache Cleaner Pro - Unauthorized Network Access

stream:bsky-jetstreamother67d ago kagi ↗

CVE-2026-64873 - cache cleaner pro extension for joomla A security issue in Joomla's Cache Cleaner Pro extension allows attackers to access internal network services. This could be used to steal sensitive information or… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec A security issue in Joomla's Cache Cleaner Pro extension allows attackers to access internal network service

CVE-2026-66012: SiYuan before v3.7.2 Unauthenticated Admin Access

stream:bsky-jetstreamother66d ago kagi ↗

CVE-2026-66012 - siyuan SiYuan, a software platform, has a security weakness that allows unauthorized users to gain administrator access. This can happen when the software is set to allow anonymous users… Too many irrelevant or confusing CVEs? Use stackflag.com #siyuan #siyuannote #CVE #infosec SiYuan, a software platform, has a security weakness that allows unauthorized users to gain administrato

CVE-2026-66013: OpenRemote Console Registration Authentication Bypass

stream:bsky-jetstreamother66d ago kagi ↗

CVE-2026-66013 - openremote OpenRemote before version 1.26.2 allows attackers to update console settings without a password. This can cause notifications to be sent to the wrong consoles or blocked altogether.… Too many irrelevant or confusing CVEs? Use stackflag.com #openremote #CVE #infosec OpenRemote before version 1.26.2 allows attackers to update console settings without a password.

⚠️ PATCH NOW A public exploit is out for a critical Oracle WebLogic flaw (CVE-2026-60206) that forges a login to take over the server. Rated CVSS 9.9, it hits WebLogic 12.2, 14.1 and 15.1. Apply Oracl

mastodon:infosec-exchangeother66d ago kagi ↗

⚠️ PATCH NOW A public exploit is out for a critical Oracle WebLogic flaw (CVE-2026-60206) that forges a login to take over the server. Rated CVSS 9.9, it hits WebLogic 12.2, 14.1 and 15.1. Apply Oracle's July 2026 patch now, then hunt for forged admin logins. https:// suriq.io/blog/oracle-weblogic- cve-2026-60206-saml-login-forgery-exploit # CVE # infosec # cybersecurity

CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports

stream:bsky-jetstreamother66d ago kagi ↗

CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports Posted by Collin Funk on Jul 25 The CVE id CVE-2026-53910 was assigned to GNU diffutils. In my personal opinion, the CVE description is an absolute joke [1]: An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, res