<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Oracle</title><description>Actively exploited vulnerabilities affecting Oracle products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/oracle.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-46817 — Oracle E-Business Suite Improper Privilege Management Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-46817</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-46817</guid><description>This vulnerability in Oracle E-Business Suite allows an unauthenticated attacker to remotely compromise Oracle Payments over HTTP — no credentials required. A successful exploit can result in a full takeover of the Oracle Payments component, meaning an attacker could manipulate financial transactions, access sensitive payment data, or disrupt payment processing entirely. Because no authentication barrier exists, any internet-exposed instance is at heightened risk and should be treated as a priority.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>E-Business Suite</category></item><item><title>CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-35273</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-35273</guid><description>This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker — someone with no credentials whatsoever — to completely take over the affected system. PeopleSoft is widely used for HR, finance, and enterprise management, making a full takeover especially damaging. The flaw is already being exploited in ransomware campaigns, meaning real-world attacks are active and the window for remediation is narrow. Any internet-exposed PeopleSoft instance should be treated as critically at risk.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Oracle</category><category> PeopleSoft Enterprise PeopleTools</category></item><item><title>CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-21182</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-21182</guid><description>Oracle WebLogic Server contains a flaw reachable over the T3 and IIOP network protocols without any authentication. An attacker who can reach the server on these ports could silently read sensitive data or gain complete access to everything the server can access. Because no credentials are required, the attack surface extends to any network-exposed WebLogic instance, making this a high-priority risk for organizations running WebLogic in internet-facing or multi-tenant environments.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>Oracle</category><category>WebLogic Server</category></item><item><title>CVE-2025-61757 — Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-61757</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-61757</guid><description>Oracle Fusion Middleware&apos;s Identity Manager can be fully taken over by an unauthenticated remote attacker due to a missing authentication check on a critical function. This means no credentials are required to exploit it — an internet-exposed instance could be compromised by anyone who can reach it. Identity Manager controls user provisioning and access across enterprise systems, so a takeover could lead to unauthorized account creation, privilege escalation, or broad lateral movement across the organization.</description><pubDate>Fri, 21 Nov 2025 00:00:00 GMT</pubDate><category>Oracle</category><category>Fusion Middleware</category></item><item><title>CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-61884</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-61884</guid><description>This unauthenticated SSRF flaw in Oracle E-Business Suite&apos;s Configurator component allows a remote attacker to force the server to make arbitrary internal network requests without needing any credentials. In practice, this can be used to probe internal infrastructure, bypass network perimeter controls, or pivot deeper into an environment. The fact that ransomware operators are already exploiting this vulnerability makes it an urgent priority for any organization running Oracle E-Business Suite.</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate><category>Oracle</category><category>E-Business Suite</category></item><item><title>CVE-2025-61882 — Oracle E-Business Suite Unspecified Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-61882</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-61882</guid><description>This vulnerability in Oracle E-Business Suite&apos;s BI Publisher Integration component allows an unauthenticated attacker over a standard HTTP connection to fully take over Oracle Concurrent Processing — the system that manages background jobs and batch operations. No credentials are required to exploit this, making it particularly dangerous on any internet-exposed or network-accessible EBS instance. It has already been linked to active ransomware campaigns, meaning real-world attackers are actively exploiting it.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate><category>Oracle</category><category>E-Business Suite</category></item></channel></rss>