Announcements

MA-1475.072026: MyCERT Advisory - Oracle E-Business Suite Improper Privilege Management Vulnerability

  • 22nd July 2026
On July 22, 2026, cybersecurity response team MyCERT released a public advisory identifying a security vulnerability in Oracle E-Business Suite. The flaw is categorized as an improper privilege management issue, meaning there is a potential for users of the software to access features, data, or administrative functions they are not authorized to ...
Continue reading

CVE-2026-60363 (matched: apache http server)

  • 22nd July 2026
A security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The supported versions confirmed to be affected are 12.2.1.4.0 and 14.1.2.0.0.This flaw is easily exploitable: an attacker does not need any login credentials to carry out an attack, as long as they can send standard ...
Continue reading

CVE-2026-48687 (matched: php)

  • 22nd July 2026
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in DD-WRT, a popular firmware used by many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error, that impacts the router's UPnP (Universal Plug and Play) feature, a tool designed to help devices on a local network automatically discover and connect ...
Continue reading