Oracle Security Updates - August 2026
Roundup of Oracle security advisories published in August 2026.
CVE search metadata
CVE search record: CVE-2026-60591. Severity: critical. CVSS: 9.1. KEV: no. Product: Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60672. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60696. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60698. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60702. Severity: critical. CVSS: 9.9. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60720. Severity: critical. CVSS: 9.9. KEV: no. Product: Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60721. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60727. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60728. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60730. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60737. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60754. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60782. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60821. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60858. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60861. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60905. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60916. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60921. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60946. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60947. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60958. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60970. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60971. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60977. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60990. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60995. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61001. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61003. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61008. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61018. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61021. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61029. Severity: critical. CVSS: 9.0. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61034. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61066. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61206. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61241. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61248. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61258. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61272. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61317. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-61318. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62452. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62457. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62463. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62512. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62539. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62541. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62543. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62544. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62585. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62588. Severity: critical. CVSS: 9.9. KEV: no. Product: Siebel CRM (25.12-26.6). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62592. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62608. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62609. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62611. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62617. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62618. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62621. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62622. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62624. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62629. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62630. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62632. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62633. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62634. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62635. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62637. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62638. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62639. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-62640. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70668. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70669. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70673. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70689. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70740. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70741. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70817. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70846. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70854. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70855. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70862. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70871. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70873. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70876. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70884. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70905. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70920. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70921. Severity: critical. CVSS: 10.0. KEV: no. Product: Hyperion Financial Management (11.2.25.0.000). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70926. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70954. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70958. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70977. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70978. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70979. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70981. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-70997. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-71014. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-71015. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-71065. Severity: critical. CVSS: 9.3. KEV: no. Product: Helidon (3.2.18). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-71152. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-71167. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-73865. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-73905. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-73912. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-73920. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-73921. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60392. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60413. Severity: high. CVSS: 7.8. KEV: no. Product: Outside In Technology (8.5.8). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60415. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60731. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60752. Severity: high. CVSS: 7.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
CVE search record: CVE-2026-60753. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/
What's new
This roundup covers 177 Oracle security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Agile PLM, Application Testing Suite, BI Publisher, Database Server, Demand Planning, E-Business Suite, Fusion Middleware, Helidon, Hospitality Simphony, Hyperion Calculation Manager, Hyperion Data Relationship Management, Hyperion Financial Management, Hyperion Financial Reporting, Hyperion Infrastructure Technology, Hyperion Profitability and Cost Management, Identity Manager, Internet Directory, JD Edwards EnterpriseOne Tools, Managed File Transfer, MySQL Cluster, Oracle Access Manager, Oracle Commerce Guided Search, Oracle Commerce Platform, Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Hyperion Data Relationship Management, Oracle Hyperion Financial Management, Oracle Hyperion Financial Reporting, Oracle Hyperion Infrastructure Technology, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle Reports Developer, Oracle Web Services Manager, Outside In Technology, PeopleSoft Enterprise PeopleTools, Siebel CRM, Siebel CRM Cloud Applications, WebCenter Content, WebCenter Enterprise Capture, WebCenter Portal, WebCenter Sites, WebLogic Server.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-60591 | Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-60672 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60696 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60698 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60702 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-60720 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-60721 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60727 | Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60728 | WebCenter Portal | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-60730 | n/a | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-60737 | Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-60754 | Siebel CRM (17.0-26.6) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-60782 | Oracle E-Business Suite (12.2.3-12.2.15) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60821 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60858 | Hyperion Calculation Manager (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60861 | n/a | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-60905 | WebCenter Content (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-60916 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-60921 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60946 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60947 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60958 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60970 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60971 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60977 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-60990 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-60995 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61001 | Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-61003 | Managed File Transfer (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61008 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-61018 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-61021 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61029 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.0 | no | NVD (authoritative) | |
| CVE-2026-61034 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-61066 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61206 | Hyperion Calculation Manager (11.2.25.0.000) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61241 | Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-61248 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61258 | Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-61272 | JD Edwards EnterpriseOne Tools (9.2.0.0-9.2.26.4) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-61317 | Siebel CRM Cloud Applications (22.3-26.6) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-61318 | Siebel CRM (22.3-26.6) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62452 | Siebel CRM Cloud Applications (22.3-26.6) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-62457 | Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62463 | Oracle Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-62512 | Siebel CRM Cloud Applications (22.3-26.6) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-62539 | Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62541 | Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62543 | Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62544 | Oracle Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62582 | Hyperion Calculation Manager (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-62585 | Siebel CRM (25.12-26.6) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62588 | Siebel CRM (25.12-26.6) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-62592 | Siebel CRM (25.12-26.6) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62608 | Oracle Fusion Middleware (12.2.1.19.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-62609 | Oracle Reports Developer (12.2.1.19.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62610 | Oracle Fusion Middleware (12.2.1.19.0) | no | NVD (authoritative) | |||
| CVE-2026-62611 | Oracle Reports Developer (12.2.1.19.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62613 | Oracle Reports Developer (12.2.1.19.0) | no | NVD (authoritative) | |||
| CVE-2026-62614 | n/a | no | NVD (authoritative) | |||
| CVE-2026-62617 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62618 | Oracle Reports Developer (12.2.1.19.0) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-62621 | Oracle Fusion Middleware (12.2.1.19.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62622 | Oracle Fusion Middleware (12.2.1.19.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62624 | Oracle Fusion Middleware | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62626 | Fusion Middleware (12.2.1.19.0) | no | NVD (authoritative) | |||
| CVE-2026-62629 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.4 | no | NVD (authoritative) | |
| CVE-2026-62630 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62632 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62633 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62634 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62635 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62637 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-62638 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-62639 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-62640 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70668 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70669 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70670 | n/a | no | NVD (authoritative) | |||
| CVE-2026-70673 | Oracle Reports Developer (14.1.2.0.0) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-70689 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70730 | Hyperion Profitability and Cost Management (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70739 | Hyperion Financial Reporting (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70740 | Hyperion Financial Reporting (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70741 | Hyperion Financial Reporting (11.2.25.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70745 | Hyperion Financial Reporting (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70817 | Hyperion Financial Management (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70846 | Demand Planning (12.1, 12.2) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-70854 | Oracle Hyperion Financial Management (11.2.25.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70855 | Siebel CRM (17.0-26.6) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-70862 | Application Testing Suite (13.3.0.1) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70871 | Oracle Hyperion Data Relationship Management (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70872 | Hyperion Data Relationship Management (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70873 | Hyperion Data Relationship Management (11.2.25.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70876 | Hyperion Data Relationship Management (11.2.25.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70880 | Hyperion Data Relationship Management (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70883 | Hyperion Data Relationship Management (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70884 | Hyperion Data Relationship Management (11.2.25.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70905 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70920 | Hyperion Financial Management (11.2.25.0.000) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-70921 | Hyperion Financial Management (11.2.25.0.000) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-70926 | Oracle E-Business Suite (12.2.3-12.2.15) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70953 | Oracle Commerce Platform (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70954 | Oracle Commerce Platform (11.4.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70958 | Hyperion Infrastructure Technology (11.2.25.0.000) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-70970 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-70976 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70977 | Oracle Commerce Guided Search (11.4.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70978 | Oracle Commerce Guided Search | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70979 | Oracle Commerce Guided Search (11.4.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70980 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70981 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70984 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70994 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70995 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-70997 | Oracle Commerce Guided Search (11.4.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70998 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-71014 | Oracle Commerce Guided Search (11.4.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-71015 | Oracle Commerce Guided Search (11.4.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-71026 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-71036 | Oracle Commerce Guided Search (11.4.0) | no | NVD (authoritative) | |||
| CVE-2026-71037 | Oracle Commerce Guided Search | no | NVD (authoritative) | |||
| CVE-2026-71040 | Agile PLM (9.3.6) | no | NVD (authoritative) | |||
| CVE-2026-71059 | BI Publisher (8.2.0.0.0, 26.1.0.0.0) | no | NVD (authoritative) | |||
| CVE-2026-71063 | Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3) | no | NVD (authoritative) | |||
| CVE-2026-71064 | Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3) | no | NVD (authoritative) | |||
| CVE-2026-71065 | Helidon (3.2.18) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-71074 | n/a | no | NVD (authoritative) | |||
| CVE-2026-71102 | Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3) | no | NVD (authoritative) | |||
| CVE-2026-71152 | Helidon (4.5.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-71164 | Helidon (3.2.18) | no | NVD (authoritative) | |||
| CVE-2026-71166 | Helidon (3.2.18) | no | NVD (authoritative) | |||
| CVE-2026-71167 | Helidon (4.5.0) | no | NVD (authoritative) | |||
| CVE-2026-73865 | Helidon (3.2.18) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-73866 | Helidon (4.5.0) | no | NVD (authoritative) | |||
| CVE-2026-73905 | Helidon (4.5.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73912 | Helidon (4.5.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73916 | Helidon (3.2.18) | no | NVD (authoritative) | |||
| CVE-2026-73917 | Helidon (4.5.0) | no | NVD (authoritative) | |||
| CVE-2026-73920 | Helidon (4.5.0) | Critical | 9.4 | no | NVD (authoritative) | |
| CVE-2026-73921 | Helidon (1.4.20) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73922 | Helidon (1.4.19) | no | NVD (authoritative) | |||
| CVE-2026-73924 | Helidon (1.4.19) | no | NVD (authoritative) | |||
| CVE-2026-73930 | Helidon (4.5.3) | no | NVD (authoritative) | |||
| CVE-2026-60391 | Oracle Hyperion Financial Reporting (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-60392 | Outside In Technology (8.5.8) | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-60393 | Hyperion Infrastructure Technology (11.2.25.0.000) | no | NVD (authoritative) | |||
| CVE-2026-60412 | Outside In Technology (8.5.8) | no | NVD (authoritative) | |||
| CVE-2026-60413 | Outside In Technology (8.5.8) | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-60414 | Oracle Fusion Middleware (8.5.8) | no | NVD (authoritative) | |||
| CVE-2026-60415 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-60590 | Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1) | no | NVD (authoritative) | |||
| CVE-2026-60592 | MySQL Cluster (8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1) | no | NVD (authoritative) | |||
| CVE-2026-60679 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | no | NVD (authoritative) | |||
| CVE-2026-60680 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | no | NVD (authoritative) | |||
| CVE-2026-60693 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-60699 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | no | NVD (authoritative) | |||
| CVE-2026-60707 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-60715 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-60716 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-60722 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-60726 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-60729 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-60731 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-60733 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-60742 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | no | NVD (authoritative) | |||
| CVE-2026-60748 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-60751 | Siebel CRM (17.0-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60752 | Siebel CRM (17.0-26.6) | High | 7.1 | no | NVD (authoritative) | |
| CVE-2026-60753 | Siebel CRM (17.0-26.6) | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-60757 | Siebel CRM (17.0-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60758 | Siebel CRM (25.12-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60759 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-60765 | Siebel CRM (17.0-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60766 | Siebel CRM (17.0-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60767 | Siebel CRM (17.0-26.6) | no | NVD (authoritative) | |||
| CVE-2026-60769 | n/a | no | NVD (authoritative) |
CVE-2026-60591
Oracle Hospitality Simphony contains a high-severity vulnerability that allows an unauthenticated attacker to perform unauthorized data modification or deletion and trigger a denial-of-service condition via network-based HTTP requests. The vulnerability affects multiple versions of the POS component.
Affected products:
- Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60591
Related in this roundup: CVE-2026-60590.
CVE-2026-60672
CVE-2026-60672 is a critical vulnerability in Oracle WebLogic Server (Core component) that allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full server takeover. The vulnerability is remotely exploitable without user interaction and carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60672
Related in this roundup: CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60696
Oracle WebLogic Server contains a critical vulnerability in its Core component that allows unauthenticated, network-adjacent attackers to achieve full system takeover via T3 or IIOP protocols. The flaw is easily exploitable, requiring no user interaction or authentication, and impacts confidentiality, integrity, and availability.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60696
Related in this roundup: CVE-2026-60672, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60698
CVE-2026-60698 is a critical vulnerability affecting the Core component of Oracle WebLogic Server. An unauthenticated attacker can exploit this via the IIOP protocol over the network to achieve full system takeover. The vulnerability carries a CVSS 3.1 score of 9.8 and impacts the confidentiality, integrity, and availability of the affected server.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60698
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60702
CVE-2026-60702 is a critical vulnerability in Oracle WebLogic Server (Core component) that allows a low-privileged attacker with network access via T3 or IIOP protocols to perform a full takeover of the server. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting other integrated products in the Fusion Middleware environment.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60702
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60720
CVE-2026-60720 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw allows a low-privileged attacker with network access via HTTP to achieve full compromise of the application. Due to a scope change, this vulnerability can also impact additional products, warranting a CVSS 3.1 base score of 9.9.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60720
Related in this roundup: CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.
CVE-2026-60721
CVE-2026-60721 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full takeover of the application. It is classified as easily exploitable and carries a CVSS 3.1 base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60721
Related in this roundup: CVE-2026-60720, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.
CVE-2026-60727
CVE-2026-60727 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to a full system takeover. It carries a CVSS base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60727
CVE-2026-60728
Oracle WebCenter Portal, specifically the Portlet Services component in versions 12.2.1.4.0 and 14.1.2.0.0, contains an unauthenticated vulnerability exploitable via HTTP network access. Successful exploitation allows an attacker to gain unauthorized access to sensitive data and cause a complete denial-of-service by crashing the application.
Affected products:
- WebCenter Portal
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60728
Related in this roundup: CVE-2026-70970, CVE-2026-60729, CVE-2026-60731, CVE-2026-60733.
CVE-2026-60730
CVE-2026-60730 is a critical vulnerability within the Composer component of Oracle WebCenter Portal. The flaw is remotely exploitable via HTTP by low-privileged attackers, potentially leading to a complete system takeover and impacting the confidentiality, integrity, and availability of the affected environment. The vulnerability is characterized by a scope change, indicating that successful exploitation can impact associated systems beyond the target product.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60730
CVE-2026-60737
CVE-2026-60737 is a critical vulnerability in the Oracle Web Services Manager component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, remote attacker with HTTP network access to perform unauthorized read, write, or deletion operations on critical data managed by the service. Given the high CVSS base score and lack of required authentication or user interaction, this flaw represents a significant risk for data integrity and confidentiality.
Affected products:
- Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60737
Related in this roundup: CVE-2026-61001.
CVE-2026-60754
CVE-2026-60754 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. The flaw is remotely exploitable by an unauthenticated attacker over HTTP, potentially leading to unauthorized access to sensitive data and complete denial-of-service via application crashes.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60754
Related in this roundup: CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60782
CVE-2026-60782 is a critical vulnerability in the Oracle Payments component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is remotely exploitable without authentication via HTTP and allows an attacker to achieve full takeover of the Oracle Payments service, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60782
Related in this roundup: CVE-2026-70926, CVE-2026-60693, CVE-2026-60748.
CVE-2026-60821
CVE-2026-60821 is a critical vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, allowing for a complete takeover of the PeopleTools environment. With a CVSS base score of 9.8, it poses a high risk to confidentiality, integrity, and availability.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60821
Related in this roundup: CVE-2026-60742.
CVE-2026-60858
CVE-2026-60858 is a critical vulnerability in Oracle Hyperion Calculation Manager, version 11.2.25.0.000. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve full system takeover via unauthenticated HTTP requests, resulting in total loss of confidentiality, integrity, and availability.
Affected products:
- Hyperion Calculation Manager (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60858
Related in this roundup: CVE-2026-61206, CVE-2026-62582.
CVE-2026-60861
CVE-2026-60861 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. An attacker with low privileges and network access via Oracle Net can exploit this vulnerability to achieve unauthorized access to, creation of, deletion of, or modification of critical data. Due to a change in scope, a successful exploit can impact additional products beyond the Service Delivery Platform itself.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60861
CVE-2026-60905
CVE-2026-60905 is a high-severity vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to compromise the system via HTTP, provided they can induce human interaction. Successful exploitation permits unauthorized access, modification, or deletion of critical data, as well as the ability to cause a partial denial of service. The vulnerability involves a scope change, meaning impacts may extend to other products within the environment.
Affected products:
- WebCenter Content (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60905
CVE-2026-60916
CVE-2026-60916 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is remotely exploitable without authentication via HTTP, allowing an attacker to impact confidentiality, integrity, and availability. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, as well as a partial denial-of-service, with potential for scope change affecting additional products.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60916
Related in this roundup: CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.
CVE-2026-60921
CVE-2026-60921 is a critical vulnerability in Oracle WebCenter Enterprise Capture (Client Bundle component) allowing unauthenticated attackers to achieve full system takeover via T3 or IIOP network protocols. The vulnerability carries a CVSS 3.1 base score of 9.8 and impacts confidentiality, integrity, and availability.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60921
Related in this roundup: CVE-2026-60916, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.
CVE-2026-60946
CVE-2026-60946 is a critical vulnerability in Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) involving the Client Bundle component. The vulnerability allows an unauthenticated attacker to execute code remotely via RMI with network access, leading to a full takeover of the application. It is highly exploitable and impacts the confidentiality, integrity, and availability of the system.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60946
Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.
CVE-2026-60947
CVE-2026-60947 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve full system takeover via RMI requests. Detection engineers should monitor for unauthorized or unusual RMI traffic patterns directed at the WebCenter Enterprise Capture application, as successful exploitation results in complete compromise of confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60947
CVE-2026-60958
CVE-2026-60958 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is remotely exploitable without authentication via HTTP and can lead to a full system takeover, indicating a high risk of remote code execution or significant privilege manipulation.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60958
Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60970, CVE-2026-60971.
CVE-2026-60970
CVE-2026-60970 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8 and impacts the confidentiality, integrity, and availability of the affected system.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60970
Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60971.
CVE-2026-60971
CVE-2026-60971 is a critical vulnerability (CVSS 9.8) affecting Oracle WebCenter Enterprise Capture within Oracle Fusion Middleware. An unauthenticated attacker with network access via T3 or IIOP protocols can exploit this flaw to fully compromise the target application. Successful exploitation leads to a complete takeover of the service, impacting confidentiality, integrity, and availability.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60971
Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970.
CVE-2026-60977
CVE-2026-60977 is a critical remote code execution vulnerability in the WLS Core Components of Oracle WebLogic Server. The vulnerability allows unauthenticated attackers with network access to the server to gain full control via RMI, resulting in a complete takeover of the affected component. It is rated with a CVSS 3.1 base score of 9.8.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60977
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60990
CVE-2026-60990 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with network access over TLS can exploit this vulnerability to achieve full compromise (takeover) of the component. The vulnerability carries a CVSS base score of 9.9 and allows for scope change, indicating the potential to impact additional products within the environment.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60990
Related in this roundup: CVE-2026-60995.
CVE-2026-60995
CVE-2026-60995 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with network access via TLS can exploit this flaw to achieve full system takeover. The vulnerability allows for scope change, potentially impacting additional products in the environment, and carries a CVSS base score of 9.9.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60995
Related in this roundup: CVE-2026-60990.
CVE-2026-61001
CVE-2026-61001 is a critical vulnerability in Oracle Web Services Manager within Oracle Fusion Middleware, allowing a low-privileged attacker with network access via HTTP to compromise the service. Due to a scope change (S:C), the vulnerability can result in unauthorized creation, deletion, or modification of critical data. It carries a CVSS 3.1 base score of 9.6, indicating significant impact to confidentiality and integrity.
Affected products:
- Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61001
Related in this roundup: CVE-2026-60737.
CVE-2026-61003
A critical vulnerability exists in the Oracle Managed File Transfer component of Oracle Fusion Middleware, allowing a low-privileged, network-adjacent attacker to achieve full takeover of the MFT Runtime Server via T3 or IIOP protocols. The flaw supports scope change, meaning exploitation can potentially lead to the compromise of additional products within the environment, warranting immediate patching.
Affected products:
- Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61003
CVE-2026-61008
CVE-2026-61008 is a critical vulnerability in Oracle WebCenter Sites (part of Fusion Middleware) that allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, deletion, or modification of critical data. With a CVSS 3.1 score of 9.1, this flaw is highly exploitable via HTTP and impacts the confidentiality and integrity of the application data.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61008
Related in this roundup: CVE-2026-61018, CVE-2026-61021, CVE-2026-61029, CVE-2026-61034.
CVE-2026-61018
CVE-2026-61018 is a critical vulnerability affecting Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 within the Oracle Fusion Middleware suite. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to a full system takeover. It carries a CVSS 3.1 base score of 9.8, indicating severe confidentiality, integrity, and availability impacts.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61018
Related in this roundup: CVE-2026-61008, CVE-2026-61021, CVE-2026-61029, CVE-2026-61034.
CVE-2026-61021
A critical vulnerability exists in Oracle WebCenter Sites within the Oracle Fusion Middleware suite, allowing low-privileged, network-adjacent attackers to achieve complete system takeover via HTTP. The vulnerability has a CVSS 3.1 base score of 9.9 and impacts confidentiality, integrity, and availability, with an associated scope change that may affect secondary products.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61021
Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61029, CVE-2026-61034.
CVE-2026-61029
Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to an unauthenticated, remote code execution or takeover attack. The vulnerability is accessible over the network via HTTP and allows for significant impact across the environment due to a change in scope, carrying a CVSS 3.1 base score of 9.0.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61029
Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61021, CVE-2026-61034.
CVE-2026-61034
CVE-2026-61034 is a critical vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware. The flaw is remotely exploitable over HTTP by a high-privileged attacker, potentially leading to a full system takeover and impacting additional products through scope change. The vulnerability carries a CVSS 3.1 base score of 9.1.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61034
Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61021, CVE-2026-61029.
CVE-2026-61066
CVE-2026-61066 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. An attacker with low privileges can exploit this vulnerability via RMI over the network to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 score of 9.9 and involves a scope change, meaning it can facilitate broader compromise beyond the Oracle Identity Manager environment.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61066
Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.
CVE-2026-61206
CVE-2026-61206 is a critical vulnerability in the Security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000. It allows a low-privileged, network-based attacker to execute a successful takeover of the application via HTTP. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting additional products within the environment.
Affected products:
- Hyperion Calculation Manager (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61206
Related in this roundup: CVE-2026-60858, CVE-2026-62582.
CVE-2026-61241
CVE-2026-61241 is a critical vulnerability in the OID LDAP Server component of Oracle Internet Directory. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve a complete takeover of the directory service. The vulnerability carries a CVSS base score of 10.0 and impacts the confidentiality, integrity, and availability of the system with an increased scope.
Affected products:
- Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61241
Related in this roundup: CVE-2026-61258.
CVE-2026-61248
CVE-2026-61248 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. A low-privileged attacker with network access via the LDAP protocol can achieve a full takeover of the Oracle Internet Directory. Due to the scope change (S:C), successful exploitation impacts the confidentiality, integrity, and availability of the directory service and potentially associated systems.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61248
CVE-2026-61258
CVE-2026-61258 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw via the LDAP protocol over the network to achieve a full takeover of the affected service. The vulnerability has a CVSS base score of 9.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61258
Related in this roundup: CVE-2026-61241.
CVE-2026-61272
CVE-2026-61272 is a critical vulnerability in the Web Runtime SEC component of Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.4. The vulnerability allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. Given the CVSS score of 9.8 and the lack of required authentication, this flaw represents a significant risk for RCE or full application compromise.
Affected products:
- JD Edwards EnterpriseOne Tools (9.2.0.0-9.2.26.4)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61272
CVE-2026-61317
CVE-2026-61317 is a critical vulnerability in the Oracle Siebel Cloud Manager component of Siebel CRM Cloud Applications (versions 22.3-26.6). A low-privileged attacker with network access can exploit this via HTTP to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.9 and involves a scope change, allowing impacts to propagate to other products.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61317
Related in this roundup: CVE-2026-62452, CVE-2026-62512.
CVE-2026-61318
CVE-2026-61318 is a critical vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via HTTP requests. With a CVSS 3.1 base score of 9.8, this vulnerability poses a severe risk to confidentiality, integrity, and availability.
Affected products:
- Siebel CRM (22.3-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61318
Related in this roundup: CVE-2026-60754, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-62452
CVE-2026-62452 is a critical, easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.6). An unauthenticated attacker with network access can leverage HTTP to achieve unauthorized access to critical data, perform unauthorized modifications (update, insert, or delete) on accessible data, and trigger a partial denial of service. The vulnerability impacts the confidentiality, integrity, and availability of the application with a CVSS 3.1 base score of 9.9.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62452
Related in this roundup: CVE-2026-61317, CVE-2026-62512.
CVE-2026-62457
CVE-2026-62457 is a critical vulnerability in the Common Events component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The flaw is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover by compromising confidentiality, integrity, and availability. With a CVSS base score of 9.8, it represents a high-risk entry point for unauthorized remote access.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62457
Related in this roundup: CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.
CVE-2026-62463
Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is vulnerable to an easily exploitable flaw in the Lifecycle Management component. A low-privileged attacker with network access via HTTP can trigger a scope change to perform unauthorized data modification, deletion, or access to critical system data. The vulnerability carries a high CVSS base score of 9.6, indicating significant impact on data confidentiality and integrity.
Affected products:
- Oracle Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62463
Related in this roundup: CVE-2026-62544.
CVE-2026-62512
CVE-2026-62512 is a critical vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. The vulnerability allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP requests. Due to the high CVSS score of 9.9 and the potential for a scope change affecting downstream products, this vulnerability represents a significant risk to confidentiality, integrity, and availability.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62512
Related in this roundup: CVE-2026-61317, CVE-2026-62452.
CVE-2026-62539
CVE-2026-62539 is a critical vulnerability affecting the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. An unauthenticated attacker can exploit this flaw over the network via HTTP to achieve full compromise of the application, resulting in impacts to confidentiality, integrity, and availability with a CVSS base score of 9.8.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62539
Related in this roundup: CVE-2026-62457, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.
CVE-2026-62541
A critical vulnerability exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The flaw is remotely exploitable over HTTP by an unauthenticated attacker without user interaction, potentially leading to a full system takeover. Given the high CVSS score of 9.8, this represents a severe risk to the confidentiality, integrity, and availability of the affected infrastructure.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62541
Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.
CVE-2026-62543
CVE-2026-62543 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology component 'Installation and Configuration' (version 11.2.25.0.000). The flaw allows an unauthenticated attacker to achieve full system takeover via network-accessible HTTP requests, resulting in high impact to confidentiality, integrity, and availability.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62543
Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-70958, CVE-2026-60393.
CVE-2026-62544
CVE-2026-62544 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. The flaw is remotely exploitable over HTTP by an unauthenticated attacker, potentially leading to a full system takeover. Given the CVSS 9.8 score and lack of required authentication, detection efforts should focus on anomalous HTTP requests targeting the installation or configuration endpoints of the Hyperion suite.
Affected products:
- Oracle Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62544
Related in this roundup: CVE-2026-62463.
CVE-2026-62582
Oracle Hyperion Calculation Manager version 11.2.25.0.000 contains a vulnerability in its Security component that allows a low-privileged, network-adjacent attacker to perform unauthorized actions, including the creation, deletion, or modification of critical data. Due to a scope change, successful exploitation can result in complete access to sensitive data managed by the application, with a high CVSS base score of 9.6.
Affected products:
- Hyperion Calculation Manager (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62582
Related in this roundup: CVE-2026-60858, CVE-2026-61206.
CVE-2026-62585
CVE-2026-62585 is a critical vulnerability in the Data Archival component of Oracle Siebel CRM Administration versions 25.12 through 26.6. The flaw is remotely exploitable without authentication via HTTP, potentially allowing a full system takeover. Security teams should prioritize patching affected instances due to the high CVSS score of 9.8.
Affected products:
- Siebel CRM (25.12-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62585
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-62588
CVE-2026-62588 is a critical vulnerability within the Open Integration component of Oracle Siebel CRM, allowing a low-privileged attacker with network access via HTTP to achieve a full takeover of the Siebel CRM Integration product. The vulnerability carries a CVSS base score of 9.9 and involves a scope change, potentially impacting additional integrated products.
Affected products:
- Siebel CRM (25.12-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62588
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-62592
CVE-2026-62592 is a critical vulnerability in the Open Integration component of Oracle Siebel CRM, affecting versions 25.12 through 26.6. The flaw allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the Siebel CRM Integration product via crafted HTTP requests, resulting in full impact to confidentiality, integrity, and availability.
Affected products:
- Siebel CRM (25.12-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62592
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-62608
CVE-2026-62608 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this flaw via CORBA to achieve a full takeover of the application. The vulnerability allows for scope change, potentially impacting additional products, with a CVSS 3.1 base score of 9.9.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62608
Related in this roundup: CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.
CVE-2026-62609
CVE-2026-62609 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The vulnerability is remotely exploitable without authentication via TCP, allowing an attacker to achieve full takeover of the affected product with significant impacts on confidentiality, integrity, and availability.
Affected products:
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62609
Related in this roundup: CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62610
CVE-2026-62610 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The flaw is remotely exploitable by an unauthenticated attacker over HTTP, allowing for unauthorized access to, or modification/deletion of, critical data. The vulnerability possesses a CVSS 3.1 base score of 9.1.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62610
Related in this roundup: CVE-2026-62608, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.
CVE-2026-62611
CVE-2026-62611 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware. The vulnerability allows an unauthenticated, remote attacker to gain full control of the application via the IIOP protocol. Due to the lack of required authentication and low complexity of the exploit, this vulnerability poses a severe risk of complete system compromise.
Affected products:
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62611
Related in this roundup: CVE-2026-62609, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62613
CVE-2026-62613 is a vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The vulnerability is network-adjacent (accessible via the physical communication segment), allowing an unauthenticated attacker to compromise the product and access or modify critical data. The vulnerability involves a scope change and carries a CVSS 3.1 base score of 9.3.
Affected products:
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62613
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62614
Oracle Reports Developer in Oracle Fusion Middleware version 12.2.1.19.0 contains a critical, easily exploitable vulnerability in the Security and Authentication component. An unauthenticated attacker can leverage network access via HTTP to achieve full compromise (takeover) of the application. The vulnerability carries a CVSS base score of 9.8.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62614
CVE-2026-62617
CVE-2026-62617 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware version 12.2.1.19.0. An unauthenticated attacker can exploit this flaw via network access over UDP to gain full control of the affected product, leading to total compromise of confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62617
CVE-2026-62618
CVE-2026-62618 is a critical vulnerability in Oracle Reports Developer (part of Oracle Fusion Middleware) that allows unauthenticated, network-based attackers to compromise the system via HTTP. The vulnerability has a high CVSS score of 9.3 and exhibits a scope change, meaning successful exploitation can lead to unauthorized access, modification, or deletion of critical data across the target application and potentially impacted secondary products.
Affected products:
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62618
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62621
CVE-2026-62621 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware version 12.2.1.19.0. An unauthenticated attacker can exploit this flaw via network access over TCP to achieve a complete takeover of the affected product. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating severe impacts to confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0)
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62621
Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.
CVE-2026-62622
CVE-2026-62622 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware version 12.2.1.19.0. The vulnerability is easily exploitable by an unauthenticated attacker over a network via the IIOP protocol. Successful exploitation allows for a full takeover of the Oracle Reports Developer instance, resulting in complete compromise of confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0)
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62622
Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62624, CVE-2026-60414.
CVE-2026-62624
CVE-2026-62624 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (within Oracle Fusion Middleware) that allows an unauthenticated, network-adjacent attacker to achieve full system takeover via IIOP. The vulnerability is easily exploitable and carries a CVSS base score of 9.8, necessitating immediate patching of the affected 12.2.1.19.0 version.
Affected products:
- Oracle Fusion Middleware
- Oracle Reports Developer (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62624
Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-60414.
CVE-2026-62626
CVE-2026-62626 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The flaw allows unauthenticated remote attackers to achieve full system takeover via HTTP requests, resulting in high impact across confidentiality, integrity, and availability.
Affected products:
- Fusion Middleware (12.2.1.19.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62626
CVE-2026-62629
CVE-2026-62629 is a critical vulnerability in Oracle Reports Developer (Oracle Fusion Middleware) that allows an unauthenticated attacker to exploit the application via HTTP. The vulnerability enables unauthorized read/write access to data and can trigger a denial-of-service (DoS) condition, impacting system availability and data integrity.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62629
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62630
CVE-2026-62630 describes a critical, easily exploitable vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 14.1.2.0.0. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via TCP, resulting in high impact to confidentiality, integrity, and availability.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62630
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62632
CVE-2026-62632 is a critical vulnerability within the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over HTTP to gain full control of the application, resulting in a complete compromise of confidentiality, integrity, and availability. Given the CVSS score of 9.8 and the lack of required authentication, this vulnerability represents a severe RCE risk to exposed instances.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62632
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62633
A critical vulnerability exists in the Oracle Reports Developer component of Oracle Fusion Middleware version 14.1.2.0.0. The vulnerability allows an unauthenticated attacker with network access to execute an exploit via HTTP, potentially leading to a full takeover of the application. The flaw carries a CVSS 3.1 base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62633
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62634
CVE-2026-62634 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 14.1.2.0.0. The vulnerability allows an unauthenticated attacker with network access to the CORBA interface to achieve full system takeover, with a CVSS base score of 9.8 representing complete impact on confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62634
CVE-2026-62635
CVE-2026-62635 is a critical vulnerability in Oracle Reports Developer within Oracle Fusion Middleware, specifically affecting the Security and Authentication component. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for full system takeover. With a CVSS base score of 9.8, it represents a high-risk remote code execution scenario requiring immediate patching.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62635
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62637
CVE-2026-62637 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with local network access (physical communication segment) to perform unauthorized data access, modification, or deletion. The vulnerability affects version 14.1.2.0.0 and allows for scope change, potentially impacting other products in the environment.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62637
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62638
CVE-2026-62638 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with network access via HTTP to perform unauthorized modifications to critical data and cause a denial-of-service condition, impacting system integrity and availability.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62638
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62639
CVE-2026-62639 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to exploit CORBA interfaces, leading to a complete takeover of the application. The vulnerability carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62639
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-62640
CVE-2026-62640 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware, specifically within the Security and Authentication module. The flaw allows an unauthenticated remote attacker with network access to the IIOP interface to achieve full system compromise, including the takeover of the application. The vulnerability carries a CVSS 3.1 base score of 9.8.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62640
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.
CVE-2026-70668
Oracle Reports Developer in Oracle Fusion Middleware contains a vulnerability in the Security and Authentication component that allows unauthenticated attackers to gain unauthorized access to critical data. The vulnerability is exploitable over the network via SOAP requests, resulting in potential unauthorized creation, deletion, or modification of accessible data with a CVSS base score of 9.1.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70668
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70669, CVE-2026-70673.
CVE-2026-70669
CVE-2026-70669 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated remote attacker with network access to achieve a complete takeover of the application via HTTP. With a CVSS base score of 9.8, it represents a high-impact risk to confidentiality, integrity, and availability.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70669
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70673.
CVE-2026-70670
CVE-2026-70670 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (version 14.1.2.0.0). The vulnerability is easily exploitable by an unauthenticated attacker with local network access to the physical communication segment where the software resides. Successful exploitation allows for a full system takeover and impacts the confidentiality, integrity, and availability of the affected product, with potential for scope change affecting other systems.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70670
CVE-2026-70673
CVE-2026-70673 is a high-severity, easily exploitable vulnerability in Oracle Reports Developer within Oracle Fusion Middleware. It allows unauthenticated attackers with network access via HTTP to compromise the application, potentially leading to unauthorized access, modification, or deletion of critical data. Due to the scope change, successful exploitation may have broader impacts beyond the component itself.
Affected products:
- Oracle Reports Developer (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70673
Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669.
CVE-2026-70689
CVE-2026-70689 is a critical remote code execution vulnerability in the Infrastructure component of Oracle Essbase, specifically version 21.8.1.0.0. The vulnerability allows an unauthenticated remote attacker to gain full control of the application via a network-based HTTP request, leading to a complete system takeover.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70689
CVE-2026-70730
CVE-2026-70730 is a critical vulnerability in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized data modification, creation, or deletion via HTTP requests, leading to full unauthorized access to critical data. The vulnerability is easily exploitable and carries a CVSS 3.1 base score of 9.1.
Affected products:
- Hyperion Profitability and Cost Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70730
CVE-2026-70739
CVE-2026-70739 is a critical vulnerability in the Oracle Hyperion Financial Reporting server component, specifically version 11.2.25.0.000. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the application, leading to a complete takeover of confidentiality, integrity, and availability. The vulnerability is rated with a CVSS 3.1 base score of 9.8.
Affected products:
- Hyperion Financial Reporting (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70739
Related in this roundup: CVE-2026-70740, CVE-2026-70741, CVE-2026-70745.
CVE-2026-70740
Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains a critical vulnerability allowing unauthenticated remote attackers to compromise the application via HTTP network access. Successful exploitation leads to a full takeover of the Financial Reporting server, impacting confidentiality, integrity, and availability with a CVSS base score of 9.8.
Affected products:
- Hyperion Financial Reporting (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70740
Related in this roundup: CVE-2026-70739, CVE-2026-70741, CVE-2026-70745.
CVE-2026-70741
CVE-2026-70741 is a critical vulnerability in Oracle Hyperion Financial Reporting (version 11.2.25.0.000) allowing an unauthenticated remote attacker with network access to leverage RMI to gain unauthorized access to or modify critical data. The vulnerability has a CVSS 3.1 score of 9.1, reflecting high confidentiality and integrity risks.
Affected products:
- Hyperion Financial Reporting (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70741
Related in this roundup: CVE-2026-70739, CVE-2026-70740, CVE-2026-70745.
CVE-2026-70745
CVE-2026-70745 is a critical vulnerability in the Oracle Hyperion Financial Reporting server component (version 11.2.25.0.000). The flaw is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover. With a CVSS score of 9.8, this vulnerability poses significant risks to the confidentiality, integrity, and availability of the affected system.
Affected products:
- Hyperion Financial Reporting (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70745
Related in this roundup: CVE-2026-70739, CVE-2026-70740, CVE-2026-70741.
CVE-2026-70817
CVE-2026-70817 is a critical vulnerability in the security component of Oracle Hyperion Financial Management (version 11.2.25.0.000) that allows an unauthenticated attacker to gain full control of the application via network-accessible HTTP requests. Due to the high CVSS base score of 9.8, the vulnerability likely involves an RCE or similar takeover primitive reachable without credentials.
Affected products:
- Hyperion Financial Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70817
Related in this roundup: CVE-2026-70920, CVE-2026-70921.
CVE-2026-70846
CVE-2026-70846 is a critical vulnerability in the Internal Operations component of Oracle Demand Planning versions 12.1 and 12.2. The flaw is remotely exploitable via HTTP by low-privileged attackers without user interaction. Successful exploitation allows for unauthorized modification, deletion, or access to critical application data, and carries a scope-change impact that may affect other integrated products.
Affected products:
- Demand Planning (12.1, 12.2)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70846
CVE-2026-70854
CVE-2026-70854 is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It allows an unauthenticated, network-adjacent attacker to perform unauthorized data modification or deletion, and to induce a persistent denial of service (DoS) crash via HTTP requests.
Affected products:
- Oracle Hyperion Financial Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70854
CVE-2026-70855
CVE-2026-70855 is a critical vulnerability in the Helpdesk/Training component of Oracle Siebel CRM's Self Service product. An unauthenticated attacker with network access can leverage this flaw via HTTP to achieve unauthorized access to, or modification of, critical data. The exploit requires human interaction from a legitimate user and results in a scope change, allowing the attacker to impact additional products within the Siebel ecosystem.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70855
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-70862
CVE-2026-70862 is an unauthenticated, network-exploitable vulnerability in Oracle Application Testing Suite version 13.3.0.1. An attacker can leverage HTTP requests to achieve unauthorized creation, deletion, or modification of critical data within the application, leading to significant impacts on data confidentiality and integrity.
Affected products:
- Application Testing Suite (13.3.0.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70862
CVE-2026-70871
CVE-2026-70871 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An unauthenticated attacker with network access via TCP can exploit this flaw to achieve full system takeover. The vulnerability has a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70871
CVE-2026-70872
CVE-2026-70872 is a critical vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to, or modify/delete, critical data within the application. The vulnerability carries a CVSS 3.1 base score of 9.1.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70872
Related in this roundup: CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.
CVE-2026-70873
Oracle Hyperion Data Relationship Management version 11.2.25.0.000 contains a critical vulnerability in the Access and security component. An unauthenticated, network-adjacent attacker can exploit this flaw to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8, indicating severe impacts on confidentiality, integrity, and availability.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70873
Related in this roundup: CVE-2026-70872, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.
CVE-2026-70876
CVE-2026-70876 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An attacker with high-level privileges and network access can exploit this vulnerability via HTTPS to achieve a full takeover of the application. The vulnerability carries a high CVSS score of 9.1 and includes a scope change, meaning exploitation can negatively impact other connected systems.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70876
Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.
CVE-2026-70880
CVE-2026-70880 is a critical, easily exploitable vulnerability in the Oracle Hyperion Data Relationship Management product's Access and Security component. An unauthenticated attacker with network access via TCP can achieve full system takeover. The vulnerability carries a CVSS base score of 10.0 and impacts the confidentiality, integrity, and availability of the system, with the potential for scope change affecting additional products.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70880
Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70883, CVE-2026-70884.
CVE-2026-70883
CVE-2026-70883 is an easily exploitable, unauthenticated vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An attacker with network access via HTTP can compromise the application, resulting in unauthorized access to, modification of, or deletion of critical data. The vulnerability carries a CVSS 3.1 base score of 9.1.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70883
Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70884.
CVE-2026-70884
CVE-2026-70884 is a critical vulnerability in Oracle Hyperion Data Relationship Management (version 11.2.25.0.000) affecting the Access and security component. The vulnerability is network-exploitable via SOAP by an unauthenticated attacker, allowing for unauthorized read, modification, or deletion of critical data, resulting in significant confidentiality and integrity impact.
Affected products:
- Hyperion Data Relationship Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70884
Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883.
CVE-2026-70905
CVE-2026-70905 is a critical vulnerability in the Agent infrastructure component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this via SAML over the network to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70905
Related in this roundup: CVE-2026-60726.
CVE-2026-70920
Oracle Hyperion Financial Management version 11.2.25.0.000 is vulnerable to a critical SQL injection-based flaw in its Security component. A low-privileged attacker with network access can exploit this vulnerability to achieve a full takeover of the application. The vulnerability carries a high CVSS 3.1 score of 9.9, and because of a scope change, successful exploitation may have cascading impacts on other integrated products.
Affected products:
- Hyperion Financial Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70920
Related in this roundup: CVE-2026-70817, CVE-2026-70921.
CVE-2026-70921
CVE-2026-70921 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management (v11.2.25.0.000). The flaw allows unauthenticated remote attackers to compromise the application over TLS, leading to unauthorized access, modification, or deletion of critical data. Due to its scope-changing nature, the vulnerability poses a high risk to the confidentiality and integrity of all data accessible within the environment.
Affected products:
- Hyperion Financial Management (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70921
Related in this roundup: CVE-2026-70817, CVE-2026-70920.
CVE-2026-70926
CVE-2026-70926 is a critical vulnerability (CVSS 9.8) in the Oracle Workflow component of Oracle E-Business Suite. The flaw allows an unauthenticated attacker with network access via SMTP to achieve full compromise (takeover) of the Oracle Workflow product. Detection engineers should monitor SMTP traffic patterns to affected Oracle E-Business Suite instances for malformed or unexpected payloads.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70926
Related in this roundup: CVE-2026-60782, CVE-2026-60693, CVE-2026-60748.
CVE-2026-70953
CVE-2026-70953 is a critical vulnerability in the Oracle Commerce Platform's Dynamo Application Framework component (version 11.4.0). The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via TCP, resulting in high impact to confidentiality, integrity, and availability.
Affected products:
- Oracle Commerce Platform (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70953
Related in this roundup: CVE-2026-70954.
CVE-2026-70954
CVE-2026-70954 is a critical vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0. The vulnerability is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover. Detection engineers should monitor for anomalous HTTP traffic targeting the Dynamo Application Framework or unexpected administrative activity originating from unauthenticated sessions.
Affected products:
- Oracle Commerce Platform (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70954
Related in this roundup: CVE-2026-70953.
CVE-2026-70958
CVE-2026-70958 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology component 'Installation and Configuration' (version 11.2.25.0.000). The flaw is remotely exploitable via HTTP by an unauthenticated attacker, though it requires human interaction. Successful exploitation results in a full takeover of the affected component and may impact other products due to a scope change, achieving high confidentiality, integrity, and availability impact.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70958
Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-60393.
CVE-2026-70970
CVE-2026-70970 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal. The flaw is remotely exploitable without authentication via HTTP, allowing a threat actor to achieve full system compromise (takeover) of the affected portal instance. It holds a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70970
Related in this roundup: CVE-2026-60728, CVE-2026-60729, CVE-2026-60731, CVE-2026-60733.
CVE-2026-70976
CVE-2026-70976 is an unauthenticated, network-exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an attacker to gain unauthorized access to modify or delete critical data and cause a denial-of-service (DoS) condition via repeatable crashes, impacting data integrity and service availability.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70976
Related in this roundup: CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70977
CVE-2026-70977 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized modification or deletion of critical data, as well as trigger a complete denial-of-service condition via HTTP requests. The vulnerability is considered easily exploitable with no user interaction required.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70977
Related in this roundup: CVE-2026-70976, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70978
CVE-2026-70978 is a critical, easily exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.4.0). An unauthenticated attacker with network access can leverage this flaw via HTTP to achieve unauthorized access to, or modification/deletion of, critical data.
Affected products:
- Oracle Commerce Guided Search
- Oracle Commerce Experience Manager
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70978
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70979
CVE-2026-70979 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is easily exploitable by an unauthenticated attacker over HTTP, allowing for unauthorized modification or deletion of critical data, as well as the ability to cause a denial-of-service (DoS) condition.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70979
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70980
CVE-2026-70980 is a high-severity, remotely exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated attacker with network access via HTTP to achieve full compromise of the application with a high impact on confidentiality, integrity, and availability, and it is capable of causing a scope change impacting additional products.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70980
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70981
An unauthenticated remote attacker can exploit a vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager version 11.4.0 via HTTP. Successful exploitation allows for unauthorized modification, deletion, or creation of critical data, as well as the ability to cause a complete denial-of-service (DoS) condition.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70981
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70984
CVE-2026-70984 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized manipulation of critical data and causing a complete denial-of-service (DoS) condition.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70984
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70994
CVE-2026-70994 is a vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data and cause a denial-of-service condition through an HTTP-based attack vector.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70994
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70995
CVE-2026-70995 describes a critical, easily exploitable vulnerability within the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated attacker with network access via HTTP to fully compromise the target application, resulting in a complete takeover of confidentiality, integrity, and availability (CVSS 9.8).
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70995
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70997
CVE-2026-70997 is a critical vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data and cause a denial-of-service (DoS) condition via crafted HTTP requests. The vulnerability is highly exploitable, requiring no authentication or user interaction.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70997
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-70998
CVE-2026-70998 is a critical, unauthenticated remote vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. An attacker with network access can exploit this flaw over HTTP to achieve unauthorized access, modification, or deletion of critical data, with a scope change impact that may affect other products.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70998
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-71014
CVE-2026-71014 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Experience Manager version 11.4.0. The vulnerability allows an unauthenticated attacker with network access via HTTP to gain unauthorized read/write access to critical data. This flaw is remotely exploitable without user interaction.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71014
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-71015
CVE-2026-71015 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized read and write access to critical application data.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71015
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.
CVE-2026-71026
CVE-2026-71026 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated remote attacker with network access via HTTP to perform unauthorized modification, deletion, or disclosure of critical system data.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71026
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71036, CVE-2026-71037.
CVE-2026-71036
CVE-2026-71036 is an easily exploitable, unauthenticated remote access vulnerability in Oracle Commerce Guided Search and Experience Manager version 11.4.0. The vulnerability allows an attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information within the application.
Affected products:
- Oracle Commerce Guided Search (11.4.0)
- Oracle Commerce Experience Manager (11.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71036
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71037.
CVE-2026-71037
CVE-2026-71037 is a critical vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.4.0) that allows an unauthenticated, remote attacker to compromise the system via HTTP. The vulnerability requires user interaction and facilitates unauthorized access to, modification of, or deletion of critical data, representing a significant scope change impact.
Affected products:
- Oracle Commerce Guided Search
- Oracle Commerce Experience Manager
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71037
Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036.
CVE-2026-71040
CVE-2026-71040 is a critical vulnerability in the Security component of Oracle Agile PLM version 9.3.6. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via crafted HTTP requests. Due to the high CVSS score of 9.8 and the ease of exploitation, this represents a significant risk for complete compromise of the product's confidentiality, integrity, and availability.
Affected products:
- Agile PLM (9.3.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71040
CVE-2026-71059
CVE-2026-71059 is a critical vulnerability in the Oracle BI Publisher component of Oracle Analytics. A low-privileged attacker with network access can exploit the Web Service API via SOAP to achieve full takeover of the affected product. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting additional products within the environment.
Affected products:
- BI Publisher (8.2.0.0.0, 26.1.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71059
CVE-2026-71063
A critical vulnerability exists in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated attacker with physical network segment access to achieve a full system compromise. The vulnerability is characterized by a CVSS 3.1 score of 9.6 with a scope change, indicating that successful exploitation can impact broader system integrity and availability beyond the clusterware itself.
Affected products:
- Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71063
Related in this roundup: CVE-2026-71064, CVE-2026-71102.
CVE-2026-71064
CVE-2026-71064 is a critical vulnerability in the Portable Clusterware component of Oracle Database Server. The flaw allows an unauthenticated attacker with access to the physical network segment where the component resides to achieve a full compromise of the service. Due to its impact on Confidentiality, Integrity, and Availability, and its potential for scope change affecting additional products, it is rated with a CVSS score of 9.6.
Affected products:
- Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71064
Related in this roundup: CVE-2026-71063, CVE-2026-71102.
CVE-2026-71065
CVE-2026-71065 is a critical vulnerability affecting the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows unauthenticated remote attackers with network access to compromise the application via HTTP requests. Due to a scope change, successful exploitation enables unauthorized access, modification, or deletion of critical data, resulting in a CVSS 3.1 score of 9.3.
Affected products:
- Helidon (3.2.18)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71065
Related in this roundup: CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-71074
CVE-2026-71074 is a critical vulnerability (CVSS 9.8) in the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated, network-adjacent attacker to achieve a complete takeover of the Helidon instance via crafted HTTP requests.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71074
CVE-2026-71102
CVE-2026-71102 is a critical vulnerability in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated, network-adjacent attacker to perform unauthorized data modifications and trigger a denial-of-service condition via HTTP. The vulnerability is highly exploitable, requiring no privileges or user interaction, impacting both system integrity and availability.
Affected products:
- Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71102
Related in this roundup: CVE-2026-71063, CVE-2026-71064.
CVE-2026-71152
CVE-2026-71152 is a critical RCE vulnerability in the Imperative Web Server component of Oracle Helidon version 4.5.0. An unauthenticated attacker can exploit this via HTTP network access to achieve a full takeover of the Helidon instance, impacting confidentiality, integrity, and availability.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71152
Related in this roundup: CVE-2026-71065, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-71164
CVE-2026-71164 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated attacker to execute a remote takeover of the Helidon server via network-accessible HTTP requests, resulting in full impact on confidentiality, integrity, and availability.
Affected products:
- Helidon (3.2.18)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71164
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-71166
CVE-2026-71166 is a critical vulnerability in the Oracle Fusion Middleware Helidon component (Imperative Web Server), specifically affecting version 3.2.18. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized data manipulation, unauthorized access to critical data, and partial denial-of-service conditions.
Affected products:
- Helidon (3.2.18)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71166
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-71167
CVE-2026-71167 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon 4.5.0. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to or modify critical data, and trigger a partial denial of service. The vulnerability impacts the confidentiality, integrity, and availability of the system.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71167
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73865
CVE-2026-73865 is a critical vulnerability within the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, modification, or deletion of critical data via HTTP requests, posing a high risk to data confidentiality and integrity.
Affected products:
- Helidon (3.2.18)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73865
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73866
CVE-2026-73866 is a critical vulnerability affecting the Imperative Web Server component of Oracle Helidon version 4.5.0. The flaw is remotely exploitable by an unauthenticated attacker over HTTP without user interaction, allowing for unauthorized read, modification, or deletion of critical data accessible by the application.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73866
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73905
CVE-2026-73905 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw allows an unauthenticated attacker to remotely compromise the application via network-accessible HTTP requests, potentially leading to a full takeover of the Helidon instance.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73905
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73912
CVE-2026-73912 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw is remotely exploitable without authentication, allowing an attacker to achieve full system takeover via standard HTTP requests. Given the CVSS 3.1 score of 9.8, this represents a significant risk to the availability, integrity, and confidentiality of the affected service.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73912
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73916
CVE-2026-73916 is a critical vulnerability in the Oracle Fusion Middleware Helidon component, specifically the Imperative Web Server. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to or modify critical data. The vulnerability is remotely exploitable without authentication, resulting in high confidentiality and integrity impacts.
Affected products:
- Helidon (3.2.18)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73916
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73917
CVE-2026-73917 is a high-severity vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw allows an unauthenticated remote attacker with network access to perform unauthorized creation, deletion, or modification of critical data. The vulnerability has a CVSS 3.1 base score of 9.1 and directly impacts both data confidentiality and integrity via HTTP-based exploitation.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73917
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73920
CVE-2026-73920 is a critical vulnerability in the Oracle Helidon Imperative Web Server (version 4.5.0) that allows an unauthenticated remote attacker to compromise the application via HTTP. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, as well as a partial denial-of-service condition.
Affected products:
- Helidon (4.5.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73920
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73921
CVE-2026-73921 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework, affecting version 1.4.20. An unauthenticated attacker with network access can exploit this flaw via HTTP to achieve full takeover of the Helidon instance, impacting confidentiality, integrity, and availability. The vulnerability is rated with a CVSS 3.1 base score of 9.8.
Affected products:
- Helidon (1.4.20)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73921
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73922
CVE-2026-73922 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 1.4.19). An unauthenticated remote attacker can exploit this via HTTP to gain unauthorized access to or perform unauthorized modifications of critical data, resulting in a CVSS score of 9.1.
Affected products:
- Helidon (1.4.19)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73922
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73924, CVE-2026-73930.
CVE-2026-73924
CVE-2026-73924 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon version 1.4.19. The flaw allows an unauthenticated remote attacker to gain unauthorized access to or perform unauthorized modifications of critical data via network-based HTTP requests.
Affected products:
- Helidon (1.4.19)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73924
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73930.
CVE-2026-73930
CVE-2026-73930 is a critical vulnerability in the Helidon component of Oracle Fusion Middleware. An unauthenticated attacker with network access can exploit the Imperative Web Server via HTTP to perform unauthorized modification, deletion, or creation of critical data, as well as unauthorized data reading and partial denial-of-service, with a CVSS base score of 9.9 and scope change.
Affected products:
- Helidon (4.5.3)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73930
Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924.
CVE-2026-60391
CVE-2026-60391 is a critical vulnerability in the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The flaw allows an unauthenticated remote attacker to gain unauthorized access to critical data through the network via HTTP, resulting in significant confidentiality impact.
Affected products:
- Oracle Hyperion Financial Reporting (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60391
CVE-2026-60392
Oracle Outside In Technology, specifically the PDF Export SDK version 8.5.8, is vulnerable to a flaw that allows an unauthenticated attacker with local access to compromise the product. Successful exploitation requires user interaction and can lead to a full takeover of the technology, impacting confidentiality, integrity, and availability.
Affected products:
- Outside In Technology (8.5.8)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60392
Related in this roundup: CVE-2026-60412, CVE-2026-60413.
CVE-2026-60393
CVE-2026-60393 is a vulnerability in the Oracle Hyperion Infrastructure Technology Lifecycle Management component. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, allowing for unauthorized access to sensitive or critical data. The flaw has a CVSS 3.1 base score of 7.5, reflecting a significant impact on data confidentiality.
Affected products:
- Hyperion Infrastructure Technology (11.2.25.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60393
Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958.
CVE-2026-60412
CVE-2026-60412 is a vulnerability in the Oracle Outside In Core component of Oracle Fusion Middleware version 8.5.8. An unauthenticated attacker can exploit this vulnerability with local access and human interaction to take over the component, resulting in full impact on confidentiality, integrity, and availability.
Affected products:
- Outside In Technology (8.5.8)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60412
Related in this roundup: CVE-2026-60392, CVE-2026-60413.
CVE-2026-60413
Oracle Outside In Technology 8.5.8 contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to the infrastructure to compromise the application. The attack requires user interaction and can result in a full takeover of the Oracle Outside In Technology component.
Affected products:
- Outside In Technology (8.5.8)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60413
Related in this roundup: CVE-2026-60392, CVE-2026-60412.
CVE-2026-60414
CVE-2026-60414 is a critical vulnerability in Oracle Outside In Technology within Oracle Fusion Middleware, specifically version 8.5.8. An unauthenticated attacker with local access to the infrastructure can compromise the component, though the attack requires human interaction. Successful exploitation can lead to a complete takeover of the Outside In Technology component, resulting in significant impacts to confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware (8.5.8)
- Outside In Technology (8.5.8)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60414
Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624.
CVE-2026-60415
Oracle WebLogic Server contains a vulnerability in the Core component that allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full compromise of the server. The vulnerability is difficult to exploit but results in high impacts to confidentiality, integrity, and availability.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60415
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60590
CVE-2026-60590 is an unauthenticated, network-accessible vulnerability in the Oracle Hospitality Simphony POS component. An attacker can exploit this via HTTP to gain unauthorized access to critical data or achieve full access to data managed by the system. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant potential for unauthorized information disclosure.
Affected products:
- Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60590
Related in this roundup: CVE-2026-60591.
CVE-2026-60592
CVE-2026-60592 is a vulnerability in the NDB Operator component of Oracle MySQL Cluster that allows unauthenticated, network-adjacent attackers to impact service availability and data integrity. Successful exploitation permits the attacker to trigger a denial-of-service (hang or crash) and perform unauthorized data modifications, including unauthorized updates, inserts, or deletions within the cluster.
Affected products:
- MySQL Cluster (8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60592
CVE-2026-60679
CVE-2026-60679 is a vulnerability in the Core component of Oracle WebLogic Server that allows a low-privileged attacker to achieve a full system takeover via network access using the T3 or IIOP protocols. The vulnerability is characterized as difficult to exploit but carries a high impact on the confidentiality, integrity, and availability of the affected server.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60679
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60680, CVE-2026-60699.
CVE-2026-60680
Oracle WebLogic Server contains a vulnerability in the Core component that allows a low-privileged, network-adjacent attacker to perform unauthorized data manipulation (creation, deletion, or modification) and trigger a denial-of-service (hang or crash) via HTTP. The vulnerability is highly exploitable due to low attack complexity and does not require user interaction, impacting both data integrity and service availability.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60680
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60699.
CVE-2026-60693
CVE-2026-60693 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application, resulting in unauthorized access, modification, or deletion of critical data, as well as the ability to cause a partial denial of service (DoS).
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60693
Related in this roundup: CVE-2026-60782, CVE-2026-70926, CVE-2026-60748.
CVE-2026-60699
CVE-2026-60699 is a critical vulnerability in the Oracle WebLogic Server Core component that allows unauthenticated attackers to gain unauthorized access to data via T3 or IIOP network protocols. Due to the scope change vector, successful exploitation can result in significant impacts across integrated systems, with a CVSS base score of 8.6 targeting data confidentiality.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60699
Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680.
CVE-2026-60707
Oracle Identity Manager in Oracle Fusion Middleware contains a vulnerability that allows a high-privileged attacker with network access via HTTP to compromise the application. The vulnerability has a scope change (S:C) and enables unauthorized modification, deletion, or access to critical data, leading to significant impact on the affected instance and potentially additional integrated products.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60707
Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.
CVE-2026-60715
A critical vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is remotely exploitable over HTTP by an attacker with low privileges, potentially leading to a full takeover of the Identity Manager application.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60715
Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60716, CVE-2026-60722.
CVE-2026-60716
CVE-2026-60716 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager within Oracle Fusion Middleware. A low-privileged attacker with network access via T3 or IIOP protocols can successfully exploit this flaw to gain full control (takeover) of the Oracle Identity Manager instance. The vulnerability carries a CVSS base score of 8.8, reflecting significant impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60716
Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60722.
CVE-2026-60722
CVE-2026-60722 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. An attacker with low-level privileges can leverage network access via T3 or IIOP protocols to achieve full system takeover. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 and carries a CVSS base score of 8.8, posing a high risk to the confidentiality, integrity, and availability of the identity management environment.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60722
Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716.
CVE-2026-60726
Oracle Access Manager (OAM) component of Oracle Fusion Middleware is vulnerable to a flaw in its Authentication Engine. A low-privileged attacker with network access can exploit this via HTTP to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60726
Related in this roundup: CVE-2026-70905.
CVE-2026-60729
A vulnerability in the Composer component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged network attacker to achieve a full takeover of the application via HTTP. The flaw carries a CVSS 3.1 score of 8.8 and impacts confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60729
Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60731, CVE-2026-60733.
CVE-2026-60731
CVE-2026-60731 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is remotely exploitable via RMI by a low-privileged attacker, potentially resulting in a complete takeover of the affected application. It carries a CVSS score of 8.8, reflecting high impact on confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60731
Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60729, CVE-2026-60733.
CVE-2026-60733
Oracle WebCenter Portal, a component of Oracle Fusion Middleware, contains a vulnerability in its Composer feature that allows a low-privileged network attacker to compromise the system. Exploitation can lead to unauthorized data access, unauthorized modification or deletion of critical data, and partial denial of service. The vulnerability supports scope change and is exploitable via HTTP.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60733
Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60729, CVE-2026-60731.
CVE-2026-60742
CVE-2026-60742 is a critical vulnerability in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw allows an unauthenticated attacker with network access via HTTP to potentially take over the PeopleTools environment. Despite the difficulty of exploitation (AC:H), the vulnerability carries a CVSS base score of 8.1, impacting confidentiality, integrity, and availability.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60742
Related in this roundup: CVE-2026-60821.
CVE-2026-60748
CVE-2026-60748 is a high-severity vulnerability within the Internal Operations component of Oracle General Ledger in Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker with high privileges can exploit this flaw over HTTP to achieve unauthorized access to, or modification of, critical data. The vulnerability supports scope changes, meaning successful exploitation can compromise data beyond the General Ledger component.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60748
Related in this roundup: CVE-2026-60782, CVE-2026-70926, CVE-2026-60693.
CVE-2026-60751
CVE-2026-60751 is a vulnerability in the Marketing component of Oracle Siebel CRM versions 17.0 through 26.6. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60751
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60752
CVE-2026-60752 is a vulnerability in the Marketing component of Oracle Siebel CRM versions 17.0 through 26.6. The vulnerability is network-accessible via HTTP and allows a low-privileged attacker to achieve unauthorized access to critical data and cause a partial denial of service. The vulnerability impacts confidentiality and availability.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60752
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60753
CVE-2026-60753 is a vulnerability in the Installation component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. The flaw allows a low-privileged authenticated attacker with local access to the infrastructure to escalate privileges and perform a full takeover of the Siebel CRM Deployment product.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60753
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60757
CVE-2026-60757 is a vulnerability in the Search component of Oracle Siebel CRM, specifically affecting versions 17.0 through 26.6. The flaw allows an unauthenticated attacker with access to the local physical communication segment to perform unauthorized data modification, deletion, or access to critical system information. The vulnerability is characterized by high confidentiality and integrity impact, requiring proximity to the target hardware.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60757
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60758
CVE-2026-60758 is a high-severity vulnerability in the Oracle Siebel CRM AI component. A low-privileged attacker with network access can exploit this via HTTP to gain unauthorized access to data, including the ability to update, insert, or delete information. The vulnerability exhibits a changed scope, meaning successful exploitation can impact secondary products beyond just the Siebel AI component.
Affected products:
- Siebel CRM (25.12-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60758
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60759
Oracle Internet Procurement Connector in Oracle E-Business Suite versions 12.2.3 through 12.2.15 contains an unauthenticated vulnerability accessible via HTTP. The vulnerability allows a remote attacker to achieve unauthorized access to, or modification of, critical data within the component. Due to the high impact on confidentiality and integrity, patching or applying vendor-supplied mitigation is critical for affected deployments.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60759
CVE-2026-60765
CVE-2026-60765 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, allowing a low-privileged attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability is difficult to exploit but carries high impact across confidentiality, integrity, and availability.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60765
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60766, CVE-2026-60767.
CVE-2026-60766
A vulnerability in the REST component of Oracle Siebel CRM allows an unauthenticated remote attacker with network access to compromise the Siebel CRM Integration service via HTTPS. Exploitation results in unauthorized read, write, or deletion access to critical data managed by the integration layer.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60766
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60767.
CVE-2026-60767
CVE-2026-60767 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. A low-privileged attacker with network access can exploit this via HTTP to achieve full takeover of the application. The vulnerability has a CVSS base score of 8.8, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Siebel CRM (17.0-26.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60767
Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766.
CVE-2026-60769
CVE-2026-60769 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw allows a low-privileged attacker with network access via HTTP to perform a full takeover of the Oracle General Ledger application. Exploitation requires high complexity but results in significant impacts to confidentiality, integrity, and availability.