Top impactful security developments (2026-07-23 07:34) - 1 day summary
High‑impact security incidents reported between the start of the monitoring window and 2026‑07‑23
| # | CVE / EUVD ID | Product / Component (what is affected) | CVSS v3.1 Score* | Brief technical impact | Affected versions (when disclosed) | Source link |
|---|---|---|---|---|---|---|
| 1 | CVE‑2026‑60366 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 10.0 (Critical) | Unauthenticated attacker can execute arbitrary code over HTTP, leading to full takeover of the Java security runtime. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60366 |
| 2 | CVE‑2026‑60367 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 9.8 (Critical) | Remote unauthenticated code execution via HTTP; same “take‑over” impact as above. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60367 |
| 3 | CVE‑2026‑60369 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 9.9 (Critical) | Remote unauthenticated attacker can compromise the platform via HTTP, full control of the Java security component. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60369 |
| 4 | CVE‑2026‑60372 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 9.8 (Critical) | Same remote code execution / takeover scenario, unauthenticated over HTTP. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60372 |
| 5 | CVE‑2026‑60373 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 8.8 (High) | Low‑privileged attacker with network access can compromise the component via HTTP; leads to full takeover. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60373 |
| 6 | CVE‑2026‑60368 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 8.8 (High) | Remote low‑privileged attacker can exploit via HTTP to gain control of the security runtime. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60368 |
| 7 | CVE‑2026‑60439 | Oracle Platform Security for Java – Centralized Third‑party JARs module | 8.8 (High) | Same remote code execution path; attacker gains full platform takeover. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60439 |
| 8 | CVE‑2026‑60455 | Oracle Platform Security for Java – Centralized Third‑party Jars module | 8.8 (High) | Remote low‑privileged exploitation over HTTP, leading to full compromise. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-60455 |
| 9 | CVE‑2026‑61246 | Oracle Platform Security for Java – Centralized Third‑party Jars module | 8.8 (High) | Remote unauthenticated attacker can take over the component via HTTP. | 12.2.1.4.0 & 14.1.2.0.0 | https://cveawg.mitre.org/api/cve/CVE-2026-61246 |
| 10 | EUVD‑2026‑47855 | Oracle Platform Security for Java – Centralized Third‑party Jars (same code base) | 9.9 (Critical) | Same exploitation chain as the CVEs above; unauthenticated remote takeover via HTTP. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47855 |
| 11 | EUVD‑2026‑47856 | Oracle Platform Security for Java – Centralized Third‑party Jars | 9.8 (Critical) | Remote unauthenticated takeover via HTTP. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47856 |
| 12 | EUVD‑2026‑47858 | Oracle Platform Security for Java – Centralized Third‑party Jars | 10.0 (Critical) | Remote unauthenticated attacker can fully compromise the component; highest severity observed. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47858 |
| 13 | EUVD‑2026‑47849 | Oracle Platform Security for Java – Centralized Third‑party Jars | 8.8 (High) | Remote low‑privileged exploitation via HTTP, leading to takeover. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47849 |
| 14 | EUVD‑2026‑47852 | Oracle Platform Security for Java – Centralized Third‑party Jars | 9.8 (Critical) | Remote unauthenticated takeover via HTTP. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47852 |
| 15 | EUVD‑2026‑47854 | Oracle Platform Security for Java – Centralized Third‑party Jars | 7.5 (High) | Exploitable but requires higher attack complexity; still grants full control. | 12.2.1.4.0 & 14.1.2.0.0 | https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47854 |
*CVSS scores are taken directly from the EUVD and CVE feeds included in the source data.
Why these items dominate Priority 1
- Library / framework focus – All entries target Oracle Platform Security for Java, a core security library used by Oracle Fusion Middleware. Compromise of this component effectively defeats any Java‑based application’s security guarantees.
- Score range 7–10 – Every listed vulnerability falls in the “High” (≥ 7) to “Critical” (≥ 9) band, satisfying the CVSS threshold for Priority 1.
- Authentication / encryption relevance – The affected module handles TLS/SSL certificate validation and cryptographic operations for Java applications; a remote attacker can bypass authentication checks and execute arbitrary code.
- Broad impact – Versions 12.2.1.4.0 and 14.1.2.0.0 are widely deployed in enterprise middleware, meaning the attack surface spans many on‑premise and cloud installations.
Other notable incidents (Priority 3)
| Incident | Description | Why it matters |
|---|---|---|
Ransomware groups “Kairos”, “Qilin”, “Chaos”, “Brain” etc. – multiple Mastodon posts from the Ransomlook feed (e.g., New post from # Kairos : Lr Reed More …) |
Large‑scale ransomware campaigns targeting enterprises; however, no technical CVE or exploit details were disclosed in the provided data. | Mentioned for completeness but does not meet the “technical detail” requirement of Priority 1/2. |
Phishing URL feeds (URLDNA scans) – dozens of URLs flagged as possible phishing (e.g., hxxp://trackyourpackageusps.blogspot.cl) |
Massive phishing campaign, but unrelated to software libraries or zero‑day exploits. | Outside the scope of the requested priorities. |
Take‑away for defenders
- Patch immediately – All affected Oracle Fusion Middleware installations should be upgraded to a version that includes the fixes released in Oracle’s July 2026 CPU (Critical Patch Update). The advisory links are embedded in each CVE/EUVD entry.
- Validate Java runtime libraries – Verify that no legacy
oracle.security.jpsJARs from the vulnerable versions remain on the classpath after upgrade. - Network segmentation – Since exploitation is possible over plain HTTP, restrict access to middleware endpoints to trusted networks or enforce TLS termination at a perimeter device.
- Monitor for exploit activity – Look for unusual outbound connections from Java processes to unknown hosts; many of these CVEs are actively exploited in the wild (as indicated by multiple EUVD posts posted on the same day).
All URLs above are directly taken from the supplied Mastodon/EUVD/CVE feeds and point to the original advisory or API entry.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster