Technology · Oracle
Oracle Solaris vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in Oracle Solaris: 0 in the last 7 days and 6 in the last 90 days, 4 of them critical and 2 exploited in the wild. The most recent, CVE-2026-61202, was published on 21 July 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 4
- Exploited in the wild
- 2
About Oracle Solaris
Solaris is a Unix-based operating system originally developed by Sun Microsystems and now maintained by Oracle Corporation.
Latest Oracle Solaris vulnerabilities
- CVE-2026-61202: Oracle Solaris data compromise in Utility componenthighCVSS 7.5
- CVE-2026-61052: Oracle Solaris denial of service in FilesystemsmediumCVSS 5.5
- CVE-2026-60834: Oracle Solaris unauthorized data access in Utility componenthighCVSS 7.1
- CVE-2026-60833: Oracle Solaris privilege escalation in Utility componenthighCVSS 7
- CVE-2026-60661: Oracle Solaris privilege escalation in FilesystemshighCVSS 7.8
- CVE-2026-60659: Oracle Solaris integrity and availability breach in FilesystemshighCVSS 7.1
- CVE-2026-46978: Oracle Solaris improper access control in Remote Administration DaemoncriticalCVSS 10EPSS 0.4%
- CVE-2026-46914: Oracle Solaris privilege escalation and DoS in FilesystemhighCVSS 7.1EPSS 0.1%
- CVE-2019-3010: Oracle Solaris Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-14871: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2017-3301: Oracle Solaris integrity vulnerability in KernellowCVSS 3.3
- CVE-2017-3276: Oracle Solaris integrity and availability issues in Kernel Zones block drivermediumCVSS 5.7
- CVE-2016-8330: Oracle Solaris integrity vulnerability in KernellowCVSS 3.7
- CVE-2016-10086: CA Service Desk Manager incorrect permissions in RESTful web serviceshighCVSS 8.1
- CVE-1999-0524: Multiple Vendors ICMP Information Disclosure via Netmask and Timestamp RequestslowCVSS 2.1
- CVE-1999-0046: Multiple Vendors rlogin buffer overflow via TERM environment variablecriticalCVSS 10
Most severe Oracle Solaris vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-14871: Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2019-3010: Oracle Solaris Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-46978: Oracle Solaris improper access control in Remote Administration DaemoncriticalCVSS 10EPSS 0.4%
- CVE-1999-0046: Multiple Vendors rlogin buffer overflow via TERM environment variablecriticalCVSS 10
- CVE-2016-10086: CA Service Desk Manager incorrect permissions in RESTful web serviceshighCVSS 8.1
- CVE-2026-60661: Oracle Solaris privilege escalation in FilesystemshighCVSS 7.8
- CVE-2026-61202: Oracle Solaris data compromise in Utility componenthighCVSS 7.5
- CVE-2026-46914: Oracle Solaris privilege escalation and DoS in FilesystemhighCVSS 7.1EPSS 0.1%
- CVE-2026-60834: Oracle Solaris unauthorized data access in Utility componenthighCVSS 7.1
- CVE-2026-60659: Oracle Solaris integrity and availability breach in FilesystemshighCVSS 7.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 6 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/solaris.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle Solaris vulnerabilities", https://junglewise.ai/threats/technologies/solaris, 26 September 2026.