Announcements

MA-1475.072026: MyCERT Advisory - Oracle E-Business Suite Improper Privilege Management Vulnerability

  • 23rd July 2026
On July 22, 2026, cybersecurity agency MyCERT published an advisory for a security flaw in Oracle E-Business Suite related to improper privilege management.Privilege management is the system that controls which users can access specific features, data, and functions within business software. A flaw in this system means the suite may fail to ...
Continue reading

CVE-2026-60363 (matched: apache http server)

  • 23rd July 2026
A critical security vulnerability has been identified in a component of Oracle’s Fusion Middleware called Oracle HTTP Server, specifically in its Apache Plugin module. Only versions 12.2.1.4.0 and 14.1.2.0.0 of this product are confirmed to be affected by this flaw.This issue is very easy for attackers to exploit. An unauthenticated user ...
Continue reading

CVE-2026-48907 (matched: php)

  • 23rd July 2026
A security flaw has been discovered in the JCE editor extension used by many Joomla content management system websites. The issue lets people who do not have authorized login access to your site create new editor profiles for your Joomla installation. If attackers exploit this flaw, they can use those unauthorized profiles to upload and run ...
Continue reading

CVE-2026-48687 (matched: php)

  • 23rd July 2026
A security flaw has been identified in FastNetMon Community Edition, affecting all versions up to 1.2.9. This is a command injection vulnerability that could allow unauthorized people to run unapproved commands on servers where this software is installed.The flaw exists in a plugin designed to connect FastNetMon to Juniper routers. The plugin ...
Continue reading