Oracle Cloud Infrastructure · Vulnerability Disclosure

Oracle Cloud Vulnerability Disclosure

Vulnerability disclosure

Oracle Cloud Infrastructure runs a coordinated vulnerability disclosure program on Hackerone.

Cloud ComputingEnterprise CloudInfrastructure-as-a-ServiceOraclePlatform-as-a-ServiceComputeObject StorageIdentity and Access ManagementDatabaseKubernetesServerlessMonitoringEvent-Driven
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-29'
method: searched
source: >-
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ and
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ and
  https://www.oracle.com/security-alerts/
provider: Oracle Cloud Infrastructure
providerId: oracle-cloud
program_published: true
policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/
reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/
advisories_url: https://www.oracle.com/security-alerts/
probed: '2026-08-29'
http_status: 200
reporting:
  customers_and_partners: >-
    Verbatim: "If you are an Oracle customer or partner, please use your designated support
    mechanism (e.g., My Oracle Support or SuiteSupport) to submit a service request for any
    security vulnerability you believe you have discovered in an Oracle product or Cloud or Cloud
    Services."
  everyone_else:
    channel: email
    address: secalert_us@oracle.com
    statement: >-
      Verbatim: "If you are not an Oracle customer or partner, please email secalert_us@oracle.com
      with your discovery."
  encryption:
    pgp: true
    note: >-
      Oracle publishes a public PGP key and asks reporters to encrypt reports, proof-of-concept
      details, logs and attachments before transmission.
bug_bounty:
  offered: false
  note: >-
    Oracle runs no paid bug bounty and is not listed on HackerOne, Bugcrowd or Intigriti for OCI.
    The stated researcher incentive is credit: "When Oracle issues a fix for a reported security
    vulnerability, Oracle's policy is to credit the researcher in the applicable Critical Patch
    Update, or Critical Security Patch Update, or Security Alert advisory." Oracle employees and
    contractors are explicitly excluded from credit.
coordinated_disclosure:
  required: true
  conditions:
    - Not publishing the vulnerability before Oracle releases a fix.
    - Not disclosing exact details of the issue, such as exploits or proof-of-concept code.
    - Coordinating disclosure with Oracle to allow sufficient time for remediation.
remediation_cadence:
  program: Critical Patch Update (CPU) and Security Alert
  schedule: Quarterly, on the third Tuesday of January, April, July and October.
  next_dates: ['2026-10-20', '2027-01-19', '2027-04-20', '2027-07-20']
  out_of_band: >-
    Verbatim: "Oracle retains the ability to issue out of schedule patches or workaround
    instructions in case of particularly critical vulnerabilities and/or when active exploits are
    reported in the wild. This program is known as the Security Alert program."
  cloud_applicability: >-
    Verbatim: "The Oracle Cloud operations and security teams regularly evaluate Oracle's Critical
    Patch Updates and Security Alerts as well as relevant third-party security updates as they
    become available and apply the relevant patches in accordance with applicable change
    management processes."
security_txt:
  served: false
  note: >-
    Despite a fully published disclosure program, Oracle serves no /.well-known/security.txt on any
    host probed (404 on the API hosts, docs.oracle.com and cloud.oracle.com; 403 for the whole
    /.well-known/ prefix on www.oracle.com). This is the cheapest gap on the list — an RFC 9116
    file pointing at the page and secalert_us@oracle.com would take minutes.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oracle-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.