FAIL › dossier
Fusion Middleware
PRODUCT· dossier confidence 20%
Oracle Fusion Middleware exhibits a high frequency of critical unauthenticated RCE vulnerabilities, with a record July 2026 CPU addressing 1,449 fixes including ten CVSS 10.0 flaws. The company has shifted to monthly security cycles due to AI-driven discovery outpacing quarterly remediation.
PROFILE
CategoryEnterprise Software VendorWhat they doOracle Corporation provides enterprise information technology frameworks including cloud software as a service and enterprise resource planning solutions.
Websitehttps://www.oracle.com ↗
SECURITY POSTURE
High volume of critical unauthenticated RCE vulnerabilities in Fusion Middleware products, with a shift to monthly patch cycles due to AI-driven discovery outpacing quarterly remediation.
Notable failures
- CVE-2025-61757: Unauthenticated takeover via Identity Manager
- CVE-2021-35587: Unauthenticated takeover of Access Manager
- CVE-2020-2551: Unauthenticated compromise of WebLogic Core Components
- CVE-2012-1710: Remote compromise of WebCenter Forms Recognition
- CVE-2012-0518: Remote integrity impact in Single Sign-On
- CVE-2012-3152: Remote confidentiality/integrity impact in Reports Developer
Patterns: Repeated unauthenticated RCEs in Fusion Middleware; High volume of critical vulnerabilities in quarterly CPU; AI-driven vulnerability discovery outpacing remediation
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-25 | CVE-2012-1710 | critical | Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability. |
| 2025-11-21 | CVE-2025-61757 | high | Oracle Fusion Middleware exposed to unauthenticated takeover via Identity Manager |
| 2023-11-16 | CVE-2020-2551 | high | Oracle Fusion Middleware WLS Core Components RCE vulnerability |
| 2022-11-28 | CVE-2021-35587 | high | Oracle Fusion Middleware exposed to unauthenticated RCE via HTTP |
| 2021-11-03 | CVE-2012-3152 | high | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity. |
| 2022-03-28 | CVE-2012-0518 | high | Oracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity. |
| 2020-05-01 | CVE-2020-10683 | critical | CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti |
| 2012-05-03 | CVE-2012-1710 | critical | CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in |
DOSSIER SOURCES
- Oracle (ORCL) Company Profile & Description - Stock Analysis · stockanalysis.com
- Profile - CRDO - NASDAQ - Weiss Ratings · weissratings.com
- Oracle July 2026 CPU: 1,449 fixes and ten 10.0 unauth takeover flaws · kkm-mako.com
- Oracle July 2026 CPU: Critical Unauth Vulnerabilities · www.indusface.com
- Oracle's Record July Patch Update Signals a Shift to Monthly Security ... · adtmag.com
Open questions: Oracle's patch management process for Fusion Middleware components · Current security posture improvements post-2025 vulnerabilities
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:43:25.577925+00:00