📁
Fastify Static Path Traversal Guard Bypass
Teams running @fastify/static should upgrade to 10.1.1 promptly. Prioritize internet-facing applications that rely on route-scoped middleware for access control.
CVE-2026-15074 is a HIGH severity vulnerability with CVSS 7.5 affecting @fastify/static up to and including version 10.1.0. The flaw allows dot-dot path segments to bypass the earlier traversal fix, enabling an unauthenticated attacker to bypass route-scoped middleware and read files within the configured static root under guarded URL prefixes. The issue does not permit access outside the configured static root and is fixed in @fastify/static 10.1.1.
🔗 Read more 🔗
Source: NVD
🌐
facil.io WebSocket Parser Input Validation Flaw
Anyone exposing facil.io WebSocket services should treat this as urgent because a public exploit is available. Limit exposure and monitor for updates or mitigations if no patch exists yet.
CVE-2026-16632 is a HIGH severity vulnerability with CVSS 7.3 affecting boazsegev facil.io up to version 0.7.4. An improper input validation flaw in the WebSocket Frame Parser can be triggered remotely through manipulation of the on_message argument. The exploit has been published and the project has not responded to the reported issue.
🔗 Read more 🔗
Source: NVD
⚠️
Oracle Fusion Middleware Java Platform Takeover Risk
Oracle Fusion Middleware administrators should prioritize patching affected deployments. The combination of easy exploitation and takeover impact makes this a high-priority update.
CVE-2026-61246 is a HIGH severity vulnerability with CVSS 8.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with network access via HTTP can easily exploit the flaw and compromise the product. Successful attacks can result in full takeover of Oracle Platform Security for Java.
🔗 Read more 🔗
Source: NVD
🛡️
Oracle Java Security Component HTTP Compromise
Apply Oracle security updates as soon as practical across affected environments. Internet-accessible systems deserve immediate attention.
CVE-2026-60455 is a HIGH severity vulnerability with CVSS 8.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with network access via HTTP can easily exploit the flaw and compromise the product. Successful attacks can result in full takeover of Oracle Platform Security for Java.
🔗 Read more 🔗
Source: NVD
🔒
Oracle Platform Security HTTP Takeover Vulnerability
Organizations using affected Oracle Fusion Middleware releases should schedule patching with high priority. The ease of exploitation significantly raises operational risk.
CVE-2026-60439 is a HIGH severity vulnerability with CVSS 8.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable by a low privileged attacker over HTTP and may lead to complete compromise of the affected product.
🔗 Read more 🔗
Source: NVD
🚨
Oracle Middleware HTTP Takeover Bug
Patch affected Oracle environments promptly, especially where HTTP access is available to untrusted users. The exploitation requirements are relatively low.
CVE-2026-60373 is a HIGH severity vulnerability with CVSS 8.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with HTTP network access can easily exploit the flaw and achieve takeover of the affected component.
🔗 Read more 🔗
Source: NVD
🔥
Critical Unauthenticated Oracle Java Takeover
This should be treated as an emergency patch for exposed Oracle deployments. Internet-facing systems are the highest priority due to unauthenticated remote exploitation.
CVE-2026-60372 is a CRITICAL severity vulnerability with CVSS 9.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can easily exploit the flaw and take over the affected product. No authentication is required for successful compromise.
🔗 Read more 🔗
Source: NVD
🔌
Oracle Java Adjacent Network Attack Vulnerability
Patch during the next high-priority maintenance window, particularly in environments with shared or exposed network segments. Although exploitation is more difficult, the impact is substantial.
CVE-2026-60371 is a HIGH severity vulnerability with CVSS 8.0 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. Exploitation requires a low privileged attacker with access to the physical communication segment attached to the hardware. Successful attacks can result in takeover of the product and may impact additional products because of scope change.
🔗 Read more 🔗
Source: NVD
🌐
Oracle HTTP Vulnerability Enables Product Takeover
Patch affected Oracle systems on a prioritized schedule. The attack is harder to execute than related flaws but still carries severe impact.
CVE-2026-60370 is a HIGH severity vulnerability with CVSS 7.5 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with HTTP network access can exploit the flaw despite higher attack complexity. Successful exploitation can result in takeover of Oracle Platform Security for Java.
🔗 Read more 🔗
Source: NVD
🚨
Critical Oracle Scope Change Takeover Flaw
Treat this as one of the highest-priority Oracle patches due to the CVSS 9.9 rating and scope change. Address internet-accessible deployments immediately.
CVE-2026-60369 is a CRITICAL severity vulnerability with CVSS 9.9 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with HTTP network access can easily compromise the product, and attacks may significantly impact additional products because of scope change. Successful exploitation can result in takeover of Oracle Platform Security for Java.
🔗 Read more 🔗
Source: NVD
🧩
Oracle SOAP Interface Takeover Vulnerability
Patch systems exposing SOAP interfaces without delay. Review external SOAP endpoints while rolling out Oracle updates.
CVE-2026-60368 is a HIGH severity vulnerability with CVSS 8.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. A low privileged attacker with network access via SOAP can easily exploit the flaw and take over the affected product.
🔗 Read more 🔗
Source: NVD
🚨
Unauthenticated Oracle HTTP Critical Vulnerability
Patch immediately wherever affected Oracle services are reachable over the network. Unauthenticated remote compromise makes this an emergency remediation item.
CVE-2026-60367 is a CRITICAL severity vulnerability with CVSS 9.8 affecting Oracle Platform Security for Java in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can easily exploit the vulnerability and take over the affected product. The flaw requires no prior authentication.
🔗 Read more 🔗
Source: NVD