Oracle
AI Threat Alert tracks 7 known AI/ML vulnerabilities affecting Oracle products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every Oracle CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| CRITICAL | CVE-2026-35304 | Oracle Coherence: unauthenticated HTTPS takeover | coherence | 9.8 |
| CRITICAL | CVE-2026-35305 | Oracle Coherence: unauth data exfiltration via bundled libs | coherence | 9.3 |
| CRITICAL | CVE-2026-35306 | Oracle Coherence: unauthenticated data access via HTTP | coherence | 9.3 |
| CRITICAL | CVE-2026-35307 | Oracle Coherence: unauthenticated RCE, CVSS 10.0 | coherence | 10.0 |
| CRITICAL | CVE-2026-35308 | Oracle Coherence: unauthenticated RCE via third-party jars | coherence | 10.0 |
| CRITICAL | CVE-2026-35309 | Oracle Coherence: unauthenticated RCE via HTTP (CVSS 9.8) | coherence | 9.8 |
| CRITICAL | CVE-2026-35310 | Oracle Coherence: unauthenticated HTTP full takeover | coherence | 9.8 |
Frequently asked questions
How many known vulnerabilities affect Oracle?
7 AI/ML CVEs affecting Oracle products are tracked, sourced from NVD and GitHub Advisory.
What Oracle products are affected?
The CVEs below map to the Oracle AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the Oracle vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor Oracle for new vulnerabilities?
AI Threat Alert tracks Oracle continuously; a Pro subscription adds breaking alerts when new CVEs affecting Oracle are published.
How do I assess Oracle's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity Oracle issues first and judge the exposure for your stack.