CRITICAL
9.8 CVE-2026-70953 Published 18 Aug 2026
Oracle Commerce Platform Remote Takeover Vulnerability
Worried this affects one of your servers?
A vulnerability has been reported in Oracle Commerce Platform, specifically in the Dynamo Application Framework component.
The issue is an easily exploitable remote takeover vulnerability that allows an unauthenticated attacker with network access via TCP to compromise the platform.
- Affected version: 11.4.0
- Attack conditions: unauthenticated, network access via TCP
- Impact: full takeover of Oracle Commerce Platform
- CVSS 3.1 Base Score: 9.8 (Confidentiality, Integrity and Availability impacts)
Reference: CVE-2026-70953 on NVD
← Back to Security News