Daily briefing · July 21, 2026

Oracle Fusion Middleware Flooded With CVSS 10.0 Flaws in Quiet July Patch Wave

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

July 21, 2026 was a calm day on the exploitation front — no active KEV entries, no weaponized exploits, and no VulnCheck pre-CISA signals — but Oracle's Critical Patch Update dropped an unusually dense cluster of perfect-score vulnerabilities across its Fusion Middleware stack. With 1,453 new CVEs published and 262 rated critical, the day's story is one of patch urgency rather than active emergency, demanding immediate attention from teams running Oracle middleware in production.

Today’s brief
  • Eight Oracle Fusion Middleware products received CVSS 10.0 flaws — all unauthenticated, network-exploitable, zero interaction required.
  • Two Autel MaxiCharger EV charger CVEs (CVSS 10.0, PoC available) expose unauthenticated OS command injection and RCE with root privileges on TCP port 9002.
  • No vulnerabilities entered active exploitation (KEV) on this day — threat is high-severity patch debt, not immediate in-the-wild fire.
  • Ransomware activity in Brazil remains intense: lockbit5, nova, Doommageddon, qilin, and unsafe all struck Brazilian targets recently.
262
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-60644CVSS 10affects Oracle WebCenter Content
A CVSS 10.0 unauthenticated remote compromise flaw in Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) via HTTP; successful exploitation can cascade to impact additional Oracle products beyond the directly affected component, making it a critical pivot point in any Fusion Middleware deployment.
2
CVE-2026-60389CVSS 10affects Service Delivery Platform
Oracle Service Delivery Platform's Messaging Enabler component (12.2.1.4.0 and 14.1.2.0.0) is fully compromisable by an unauthenticated attacker over HTTP with no user interaction; the ripple-effect language in Oracle's advisory suggests broader infrastructure impact should exploitation occur.
3
CVE-2026-60379CVSS 10affects Service Delivery Platform
A second CVSS 10.0 flaw in the same Oracle Service Delivery Platform Messaging Enabler component, this one exploitable over SOAP; organizations exposing SOAP endpoints externally should treat this as equivalent urgency to its HTTP sibling CVE-2026-60389.
4
CVE-2026-60365CVSS 10affects Oracle HTTP Server
The Oracle WebLogic Server Proxy Plug-In for third-party web servers (version 15.1.1.0.0) carries a perfect-score unauthenticated HTTP flaw that can compromise the underlying Oracle HTTP Server; environments using Apache HTTP Server or OHS as a WebLogic proxy front-end are directly in scope.
5
CVE-2026-60360CVSS 10affects Oracle Unified Directory
Oracle Unified Directory's OUD Core component (12.2.1.4.0 and 14.1.2.1.0) is exploitable over LDAP by an unauthenticated attacker, threatening the identity backbone of any organization using OUD as its directory service — a compromise here can enable broad lateral movement.
6
CVE-2026-60358CVSS 10affects Oracle Access Manager
Oracle Access Manager's Authentication Engine (12.2.1.4.0 and 14.1.2.1.0) can be fully taken over by an unauthenticated HTTP attacker; given OAM's role as a single sign-on gateway, exploitation could grant an attacker control over authentication for an entire enterprise application portfolio.
7
CVE-2026-60217CVSS 10affects Oracle Coherence
Oracle Coherence's Core component across four versions (12.2.1.4.0 through 15.1.1.0.0) is exploitable over TCP without authentication; Coherence is widely used as a distributed cache and session store, meaning compromise can expose sensitive application data at scale.
8
CVE-2026-47056CVSS 10affects Oracle Data Integrator
Oracle Data Integrator's REST Service component (12.2.1.4.0 and 14.1.2.0.0) allows unauthenticated full compromise via HTTP; ODI typically has privileged database connectivity, so an attacker gaining control could directly reach underlying data stores and ETL pipelines.
9
CVE-2026-8985CVSS 10PoCaffects MaxiCharger Single
A CVSS 10.0 OS command injection flaw in Autel MaxiCharger Single firmware (through V1.03.51) exposed on TCP port 9002, with a public proof-of-concept available; any charger reachable from the network is vulnerable to arbitrary command execution without any credentials.
10
CVE-2026-8984CVSS 10PoCaffects MaxiCharger Single
A companion unauthenticated RCE flaw in the same Autel MaxiCharger Single firmware on TCP port 9002 allows an attacker to push, extract, and execute arbitrary files with root privileges; with PoC code available, these EV charger flaws are one weaponization step away from becoming a serious OT/IoT threat.
Ransomware today

Ransomware groups have been highly active against Brazilian targets in recent days. Lockbit5 alone claimed multiple victims spanning manufacturing (grupoferrosider.com.br, limpebras.com.br), education (uniplaclages.edu.br), technology (technicare.com.br, kenta.com.br), and business services (guarnera.com.br, gruposelpe.com.br). Beyond lockbit5, the groups qilin (PP+K), nova (Jota Joias Premium, FMZ Tecnologia em Sistemas), Doommageddon (Reni Farmácias Associadas), and unsafe (CCR Solutions) also listed Brazilian organizations — underscoring that Brazil remains a primary hunting ground for multiple concurrent ransomware operations.

PP+K BRqilin
Jota Joias Premium BRnova · Consumer Services
Reni Farmácias Associadas BRDoommageddon · Healthcare
CCR Solutions BRunsafe · Business Services
grupoferrosider.com.br BRlockbit5 · Manufacturing
limpebras.com.br BRlockbit5 · Manufacturing
uniplaclages.edu.br BRlockbit5 · Education
technicare.com.br BRlockbit5 · Technology
FMZ Tecnologia em Sistemas BRnova · Technology
guarnera.com.br BRlockbit5 · Business Services
gruposelpe.com.br BRlockbit5 · Business Services
kenta.com.br BRlockbit5 · Technology
lockbit5 49lockbit3 39ransomhub 35thegentlemen 208base 20arcusmedia 19
Active groups & APTs

Several threat actors and APT-tracked groups have been flagged as active or updated in current intelligence feeds, including blackshadow (attributed to Iran), coinbasecartel, kazu, kelvinsecurity, krybit, and apt73. While no confirmed victims are currently attributed to these groups in the latest data, their presence in threat intelligence platforms signals active infrastructure or reconnaissance operations that defenders should monitor.

Brazil focus

Brazil is facing an exceptionally concentrated ransomware campaign period, with at least twelve organizations across diverse sectors listed as recent victims. The healthcare sector was hit by Doommageddon targeting Reni Farmácias Associadas, a particularly sensitive target given patient data implications. Lockbit5 dominates the Brazilian threat landscape over the past 30 days with 49 recorded victims, followed by lockbit3 (39), ransomhub (35), thegentlemen (20), 8base (20), and arcusmedia (19) — indicating that Brazilian organizations of all sizes and sectors are under sustained, multi-group pressure.

Reni Farmácias AssociadasDoommageddon · Healthcare
PP+Kqilin
Jota Joias Premiumnova · Consumer Services
CCR Solutionsunsafe · Business Services
kenta.com.brlockbit5 · Technology
gruposelpe.com.brlockbit5 · Business Services
guarnera.com.brlockbit5 · Business Services
grupoferrosider.com.brlockbit5 · Manufacturing
Today’s recommendation: Prioritize immediate patching of all Oracle Fusion Middleware components affected by today's CVSS 10.0 disclosures, particularly Oracle Access Manager and Oracle Unified Directory given their identity-critical roles; simultaneously, audit network exposure of Autel MaxiCharger devices and restrict TCP port 9002 access pending vendor firmware updates, as proof-of-concept code is already available for those two flaws.
The breadth of today's critical disclosures — spanning enterprise middleware, identity systems, and OT/IoT devices — is a strong reminder that understanding exactly which of these surfaces are reachable in your environment is the only way to prioritize response before a calm day becomes an active incident.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →