< ciso
brief />
Tag Banner

All news with #oracle tag

92 articles · page 2 of 5

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Oracle WebLogic vulnerability, CVE-2024-21182 (CVSS 7.5), to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The flaw permits unauthenticated network attackers to compromise servers via T3 and IIOP protocols and was patched by Oracle in July 2024. Federal agencies are urged to apply fixes by June 4, 2026, to protect critical data and systems.
read more →

CISA orders federal patch for WebLogic zero-day

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch an actively exploited Oracle WebLogic vulnerability, CVE-2024-21182, by June 4 under BOD 22-01. The flaw affects Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 and enables unauthenticated remote compromise via T3/IIOP. Shodan reports over 1,592 exposed and vulnerable WebLogic instances, and CISA urges all organizations to apply vendor mitigations or discontinue use if fixes are unavailable.
read more →

Oracle launches monthly Critical Security Patch Update

🔒 Oracle has issued its first monthly Critical Security Patch Update (CSPU), addressing 35 vulnerabilities that require more urgent attention than quarterly releases. The batch includes 11 critical, 18 high, and 6 medium severity flaws, with several affecting Oracle REST Data Services, Oracle E-Business Suite, and Oracle Payments. Some older supply-chain bugs have public proof-of-concept exploits, increasing patching urgency.
read more →

Amazon RDS for Oracle adds April 2026 RU and SPB

🔔 Amazon RDS for Oracle now supports the Oracle April 2026 Release Update (RU) for 19c and 21c and the Supplemental Patch Bundle (SPB) for 19c. The SPB, formerly the Oracle Spatial Patch Bundle, contains additional patches for targeted features such as Oracle Spatial, Data Pump, and GoldenGate. You can apply the RU or SPB via the RDS Console, SDK, or CLI and enable Automatic Minor Version Upgrade or use AWS Organizations rollout policies to stagger updates across environments.
read more →

Oracle Database@AWS expands to twenty AWS regions

🟢 Oracle Database@AWS is now generally available in eight additional AWS Regions — Zurich, Milan, Spain, Paris, Osaka, Singapore, Melbourne, and Sao Paulo — enabling customers to access OCI-managed Oracle Exadata systems from within AWS data centers. This expansion brings the service to twenty regions total, supporting migrations of on-premises Oracle Exadata and Oracle RAC workloads and meeting in-region data residency requirements. Customers can request a private offer from Oracle via the AWS Marketplace and configure databases through the AWS Management Console.
read more →

Oracle moves to monthly security patches to counter AI

🔔 Oracle will issue monthly Critical Security Patch Updates (CSPUs) for its ERP, database and other software, shifting from a quarterly cadence to address faster AI-driven vulnerability discovery. The first monthly CSPU will arrive May 28, then releases will follow on the third Tuesday of each month (June 16, July 21, August 18). Oracle will still publish a cumulative quarterly Critical Patch Update and will auto-apply fixes for customers in Oracle-managed cloud environments. The change primarily affects customers running Oracle software on premises or in third-party hosting.
read more →

Oracle AI Database@Google Cloud: Enabling Agentic AI

🧭 Oracle AI Database@Google Cloud brings Oracle's mission-critical databases natively into Google Cloud to enable direct pipelines from enterprise records to the AI layer. The announcement expands regional availability, introduces an Oracle AI Database Agent for Gemini interaction, and integrates with Database Center, Knowledge Catalog, OCI GoldenGate, and VPC Service Controls. These features aim to lower latency, simplify governance, and make Oracle data actionable for agentic AI workflows.
read more →

Oracle Database@AWS Expands to Twelve AWS Regions Globally

🚀 Oracle Database@AWS is now generally available in five additional AWS Regions — EU-West-1 (Dublin), EU-West-2 (London), AP-South-1 (Mumbai), AP-South-2 (Hyderabad), and AP-Northeast-2 (Seoul) — expanding coverage to twelve Regions. The service enables AWS customers to access OCI-managed Oracle Exadata systems from within AWS data centers, supporting in-region data residency and migrations of on-prem Exadata and RAC workloads. Dublin, Mumbai, and Hyderabad offer two Availability Zones while London and Seoul currently provide one; CA-Central-1 and AP-Southeast-2 now support two AZs for enhanced production availability. To consume the service, request a private offer from Oracle via the AWS Marketplace and provision databases through the AWS Management Console.
read more →

Amazon RDS for Oracle Adds OMA 24.1.0.0.v1 Support

📣 Amazon RDS for Oracle now supports Oracle Management Agent version 24.1.0.0.v1 for Oracle Enterprise Manager Cloud Control 24aiR1. To enable it, add the OEM_AGENT option in Option Groups and set the AGENT_VERSION to "24.1.0.0.v1". You must also configure OMS hostname (or IP), port, agent registration password, and a minimum TLS version of TLSv1.2 so the agent can securely communicate with your Oracle Management Service. Refer to the Amazon RDS for Oracle documentation for full configuration guidance.
read more →

Oracle Database@AWS adds sub-millisecond network latency

Oracle Database@AWS (ODB@AWS) now provides consistent sub-millisecond roundtrip latency between Amazon EC2 instances and ODB@AWS databases. By automatically optimizing compute placement within ODB@AWS networks, customers can migrate latency-sensitive workloads — such as payment processing and securities trading — to AWS while using existing EC2 APIs and workflows. There is no additional charge for EC2 instances using the optimized placement; the capability is available in six Regions today, with more Regions planned.
read more →

Rapid Weaponization of Critical Oracle WebLogic RCE

⚠ A critical Oracle WebLogic RCE (CVE-2026-21962, CVSS 10.0) was weaponized the same day public exploit code was released, a CloudSEK honeypot study found. The high-interaction honeypot, run between January 22 and February 3, 2026, recorded immediate automated scanning and exploitation attempts. Researchers also observed probes for older WebLogic flaws and widespread generic web reconnaissance. Organizations are urged to apply patches, restrict console access, deploy WAFs and monitor logs.
read more →

Oracle patches critical RCE in Identity and Web Services

🔒 Oracle has released fixes for a critical pre-authentication remote code execution flaw, CVE-2026-21992, affecting Oracle Identity Manager and Oracle Web Services Manager. The issue carries a CVSS score of 9.8 and is described by NVD as "easily exploitable" over HTTP by unauthenticated attackers. Oracle says the flaw can enable full takeover of vulnerable instances and urges customers to apply updates immediately.
read more →

Oracle issues emergency patch for Identity Manager RCE

🛡️ Oracle has released an out-of-schedule security update to fix a critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-21992, that affects Oracle Identity Manager and Oracle Web Services Manager. Oracle says the flaw is low complexity, exploitable remotely over HTTP without authentication or user interaction. The company strongly recommends applying patches or mitigations immediately and notes fixes via the Security Alert program are limited to supported versions.
read more →

Unlocking Document Understanding with Mistral in Foundry

📄 Mistral Document AI 2512 in Microsoft Foundry combines high-end OCR (mistral-ocr-2512) with contextual extraction (mistral-small-2506) to convert scans, photos and digital documents into structured JSON and markup while preserving layout, tables and handwritten notes. It emphasizes enterprise-grade accuracy, multilingual coverage and private/secure inference. Paired with the ARGUS accelerator, organizations can deploy end-to-end pipelines quickly and switch OCR providers at runtime.
read more →

Spanner Columnar Engine Preview: Serving Iceberg Lakehouses

🚀 The preview of the Spanner columnar engine enables low-latency serving of Apache Iceberg lakehouse data with Spanner’s horizontal scale and strong consistency. It adds a columnar storage layer and vectorized execution to accelerate analytical scans — Google cites up to 200× faster scans — while isolating heavy analytical queries from transactional workloads. The feature supports on-demand columnar conversion, automatic query routing, and reverse ETL integrations with BigQuery, Databricks, Snowflake and Oracle to make curated analytical data available for real-time applications.
read more →

Amazon RDS for Oracle: January 2026 Release Update

🔔 Amazon RDS for Oracle now supports the Oracle January 2026 Release Update (RU) for Oracle Database versions 19c and 21c, and the corresponding Spatial Patch Bundle for 19c. The January 2026 RU includes important security updates, while the Spatial Patch Bundle delivers fixes to improve Oracle Spatial and Graph reliability and performance. You can apply these updates via the AWS Management Console, AWS SDK, or CLI, enable Automatic Minor Version Upgrade to apply during maintenance windows, and use AWS Organizations upgrade rollout policy to stagger upgrades across environments.
read more →

Oracle Database@AWS Expands to Canada Central and Sydney

📢 Oracle Database@AWS is now available in CA-Central-1 (Canada Central) and AP-Southeast-2 (Sydney), each starting with one Availability Zone. The service provides access to OCI-managed Exadata systems hosted inside AWS data centers, enabling like-for-like migrations of on-premises Oracle Exadata and RAC workloads. Integrations with AWS services such as AWS KMS for encryption and Amazon CloudWatch for monitoring are supported. Customers must request a private offer from Oracle via the AWS Marketplace and use the AWS Management Console to provision and manage databases.
read more →

Amazon RDS for Oracle Adds Multi-Tenant Replica Support

🔁 Amazon RDS for Oracle now supports database replicas for instances configured in Oracle multi-tenant (CDB/PDB) environments. You can create replicas in mounted or read-only modes via the AWS Management Console, CLI, or SDK, with Amazon RDS managing asynchronous physical replication using Oracle Data Guard. Replicas can scale read workloads, be promoted for disaster recovery, or be configured as cross-Region copies; licensing requirements differ by mode and should be reviewed before deployment.
read more →

TikTok Forms U.S. Joint Venture to Continue Operations

🔒 TikTok USDS Joint Venture LLC was formed to allow TikTok to continue operating in the U.S. under a majority-American ownership while ByteDance retains 19.9%. U.S. users' data and a retrained recommendation algorithm will be hosted in Oracle's secure U.S. cloud and protected under defined safeguards for algorithm security, content moderation, and software assurances. An independent, audited cybersecurity and privacy program will follow standards such as NIST CSF, NIST 800-53, ISO 27001, and CISA requirements.
read more →

Oracle issues 337 patches including critical Tika fix

🛡️ Oracle's January quarterly update delivers 337 security fixes across its product portfolio, including 27 rated critical. The vendor reports no known in-the-wild exploitation at release, but urges priority attention to the 13 CVEs mapped to critical severity. A substantial share of patches address third-party and open-source components such as Apache Tika, creating cross-product CVE overlap and assessment complexity.
read more →