generated: '2026-08-29' method: searched source: >- https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ and https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ and https://www.oracle.com/security-alerts/ provider: Oracle Cloud Infrastructure providerId: oracle-cloud program_published: true policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ advisories_url: https://www.oracle.com/security-alerts/ probed: '2026-08-29' http_status: 200 reporting: customers_and_partners: >- Verbatim: "If you are an Oracle customer or partner, please use your designated support mechanism (e.g., My Oracle Support or SuiteSupport) to submit a service request for any security vulnerability you believe you have discovered in an Oracle product or Cloud or Cloud Services." everyone_else: channel: email address: secalert_us@oracle.com statement: >- Verbatim: "If you are not an Oracle customer or partner, please email secalert_us@oracle.com with your discovery." encryption: pgp: true note: >- Oracle publishes a public PGP key and asks reporters to encrypt reports, proof-of-concept details, logs and attachments before transmission. bug_bounty: offered: false note: >- Oracle runs no paid bug bounty and is not listed on HackerOne, Bugcrowd or Intigriti for OCI. The stated researcher incentive is credit: "When Oracle issues a fix for a reported security vulnerability, Oracle's policy is to credit the researcher in the applicable Critical Patch Update, or Critical Security Patch Update, or Security Alert advisory." Oracle employees and contractors are explicitly excluded from credit. coordinated_disclosure: required: true conditions: - Not publishing the vulnerability before Oracle releases a fix. - Not disclosing exact details of the issue, such as exploits or proof-of-concept code. - Coordinating disclosure with Oracle to allow sufficient time for remediation. remediation_cadence: program: Critical Patch Update (CPU) and Security Alert schedule: Quarterly, on the third Tuesday of January, April, July and October. next_dates: ['2026-10-20', '2027-01-19', '2027-04-20', '2027-07-20'] out_of_band: >- Verbatim: "Oracle retains the ability to issue out of schedule patches or workaround instructions in case of particularly critical vulnerabilities and/or when active exploits are reported in the wild. This program is known as the Security Alert program." cloud_applicability: >- Verbatim: "The Oracle Cloud operations and security teams regularly evaluate Oracle's Critical Patch Updates and Security Alerts as well as relevant third-party security updates as they become available and apply the relevant patches in accordance with applicable change management processes." security_txt: served: false note: >- Despite a fully published disclosure program, Oracle serves no /.well-known/security.txt on any host probed (404 on the API hosts, docs.oracle.com and cloud.oracle.com; 403 for the whole /.well-known/ prefix on www.oracle.com). This is the cheapest gap on the list — an RFC 9116 file pointing at the page and secalert_us@oracle.com would take minutes.