Oracle Cloud Infrastructure · Vulnerability Disclosure
Oracle Cloud Vulnerability Disclosure
Vulnerability disclosure
Oracle Cloud Infrastructure runs a coordinated vulnerability disclosure program on Hackerone.
Cloud ComputingEnterprise CloudInfrastructure-as-a-ServiceOraclePlatform-as-a-ServiceComputeObject StorageIdentity and Access ManagementDatabaseKubernetesServerlessMonitoringEvent-Driven
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-29'
method: searched
source: >-
https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ and
https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ and
https://www.oracle.com/security-alerts/
provider: Oracle Cloud Infrastructure
providerId: oracle-cloud
program_published: true
policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/
reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/
advisories_url: https://www.oracle.com/security-alerts/
probed: '2026-08-29'
http_status: 200
reporting:
customers_and_partners: >-
Verbatim: "If you are an Oracle customer or partner, please use your designated support
mechanism (e.g., My Oracle Support or SuiteSupport) to submit a service request for any
security vulnerability you believe you have discovered in an Oracle product or Cloud or Cloud
Services."
everyone_else:
channel: email
address: secalert_us@oracle.com
statement: >-
Verbatim: "If you are not an Oracle customer or partner, please email secalert_us@oracle.com
with your discovery."
encryption:
pgp: true
note: >-
Oracle publishes a public PGP key and asks reporters to encrypt reports, proof-of-concept
details, logs and attachments before transmission.
bug_bounty:
offered: false
note: >-
Oracle runs no paid bug bounty and is not listed on HackerOne, Bugcrowd or Intigriti for OCI.
The stated researcher incentive is credit: "When Oracle issues a fix for a reported security
vulnerability, Oracle's policy is to credit the researcher in the applicable Critical Patch
Update, or Critical Security Patch Update, or Security Alert advisory." Oracle employees and
contractors are explicitly excluded from credit.
coordinated_disclosure:
required: true
conditions:
- Not publishing the vulnerability before Oracle releases a fix.
- Not disclosing exact details of the issue, such as exploits or proof-of-concept code.
- Coordinating disclosure with Oracle to allow sufficient time for remediation.
remediation_cadence:
program: Critical Patch Update (CPU) and Security Alert
schedule: Quarterly, on the third Tuesday of January, April, July and October.
next_dates: ['2026-10-20', '2027-01-19', '2027-04-20', '2027-07-20']
out_of_band: >-
Verbatim: "Oracle retains the ability to issue out of schedule patches or workaround
instructions in case of particularly critical vulnerabilities and/or when active exploits are
reported in the wild. This program is known as the Security Alert program."
cloud_applicability: >-
Verbatim: "The Oracle Cloud operations and security teams regularly evaluate Oracle's Critical
Patch Updates and Security Alerts as well as relevant third-party security updates as they
become available and apply the relevant patches in accordance with applicable change
management processes."
security_txt:
served: false
note: >-
Despite a fully published disclosure program, Oracle serves no /.well-known/security.txt on any
host probed (404 on the API hosts, docs.oracle.com and cloud.oracle.com; 403 for the whole
/.well-known/ prefix on www.oracle.com). This is the cheapest gap on the list — an RFC 9116
file pointing at the page and secalert_us@oracle.com would take minutes.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oracle-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.