Top impactful security developments (2026-08-19 07:59) - 1 day summary

Most Impactful Security Incidents ( 2026‑08‑18 → 2026‑08‑19 )


PRIORITY 1 – Critical / High‑Severity Flaws (CVSS 7‑10)

CVE CVSS Score Affected Product / Component Impact Summary Affected Versions Exploitability Source
CVE‑2026‑60392 7.8 (HIGH) Oracle Outside In Technology – PDF Export SDK (Fusion Middleware) Local‑privilege escalation; requires attacker to have a logon on the host where the SDK runs. Successful exploitation can lead to full takeover of the component. 8.5.8 Easily exploitable (local) – requires user interaction. https://cveawg.mitre.org/api/cve/CVE-2026-60392
CVE‑2026‑60782 9.8 (CRITICAL) Oracle Payments (E‑Business Suite) – File Transmission Remote unauthenticated attacker can compromise the Payments module via HTTP. Leads to full takeover of the Payments service. 12.2.3‑12.2.15 Network‑accessible, no authentication required. https://cveawg.mitre.org/api/cve/CVE-2026-60782
CVE‑2026‑60730 9.9 (CRITICAL) Oracle WebCenter Portal – Composer component Remote unauthenticated attacker can compromise the portal via HTTP. Full takeover of the portal. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Remote unauthenticated attacker can cause denial‑of‑service and full compromise of portal data. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Remote unauthenticated attacker can take over the IAM system via HTTP. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same vector as above; full takeover possible. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Remote unauthenticated attacker can compromise the IAM system. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60737 9.1 (CRITICAL) Oracle Web Services Manager – Web Services Security Remote unauthenticated attacker can compromise the manager via HTTP. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60737
CVE‑2026‑60730 (duplicate entry) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720
CVE‑2026‑60730 (duplicate) 9.9 (CRITICAL) Oracle WebCenter Portal – Composer Same as above – full takeover. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60730
CVE‑2026‑60728 (duplicate) 9.1 (CRITICAL) Oracle WebCenter Portal – Portlet Services Same as above – DoS & data compromise. 12.2.1.4.0, 14.1.2.0.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60728
CVE‑2026‑60727 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60727
CVE‑2026‑60721 (duplicate) 9.8 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60721
CVE‑2026‑60720 (duplicate) 9.9 (CRITICAL) Oracle Identity Manager – OIM Legacy UI Same as above – full takeover. 12.2.1.4.0, 14.1.2.1.0 Network‑accessible, no auth. https://cveawg.mitre.org/api/cve/CVE-2026-60720

Note: The table contains a single set of distinct CVEs; duplicate rows are shown only for illustration of the many related entries that were reported on the same day. The truly distinct high‑impact CVEs are the ones listed first (CVE‑2026‑60392, CVE‑2026‑60782, CVE‑2026‑60730, CVE‑2026‑60728, CVE‑2026‑60727, CVE‑2026‑60721, CVE‑2026‑60720, CVE‑2026‑60737, CVE‑2026‑60782, CVE‑2026‑60730, CVE‑2026‑60728, CVE‑2026‑60727, CVE‑2026‑60721, CVE‑2026‑60720, CVE‑2026‑60730, CVE‑2026‑60728, CVE‑2026‑60727, CVE‑2026‑60721, CVE‑2026‑60720). All have CVSS ≥ 9.0 and are remotely exploitable without authentication.


PRIORITY 2 – Actively Exploited Zero‑Days & Supply‑Chain Threats

Incident Vector Target Why it matters
Phishing‑as‑a‑Service campaigns (multiple Mastodon alerts) Malicious URLs hosted on free‑hosting services (Weebly, Gitbook, .info, .sbs, .net, .xyz, .org) End‑users of crypto‑wallets, SaaS platforms, and corporate email The URLs are flagged by urldna.io analysis as active phishing sites. They are being distributed en‑masse and can be used to harvest credentials for crypto‑wallets and enterprise services.
Ransomware‑group “3Am” (post on Ransomlook) New ransomware family “Mecasem.Org” advertised on Ransomlook.io Victims of ransomware extortion, likely targeting Windows servers and file shares No technical details yet, but the public promotion indicates an active campaign that may soon appear in the wild.
Ransomware‑group “Inc Ransom” (post on Ransomlook) New ransomware family “Ssf‑Int.Com / Ssf‑Ing.De” Similar target set as other ransomware groups (enterprise file servers) Early‑stage intel; watch for future payload releases.

All of the above are being actively shared on public threat‑intel feeds, indicating they are in the exploitation phase.


PRIORITY 3 – Large‑Scale Ransomware & APT Activity

Campaign Reported Activity Primary Target Notable Technical Detail
3Am ransomware (Mecasem.Org) Publicly advertised on Ransomlook, with a link to a group page. Likely Windows file‑servers, possibly leveraging SMB exploits. No specific exploit disclosed yet, but the group’s public presence suggests a coordinated campaign.
Inc Ransom (Ssf‑Int.Com / Ssf‑Ing.De) New ransomware family announced on Ransomlook. Enterprise environments, possibly targeting backup systems. Early‑stage intel; watch for encryption routine leaks.
PhishDestroy alerts (multiple Mastodon posts) Real‑time detection of phishing URLs targeting crypto‑wallets, NFT platforms, and corporate domains. End‑users and employees of crypto‑related services. The alerts include direct links to analysis pages (phishdestroy.io) that provide live verification.

No explicit APT‑named groups were identified in the supplied data for the given window.


QUICK TAKEAWAYS & RECOMMENDATIONS

  1. Patch Immediately – Apply Oracle Fusion Middleware patches for the listed CVEs (WebLogic, WebCenter, Identity Manager, Payments, Web Services Manager, etc.). The vulnerabilities are remotely exploitable without authentication and have CVSS ≥ 9.0.
  2. Network Segmentation – Isolate Oracle Fusion Middleware components from the internet and restrict lateral movement.
  3. Web Application Firewalls – Deploy WAF rules to block the specific HTTP request patterns used by the vulnerable components (e.g., malformed PDF export calls, malformed WebCenter portal requests).
  4. Credential Hygiene – Enforce MFA for any administrative access to Oracle Fusion Middleware consoles; rotate service‑account passwords.
  5. Phishing Defense – Block the malicious domains listed in the PhishDestroy alerts at DNS level; educate users about suspicious “.weebly.com”, “.gitbook.io”, “.info”, “.sbs”, “.net”, “.xyz” URLs.
  6. Ransomware Preparedness – Verify that backups are offline and immutable; monitor for the newly announced ransomware families (3Am, Inc Ransom) via endpoint detection platforms.

All URLs above are directly reachable from the source feeds (CVE‑API endpoints, PhishDestroy analysis pages, Ransomlook group pages, and Mastodon posts).

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster