CVE-2026-58644
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Oracle enterprise middleware accounts for most of the day's critical disclosures, with multiple CVSS 10 flaws in HTTP Server, Access Manager, Unified Directory, WebCenter Content, and the Service Delivery Platform. Critical CVEs rose to 48 from 20 the prior day (up 140%), while high-priority CVEs eased to 100 from 109 (down 8%). Named critical issues include CVE-2026-60365 (CVSS 10) in Oracle HTTP Server, CVE-2026-60644 (CVSS 10) in Oracle WebCenter Content, and CVE-2026-52348 (CVSS 9.8) in cool-team-official cool-admin-java. The concentration in identity, directory, and content-management components points to authentication and remote-code-execution exposure across widely deployed Oracle stacks. No patch data was available at disclosure time, so teams should track vendor advisories and stage updates for internet-facing systems first.
Immediate action: Prioritize Oracle middleware (HTTP Server, Access Manager, Unified Directory, WebCenter Content, Service Delivery Platform) and any internet-facing SharePoint or FortiSandbox instances for immediate review and mitigation. With no patches published at disclosure, monitor vendor advisories closely and apply available updates or workarounds as soon as they are released.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.
An OS command injection vulnerability in FortiSandbox allows unauthenticated attackers to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet FortiSandbox is vulnerable to OS command injection, allowing unauthenticated attackers to execute unauthorized code on the appliance.
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
A critical vulnerability in Langflow allows unauthenticated remote attackers to execute arbitrary code via the /validate endpoint's exec_globals parameter.
DD-WRT is vulnerable to a stack-based buffer overflow in the UPnP service, which could allow an unauthenticated attacker to achieve remote code execution.
The KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that is currently being exploited in the wild.
WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.
A critical vulnerability in the Oracle TimesTen In-Memory Database Kubernetes Operator allows low privileged attackers to achieve full system takeover.
A critical, unauthenticated remote code execution vulnerability exists in the Oracle WebLogic Server Proxy Plug-in for third-party web servers.
A vulnerability in the Oracle BI Publisher Web Service API allows low privileged, authenticated attackers to compromise data and cause partial denial of service via HTTP.
A SQL injection vulnerability in the order() method of CrudOption.java within cool-admin-java 8.0.0 allows unauthenticated attackers to compromise the database.
A critical vulnerability in the Oracle Access Manager Authentication Engine allows unauthenticated, remote attackers to achieve a full system takeover via HTTP.
A critical vulnerability in the Oracle Unified Directory OUD Core allows unauthenticated, remote attackers to achieve a full system takeover via LDAP.
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler component allows unauthenticated attackers to achieve full system takeover via network-accessible SOAP requests.
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler component allows unauthenticated attackers to achieve full system takeover via HTTP network requests.
A critical vulnerability in the Oracle WebCenter Content Web Content Management component allows unauthenticated attackers to achieve full system takeover via HTTP network requests.
A critical vulnerability in the Oracle Data Integrator Rest Service component allows an unauthenticated attacker to achieve full system takeover via network access.
A critical vulnerability in the Oracle Coherence Core component allows an unauthenticated attacker to achieve full system takeover via network access.
A critical vulnerability in the Oracle Access Manager Authentication Engine allows a low-privileged attacker to achieve full system takeover via network access.
A critical vulnerability in Oracle Unified Directory allows an authenticated attacker with low privileges to achieve full system compromise via network access.
A critical vulnerability in Oracle Service Delivery Platform allows authenticated attackers to perform unauthorized data modification and partial denial of service via T3 or IIOP protocols.
A critical vulnerability in Oracle Service Delivery Platform allows an authenticated attacker to achieve a complete system takeover via the Messaging Enabler component.
A vulnerability in Oracle Unified Directory allows a low privileged attacker with network access via LDAP to compromise the directory, potentially impacting other products through scope change.
A vulnerability in Oracle Unified Directory allows a low privileged, network-based attacker to perform a full system takeover, with potential impacts extending to other integrated products.
A vulnerability in Oracle WebCenter Enterprise Capture allows a low privileged network attacker to gain full system control via T3 or IIOP protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low privileged attacker to achieve full system takeover via network-based HTTP requests.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low privileged attacker to achieve full system takeover via network-based HTTP requests.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low privileged attacker to achieve system takeover via network-based T3 or IIOP protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated, low-privileged attacker to achieve full system compromise via T3 or IIOP protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated, low-privileged attacker to achieve full system compromise via HTTP.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated, low-privileged attacker to achieve full system compromise via T3 or IIOP protocols.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low privileged, network-based attacker to fully compromise the system and impact other products via scope change.
A critical vulnerability in the Oracle Identity Manager Connector allows a low privileged, network-based attacker to fully compromise the system and impact other products via scope change.
A critical vulnerability in Oracle Managed File Transfer allows a low privileged, network-based attacker to fully compromise the system and impact other products via scope change.
A critical vulnerability in Oracle Business Process Management Suite allows low privileged attackers to compromise the system via T3 or IIOP protocols.
A critical vulnerability in Oracle Managed File Transfer allows low privileged attackers to compromise the system via HTTP.
A critical vulnerability in Oracle WebCenter Sites allows low privileged attackers to compromise the system via HTTP.
A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve full system takeover via HTTP.
A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve full system takeover via HTTP.
A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve full system takeover via HTTP.
A critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged attacker to achieve full system takeover via network-accessible HTTP requests.
A critical vulnerability in the Installation Security component of JD Edwards EnterpriseOne Tools allows a low privileged attacker to achieve full system takeover via network-based HTTP attacks.
A critical vulnerability in the Web Content Management component of Oracle WebCenter Content allows a low privileged attacker to achieve full system takeover via network-accessible HTTP requests.
A critical vulnerability in Oracle Siebel CRM Cloud Applications allows a low-privileged, network-based attacker to achieve full system takeover via HTTP.
A critical flaw in Oracle Demantra Demand Management allows a low-privileged, network-based attacker to execute a full system takeover via HTTP.
A critical flaw in PeopleSoft Enterprise FIN Staffing Front Office Brazil allows a low-privileged, network-based attacker to achieve full system takeover via HTTP.
A critical vulnerability in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager allows a low privileged attacker to achieve full system takeover via network-based HTTP requests.
A critical vulnerability in the Content Acquisition System of Oracle Commerce allows a low privileged attacker to compromise the application and impact associated systems via HTTP.
A critical vulnerability in Oracle PeopleSoft In-Memory Project Discovery allows a low privileged attacker to achieve full system takeover via network-based HTTP requests.
A vulnerability in the RDBMS component of Oracle Database Server allows low privileged, authenticated attackers to potentially compromise the entire database system.
An unauthenticated vulnerability in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina enables remote attackers to compromise the system over HTTP.
A remote code execution vulnerability in the Autel MaxiCharger Single firmware allows unauthenticated attackers to execute commands with root privileges via TCP port 9002.
The Autel MaxiCharger Single firmware contains an OS command injection vulnerability in the /test endpoint, allowing unauthenticated remote code execution via the url parameter.
The Autel MaxiCharger Single firmware contains undocumented privileged accounts with deterministic password derivation, allowing attackers to gain unauthorized administrative access.
A hard-coded authentication token exists in the Autel MaxiCharger Single firmware, allowing unauthenticated attackers to bypass authorization and access privileged management endpoints.
A vulnerability in the Oracle WebCenter Content Content Server component allows an authenticated attacker with network access to achieve a full system takeover.
A vulnerability in the core component of Oracle WebLogic Server allows an authenticated attacker with network access to achieve a full system takeover.
A vulnerability in Oracle GoldenGate Microservices allows an authenticated attacker with network access to achieve a full system takeover.
A vulnerability in the Oracle GoldenGate Admin Server allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Oracle Unified Directory (OUD) Core component allows a low privileged attacker to compromise the directory server via LDAP.
A vulnerability in the Oracle Unified Directory (OUD) Core component allows a low privileged attacker to compromise the directory server via LDAP.
An easily exploitable vulnerability in Oracle Unified Directory allows a low privileged attacker with network access via LDAP to achieve full system takeover.
An easily exploitable vulnerability in Oracle WebCenter Content: Imaging allows a low privileged attacker with network access via HTTP to achieve full system takeover.
An easily exploitable vulnerability in Oracle WebCenter Content: Imaging allows a low privileged attacker with network access via T3 or IIOP protocols to achieve full system takeover.
A vulnerability in the Core component of Oracle WebCenter Content: Imaging allows low-privileged network attackers to potentially gain full control of the application.
A vulnerability in the CRM Foundation component of Oracle JD Edwards EnterpriseOne allows low-privileged network attackers to achieve full system takeover.
A vulnerability in Oracle JD Edwards EnterpriseOne CRM Foundation allows a low privileged attacker with network access to compromise and potentially take over the application.
A vulnerability in Oracle JD Edwards EnterpriseOne Human Resources Management allows a low privileged attacker with network access to compromise and potentially take over the application.
A vulnerability in Oracle JD Edwards EnterpriseOne Solution Advisor allows a low privileged attacker with network access to compromise and potentially take over the application.
A core component vulnerability in Oracle WebCenter Content: Imaging allows low privileged network attackers to gain unauthorized control over the application.
A high-severity vulnerability in the Integration Business Insight component of Oracle SOA Suite allows authenticated attackers to compromise the system via network access.
A high-severity vulnerability in the MFT Runtime Server of Oracle Managed File Transfer allows authenticated attackers to compromise the system via network access.
A high-severity vulnerability in the MFT Runtime Server of Oracle Managed File Transfer allows authenticated attackers to compromise the system via network access.
A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows a low privileged attacker to achieve full system compromise via network access.
An unauthenticated vulnerability in the Oracle Enterprise Command Center Framework allows an attacker with physical network segment access to compromise the system.
A vulnerability in the Install component of Oracle Transportation Management allows a low privileged attacker to compromise the application via network access.
A vulnerability in the Integration and Interfaces component of Oracle PeopleSoft Enterprise CS Campus Community allows a low privileged attacker to achieve full system takeover.
A vulnerability in the Billing component of Oracle PeopleSoft Enterprise CS Student Financials allows a low privileged attacker to achieve full system takeover.
A vulnerability in the Australian Features component of Oracle PeopleSoft Enterprise CS Student Records allows a low privileged attacker to achieve full system takeover.
A vulnerability in the Procurement component of Oracle JD Edwards EnterpriseOne allows a low privileged attacker with network access to compromise the system.
A vulnerability in the Content Server component of Oracle WebCenter Content allows an unauthenticated attacker to compromise the system via a cross-site interaction.
A vulnerability in the Content Server component of Oracle WebCenter Content allows an unauthenticated attacker to compromise the system via a cross-site interaction.
An unauthenticated, remotely exploitable vulnerability in Oracle WebCenter Content allows for full system takeover when combined with user interaction.
An unauthenticated, remotely exploitable vulnerability in Oracle WebCenter Content allows for full system takeover when combined with user interaction.
An unauthenticated, remotely exploitable vulnerability in Oracle WebCenter Content allows for full system takeover when combined with user interaction.
A high severity vulnerability in the Oracle WebCenter Content component allows an unauthenticated attacker to achieve full system takeover via network-based exploitation requiring user interaction.
A high severity vulnerability in the Oracle WebCenter Content component allows an unauthenticated attacker to achieve full system takeover via network-based exploitation requiring user interaction.
A high severity vulnerability in the Oracle WebCenter Content component allows an unauthenticated attacker to achieve full system takeover via network-based exploitation requiring user interaction.
A high-severity vulnerability in the Oracle WebCenter Content Web Content Management component allows a low-privileged authenticated attacker to gain full system control via network access.
A high-severity vulnerability in the Oracle WebCenter Content Web Content Management component allows a low-privileged authenticated attacker to gain full system control via network access.
A high-severity vulnerability in the Oracle WebCenter Content Web Content Management component allows a low-privileged authenticated attacker to gain full system control via network access.
An unauthenticated, remote vulnerability in Oracle WebCenter Content allows for full system takeover via network-based attacks requiring user interaction.
A vulnerability in the Oracle Applications Framework Search Bean component allows authenticated, low-privileged users to achieve full system takeover.
A vulnerability in the Oracle Applications Framework Search Bean component allows authenticated, low-privileged users to achieve full system takeover.
A vulnerability in the Oracle General Ledger component of Oracle E-Business Suite allows a low privileged attacker to compromise the application via network access using SOAP.
A vulnerability in Oracle Process Manufacturing Regulatory Management allows a low privileged attacker with network access via HTTP to compromise the software.
A vulnerability in Oracle Enterprise Asset Management allows a low privileged attacker with network access via HTTP to compromise the application.
A vulnerability in the Create Item Instance component of Oracle Installed Base allows authenticated attackers with network access to achieve full system takeover.
A vulnerability in the AR Web Utilities component of Oracle iReceivables allows authenticated attackers with network access to achieve full system takeover.
A vulnerability in the Internal Operations component of Oracle Sales Offline allows authenticated attackers with network access to achieve full system takeover.
A high-severity vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite allows low-privileged attackers to achieve full system compromise via network access.
A high-severity vulnerability in the Oracle Advanced Pricing component of Oracle E-Business Suite allows authenticated attackers to achieve full system compromise via network access.
A high-severity vulnerability in the Oracle Order Management component of Oracle E-Business Suite allows authenticated attackers to achieve full system compromise via network access.
A vulnerability in the Internal Operations component of Oracle Payroll allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Internal Operations component of Oracle Payroll allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Internal Operations component of Oracle Warehouse Management allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Internal Operations component of Oracle Project Intelligence allows a low-privileged authenticated attacker to compromise the system via network access.
A vulnerability in the Internal Operations component of Oracle Customer Care allows a low-privileged authenticated attacker to compromise the system via network access.
A vulnerability in the Internal Operations component of Oracle Public Sector Payroll allows a low-privileged authenticated attacker to compromise the system via network access.
A critical vulnerability in Oracle Labor Distribution allows low privileged, authenticated attackers to achieve a full system takeover via network access.
A security flaw in Oracle Transportation Execution enables authenticated, low-privileged attackers to achieve full system takeover via network-based exploitation.
A severe vulnerability in Oracle SDP Number Portability allows authenticated, low-privileged local attackers to achieve system takeover and impact additional connected products.
A critical vulnerability in Oracle Advanced Collections allows a low privileged, authenticated network attacker to achieve a full system takeover.
A critical vulnerability in Oracle Process Manufacturing Systems allows a low privileged, authenticated network attacker to achieve a full system takeover.
A vulnerability in PeopleSoft Enterprise FIN Cash Management allows a local, low privileged attacker to compromise the application and potentially impact other products due to scope change.
A security vulnerability exists in Oracle PeopleSoft Enterprise SCM Supplier Contract Management, potentially allowing a low privileged local attacker to achieve a full system takeover.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows a low privileged network-based attacker to compromise the application.
A vulnerability within the Oracle WebCenter Enterprise Capture Client Bundle allows a low privileged network-based attacker to gain unauthorized control of the system.
A vulnerability in the ADPatch component of Oracle Applications DBA allows a low privileged attacker to achieve full system takeover via network access.
A vulnerability in the UK Payroll component of Oracle HRMS (UK) permits a low privileged attacker to compromise the application through network-based HTTP exploitation.
A vulnerability in the Solution Designer component of Oracle Communications Service Catalog and Design allows a low privileged attacker to compromise the software via network access.
A vulnerability in the Oracle Commerce Experience Manager component allows a low privileged, network-based attacker to gain full control over the application.
A critical flaw in the Oracle Commerce Experience Manager component enables a low privileged, network-based attacker to compromise the integrity and availability of the system.
A vulnerability in the User and User Group component of Oracle Agile PLM allows a low privileged, network-based attacker to gain unauthorized control of the application.
A security vulnerability in Oracle Agile PLM allows a low privileged, network-authenticated attacker to gain full control of the application via HTTP.
A vulnerability in the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process allows a low-privileged attacker to compromise the system.
A vulnerability in the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process allows low-privileged network-based attackers to compromise the system.
A vulnerability in the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina allows a low privileged attacker to achieve system takeover via network access.
A vulnerability in the Quality Management Specs component of Oracle Process Manufacturing Product Development allows a low privileged attacker to achieve system takeover via network access.
A vulnerability in the Internal Operations component of Oracle Product Hub allows a low privileged attacker to achieve system takeover via network access.
A vulnerability in the Internal Operations component of Oracle Payables allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Internal Operations component of Oracle TeleSales allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Claim LOV component of Oracle Trade Management allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Oracle Payroll component of Oracle E-Business Suite allows a low privileged attacker with network access to achieve a full system takeover.
A vulnerability in the Oracle Public Sector Payroll component of Oracle E-Business Suite allows a low privileged attacker to compromise the application via network access.
A vulnerability in the Oracle Public Sector Financials component of Oracle E-Business Suite allows a low privileged attacker to compromise the application via network access.
A vulnerability in the Oracle Yard Management component of Oracle E-Business Suite allows a low privileged, network-based attacker to compromise the application.
A vulnerability in the Oracle Flow Manufacturing component of Oracle E-Business Suite allows a low privileged, network-based attacker to compromise the application.
A vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain allows a low privileged, network-based attacker to compromise the application via SQL.
A high-severity vulnerability exists in the Web Utilities component of Oracle Applications Framework, allowing an authenticated attacker to compromise the application.
A high-severity vulnerability in the Enterprise Config Management component of Oracle Enterprise Manager allows an authenticated attacker to compromise the platform.
A high-severity vulnerability in the Metadata Plugin of Oracle Enterprise Manager allows an authenticated attacker to compromise the platform.
A vulnerability in the Metadata Plugin of Oracle Enterprise Manager Base Platform allows an unauthenticated attacker to compromise the system via network access.
A vulnerability in the Self Update Framework of Oracle Enterprise Manager Base Platform allows a low privileged attacker with network access to compromise the system.
A vulnerability in the Bill Issues component of Oracle Bills of Material allows a low privileged attacker to compromise the application via network access.
A vulnerability in the Oracle Access Manager Authentication Engine allows a low privileged attacker with network access to achieve a full system takeover.
A vulnerability in the Oracle GoldenGate Service Manager allows a low privileged attacker with network access to gain full control of the application.
A vulnerability in the Oracle Database Server RDBMS component allows an authenticated user to perform a complete system takeover.
A vulnerability in the Oracle WebLogic Server Core component allows a low privileged attacker to compromise the server via network access.
A vulnerability in the Oracle WebLogic Server Core component permits low privileged attackers to compromise the system via network access.
A vulnerability in the Oracle Coherence Core component allows an unauthenticated attacker on the physical communication segment to take over the software.
FUXA contains multiple vulnerabilities including code injection and authentication bypass, allowing unauthenticated attackers to compromise the system.
FUXA contains an incorrect authorization vulnerability that allows unauthenticated attackers to bypass security restrictions.
SMCI SMASH services on specific hardware models contain an OS command injection vulnerability that allows authenticated attackers to execute arbitrary code.
A vulnerability in MCMS v.6.1.1 allows remote, unauthenticated attackers to retrieve sensitive information by manipulating the source parameter.