Technology · Oracle
Oracle WebCenter Sites vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Oracle WebCenter Sites: 0 in the last 7 days and 17 in the last 90 days, 16 of them critical and 0 exploited in the wild. The most recent, CVE-2026-83037, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 16
- Exploited in the wild
- 0
About Oracle WebCenter Sites
Oracle WebCenter Sites is a content management system used for building and managing high-traffic websites.
Latest Oracle WebCenter Sites vulnerabilities
- CVE-2026-83037: Oracle WebCenter Sites remote code executioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83036: Oracle WebCenter Sites unauthenticated remote code executioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83035: Oracle WebCenter Sites remote code executioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83034: Oracle WebCenter Sites unauthenticated data access vulnerabilityhighCVSS 7.5EPSS 0.4%
- CVE-2026-83033: Oracle WebCenter Sites privilege escalation in WebCenter SiteshighCVSS 8.8EPSS 0.4%
- CVE-2026-83032: Oracle WebCenter Sites privilege escalation via HTTPhighCVSS 8.8EPSS 0.4%
- CVE-2026-83031: Oracle WebCenter Sites privilege escalation via HTTPcriticalCVSS 9.9EPSS 0.4%
- CVE-2026-61140: Oracle WebCenter Sites remote compromise and takeovercriticalCVSS 9.8
- CVE-2026-60558: Oracle WebCenter Sites unauthenticated takeover via HTTPhighCVSS 8.1
- CVE-2026-60557: Oracle WebCenter Sites unauthorized data access via HTTPmediumCVSS 6.5
- CVE-2026-60556: Oracle WebCenter Sites unauthorized data access via HTTPhighCVSS 8.6
- CVE-2026-60555: Oracle WebCenter Sites remote compromise in WebCenter Sites componentcriticalCVSS 9.8
- CVE-2026-60554: Oracle WebCenter Sites unauthorized data access vulnerabilityhighCVSS 7.5
- CVE-2026-60553: Oracle WebCenter Sites unauthorized data access and modificationhighCVSS 8.7
- CVE-2026-60552: Oracle WebCenter Sites remote compromise and takeovercriticalCVSS 9.9
- CVE-2026-60551: Oracle WebCenter Sites remote compromise vulnerabilitycriticalCVSS 9.8
- CVE-2026-60550: Oracle WebCenter Sites unauthorized data access via HTTPhighCVSS 8.6
- CVE-2026-46809: Oracle WebCenter Sites improper access controlcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-46801: Oracle WebCenter Sites authentication bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46800: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 10EPSS 0.5%
- CVE-2026-46799: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46798: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 10EPSS 0.5%
- CVE-2026-46797: Oracle WebCenter Sites improper access controlcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46796: Oracle WebCenter Sites open redirect and system takeoverhighCVSS 8EPSS 0.4%
- CVE-2026-35318: Oracle WebCenter Sites improper access controlhighCVSS 8.8EPSS 0.5%
Most severe Oracle WebCenter Sites vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-46800: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 10EPSS 0.5%
- CVE-2026-46798: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 10EPSS 0.5%
- CVE-2026-83031: Oracle WebCenter Sites privilege escalation via HTTPcriticalCVSS 9.9EPSS 0.4%
- CVE-2026-60552: Oracle WebCenter Sites remote compromise and takeovercriticalCVSS 9.9
- CVE-2026-46801: Oracle WebCenter Sites authentication bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46799: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46797: Oracle WebCenter Sites improper access controlcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-35296: Oracle WebCenter Sites authentication bypass and system takeovercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-35293: Oracle WebCenter Sites missing authentication for critical functioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83037: Oracle WebCenter Sites remote code executioncriticalCVSS 9.8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 10 | 4 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 7 | 4 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/webcenter-sites.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle WebCenter Sites vulnerabilities", https://junglewise.ai/threats/technologies/webcenter-sites, 26 September 2026.