BoletimSecAugust 20, 2026🇵🇹Translated from Portuguese

Oracle Issues Emergency Patches for Critical Remotely Exploitable WebLogic Server Vulnerabilities

Oracle has published an emergency security update on 18 August containing 943 new patches for dozens of enterprise product families. The package addresses vulnerabilities across platforms including WebLogic Server, Fusion Middleware, E-Business Suite, Oracle Database, and Commerce.

Among the most severe issues are remotely exploitable vulnerabilities in Oracle WebLogic Server that require no authentication. The flaws CVE-2026-60698, CVE-2026-60672, CVE-2026-60696, and CVE-2026-60977 were assigned CVSS scores of 9.8. These affect core components of WebLogic through the IIOP, T3, and RMI protocols. Successful exploitation can compromise the confidentiality, integrity, and availability of the affected server depending on the specific vulnerability.

Another critical finding is CVE-2026-61241 in the LDAP server of Oracle Internet Directory. This vulnerability received the maximum CVSS score of 10.0, can be exploited over the network without credentials, and impacts versions 12.2.1.4.0 and 14.1.2.1.0.

Oracle recommends keeping installations on actively supported releases and applying patches as soon as possible. The company referenced previous cases where already-patched vulnerabilities were exploited against outdated systems. Validation of patches in test environments is advised to reduce operational risks before production rollout.

Related articles

HabrVulnerabilities & Exploits

Mind Games: 30 Years of Hacking and Securing Game Consoles

The article traces the evolution of security mechanisms in home game consoles from the unprotected Atari 2600 in 1977 through hardware locks, optical media protections, and cryptographic boot chains up to the seventh generation. Early systems like the NES relied on the 10NES/CIC chip for mutual authentication using identical Sharp SM590 microcontrollers, which was quickly defeated by Tengen's Rabbit clone and physical pin-clipping attacks. PlayStation introduced SCEx regional signals on discs, leading to widespread modchip installations and swap tricks that bypassed all code verification. Microsoft’s original Xbox implemented a full cryptographic chain of trust starting from the MCPX southbridge, yet it fell to HyperTransport bus sniffing by bunnie Huang and buffer overflows in titles such as MechAssault. Nintendo Wii’s Twilight Hack exploited a stack overflow via an excessively long horse name in The Legend of Zelda: Twilight Princess, enabling unsigned code execution. The piece highlights recurring lessons about the limits of security-through-obscurity and the necessity of protecting both boot chains and runtime memory handling.

BoletimSecVulnerabilities & Exploits

Google Patches Two Critical Memory Corruption Flaws in Chrome WebGL and Dawn Components

Google has issued a security update for Chrome that addresses 15 vulnerabilities, two of which are rated critical. The flaws, tracked as CVE-2026-76034 and CVE-2026-76036, involve buffer overflow conditions that can lead to out-of-bounds memory writes. CVE-2026-76034 affects the WebGL component used for 2D and 3D graphics rendering on web pages, while CVE-2026-76036 impacts Dawn, the Chromium implementation of WebGPU. Both issues were discovered internally and could result in crashes or remote code execution in certain scenarios. Updated versions are now available for Windows, macOS, Linux, and Android, and users are strongly advised to apply the patches immediately.

Security NEXTVulnerabilities & Exploits

Oracle Releases August 2026 Monthly Security Patches Fixing 943 Vulnerabilities

Oracle has published its monthly Critical Security Patch Update on August 18, 2026, addressing a total of 943 vulnerabilities across a wide range of products. This release supplements the company's quarterly Critical Patch Update and includes fixes for third-party software issues, resulting in 925 unique CVEs after removing duplicates. Of these, 710 vulnerabilities received CVSSv3 base scores of 7.0 or higher, with 154 scoring 9.0 or above, including three at the maximum 10.0. A total of 467 flaws can be exploited remotely without authentication. Major products affected include Oracle Fusion Middleware with 262 patches, Oracle E-Business Suite with 120 fixes, and Oracle Database Server with six updates. The next monthly update is scheduled for September 15, 2026, followed by the quarterly release on October 20.

AntiMalwareVulnerabilities & Exploits

PoC Exploit Released for Android CVE-2026-0075 Allowing Contact Theft Without READ_CONTACTS Permission

A researcher has published a proof-of-concept exploit for CVE-2026-0075 affecting Android 14, 15, 16 and 16 QPR2. The flaw resided in the ContactsProvider2 component and enabled local applications to extract contact database entries through SQL injection and verbose SQLite error responses, bypassing the need for any user-granted permissions. Google rated the issue high severity and addressed it in the June 2026 security bulletin by stripping detailed JSON error information from responses to unprivileged apps. The publicly available PoC on GitHub deliberately avoids requesting READ_CONTACTS or WRITE_CONTACTS and is intended strictly for lab comparison of patched versus vulnerable builds. No confirmed in-the-wild exploitation has been observed yet, but the release of working code increases risk for devices running older firmware. Users are advised to verify that their devices have received the security patch dated 5 June 2026 or later.