Oracle and Adobe ship emergency fixes for maximum-severity flaws
Oracle’s July update patches five critical bugs — one reportedly exploited in PeopleSoft — while Adobe ships ColdFusion fixes for six CVSS 10.0 vulnerabilities.
Two major enterprise software vendors issued urgent security fixes this month for flaws rated at or near the top of the severity scale.
Oracle’s July 2026 Critical Patch Update addresses five critical vulnerabilities (CVSS score 9.0 or higher) and more than a dozen high-severity issues across products including WebLogic Server, PeopleSoft, Identity Manager, WebCenter and VirtualBox. According to a Threat-Modeling.com analysis, one of them — CVE-2026-35278 in PeopleSoft — is being actively exploited in the wild by the ShinyHunters group, chained with a second bug, CVE-2026-35273, to achieve remote code execution.
Adobe, meanwhile, patched 11 critical vulnerabilities in ColdFusion, six of which carry the maximum CVSS score of 10.0 and allow unauthenticated attackers to run arbitrary code on affected servers. Adobe assigned its highest priority rating and urged customers to patch within 72 hours.
Both updates target software that commonly sits on internet-facing enterprise servers, where unpatched code-execution flaws are prime targets. Administrators should prioritize the actively exploited PeopleSoft chain and the ColdFusion fixes.
Sources: Threat-Modeling.com (Oracle CPU analysis); Oracle and Adobe security advisories.
Drafted with AI assistance and reviewed by the IT Magazine news desk. Facts verified against the linked sources. Spotted an error? See our Corrections Policy.



