CVE-2026-70954 – Oracle Commerce Platform

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“Unauthenticated network attacks can lead to complete takeover of affected Oracle Commerce environments.”

Oracle addresses two Critical vulnerabilities in the Dynamo Application Framework component of Oracle Commerce Platform 11.4.0. CVE-2026-70953 is remotely exploitable without authentication over TCP, while CVE-2026-70954 is remotely exploitable without authentication over HTTP. Successful exploitation can result in takeover of Oracle Commerce Platform.

CVE-2026-70953 has a CVSS score of 9.8, Critical severity. CVE-2026-70954 has a CVSS score of 9.8, Critical severity. Both issues are addressed in Oracle’s August 2026 Critical Security Patch Update.

Key Details

Affected Product
Oracle Commerce Platform
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-306
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.