Skip to content
Threat Feed
high threat

Oracle Security Updates - August 2026

Roundup of Oracle security advisories published in August 2026.

CVE search metadata

CVE search record: CVE-2026-60591. Severity: critical. CVSS: 9.1. KEV: no. Product: Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60672. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60696. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60698. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60702. Severity: critical. CVSS: 9.9. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60720. Severity: critical. CVSS: 9.9. KEV: no. Product: Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60721. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60727. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60728. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60730. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60737. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60754. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60782. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60821. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60858. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60861. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60905. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60916. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60921. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60946. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60947. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60958. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60970. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60971. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60977. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60990. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60995. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61001. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61003. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61008. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61018. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61021. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61029. Severity: critical. CVSS: 9.0. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61034. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61066. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61206. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61241. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61248. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61258. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61272. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61317. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-61318. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62452. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62457. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62463. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62512. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62539. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62541. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62543. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62544. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62585. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62588. Severity: critical. CVSS: 9.9. KEV: no. Product: Siebel CRM (25.12-26.6). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62592. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62608. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62609. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62611. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62617. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62618. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62621. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62622. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62624. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62629. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62630. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62632. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62633. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62634. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62635. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62637. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62638. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62639. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-62640. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70668. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70669. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70673. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70689. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70740. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70741. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70817. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70846. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70854. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70855. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70862. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70871. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70873. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70876. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70884. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70905. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70920. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70921. Severity: critical. CVSS: 10.0. KEV: no. Product: Hyperion Financial Management (11.2.25.0.000). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70926. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70954. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70958. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70977. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70978. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70979. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70981. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-70997. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-71014. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-71015. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-71065. Severity: critical. CVSS: 9.3. KEV: no. Product: Helidon (3.2.18). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-71152. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-71167. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-73865. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-73905. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-73912. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-73920. Severity: critical. CVSS: 9.4. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-73921. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60392. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60413. Severity: high. CVSS: 7.8. KEV: no. Product: Outside In Technology (8.5.8). Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60415. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60731. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60752. Severity: high. CVSS: 7.1. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

CVE search record: CVE-2026-60753. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - August 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-08-oracle-security-updates/

What's new

  • 1. added CVE-2026-70981 +1 Aug 18, 23:12 via nvd
  • 2. added CVE-2026-70876 +2 Aug 18, 23:12 via nvd
  • 3. added CVE-2026-70668 +2 Aug 18, 23:12 via nvd
  • 4. added CVE-2026-60753 +1 Aug 18, 23:12 via nvd
  • 5. added CVE-2026-60752 Aug 18, 23:11 via nvd

This roundup covers 177 Oracle security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Agile PLM, Application Testing Suite, BI Publisher, Database Server, Demand Planning, E-Business Suite, Fusion Middleware, Helidon, Hospitality Simphony, Hyperion Calculation Manager, Hyperion Data Relationship Management, Hyperion Financial Management, Hyperion Financial Reporting, Hyperion Infrastructure Technology, Hyperion Profitability and Cost Management, Identity Manager, Internet Directory, JD Edwards EnterpriseOne Tools, Managed File Transfer, MySQL Cluster, Oracle Access Manager, Oracle Commerce Guided Search, Oracle Commerce Platform, Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Hyperion Data Relationship Management, Oracle Hyperion Financial Management, Oracle Hyperion Financial Reporting, Oracle Hyperion Infrastructure Technology, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle Reports Developer, Oracle Web Services Manager, Outside In Technology, PeopleSoft Enterprise PeopleTools, Siebel CRM, Siebel CRM Cloud Applications, WebCenter Content, WebCenter Enterprise Capture, WebCenter Portal, WebCenter Sites, WebLogic Server.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-60591Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)Critical9.1noNVD (authoritative)
CVE-2026-60672WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60696WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60698WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60702WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.9noNVD (authoritative)
CVE-2026-60720Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-60721Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-60727Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-60728WebCenter PortalCritical9.1noNVD (authoritative)
CVE-2026-60730n/aCritical9.9noNVD (authoritative)
CVE-2026-60737Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-60754Siebel CRM (17.0-26.6)Critical9.1noNVD (authoritative)
CVE-2026-60782Oracle E-Business Suite (12.2.3-12.2.15)Critical9.8noNVD (authoritative)
CVE-2026-60821PeopleSoft Enterprise PeopleTools (8.61-8.63)Critical9.8noNVD (authoritative)
CVE-2026-60858Hyperion Calculation Manager (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-60861n/aCritical9.6noNVD (authoritative)
CVE-2026-60905WebCenter Content (12.2.1.4.0, 14.1.2.0.0)Critical9.6noNVD (authoritative)
CVE-2026-60916WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-60921WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60946WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60947n/aCritical9.8noNVD (authoritative)
CVE-2026-60958WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60970WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60971WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60977WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-60990Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-60995Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-61001Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)Critical9.6noNVD (authoritative)
CVE-2026-61003Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-61008WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-61018WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-61021WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-61029WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.0noNVD (authoritative)
CVE-2026-61034WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-61066Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-61206Hyperion Calculation Manager (11.2.25.0.000)Critical9.9noNVD (authoritative)
CVE-2026-61241Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical10.0noNVD (authoritative)
CVE-2026-61248Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-61258Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-61272JD Edwards EnterpriseOne Tools (9.2.0.0-9.2.26.4)Critical9.8noNVD (authoritative)
CVE-2026-61317Siebel CRM Cloud Applications (22.3-26.6)Critical9.9noNVD (authoritative)
CVE-2026-61318Siebel CRM (22.3-26.6)Critical9.8noNVD (authoritative)
CVE-2026-62452Siebel CRM Cloud Applications (22.3-26.6)Critical9.9noNVD (authoritative)
CVE-2026-62457Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-62463Oracle Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.6noNVD (authoritative)
CVE-2026-62512Siebel CRM Cloud Applications (22.3-26.6)Critical9.9noNVD (authoritative)
CVE-2026-62539Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-62541Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-62543Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-62544Oracle Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-62582Hyperion Calculation Manager (11.2.25.0.000)noNVD (authoritative)
CVE-2026-62585Siebel CRM (25.12-26.6)Critical9.8noNVD (authoritative)
CVE-2026-62588Siebel CRM (25.12-26.6)Critical9.9noNVD (authoritative)
CVE-2026-62592Siebel CRM (25.12-26.6)Critical9.8noNVD (authoritative)
CVE-2026-62608Oracle Fusion Middleware (12.2.1.19.0)Critical9.9noNVD (authoritative)
CVE-2026-62609Oracle Reports Developer (12.2.1.19.0)Critical9.8noNVD (authoritative)
CVE-2026-62610Oracle Fusion Middleware (12.2.1.19.0)noNVD (authoritative)
CVE-2026-62611Oracle Reports Developer (12.2.1.19.0)Critical9.8noNVD (authoritative)
CVE-2026-62613Oracle Reports Developer (12.2.1.19.0)noNVD (authoritative)
CVE-2026-62614n/anoNVD (authoritative)
CVE-2026-62617n/aCritical9.8noNVD (authoritative)
CVE-2026-62618Oracle Reports Developer (12.2.1.19.0)Critical9.3noNVD (authoritative)
CVE-2026-62621Oracle Fusion Middleware (12.2.1.19.0)Critical9.8noNVD (authoritative)
CVE-2026-62622Oracle Fusion Middleware (12.2.1.19.0)Critical9.8noNVD (authoritative)
CVE-2026-62624Oracle Fusion MiddlewareCritical9.8noNVD (authoritative)
CVE-2026-62626Fusion Middleware (12.2.1.19.0)noNVD (authoritative)
CVE-2026-62629Oracle Reports Developer (14.1.2.0.0)Critical9.4noNVD (authoritative)
CVE-2026-62630Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-62632Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-62633Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-62634n/aCritical9.8noNVD (authoritative)
CVE-2026-62635Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-62637Oracle Reports Developer (14.1.2.0.0)Critical9.3noNVD (authoritative)
CVE-2026-62638Oracle Reports Developer (14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-62639Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-62640Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-70668Oracle Reports Developer (14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-70669Oracle Reports Developer (14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-70670n/anoNVD (authoritative)
CVE-2026-70673Oracle Reports Developer (14.1.2.0.0)Critical9.3noNVD (authoritative)
CVE-2026-70689n/aCritical9.8noNVD (authoritative)
CVE-2026-70730Hyperion Profitability and Cost Management (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70739Hyperion Financial Reporting (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70740Hyperion Financial Reporting (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-70741Hyperion Financial Reporting (11.2.25.0.000)Critical9.1noNVD (authoritative)
CVE-2026-70745Hyperion Financial Reporting (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70817Hyperion Financial Management (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-70846Demand Planning (12.1, 12.2)Critical9.6noNVD (authoritative)
CVE-2026-70854Oracle Hyperion Financial Management (11.2.25.0.000)Critical9.1noNVD (authoritative)
CVE-2026-70855Siebel CRM (17.0-26.6)Critical9.3noNVD (authoritative)
CVE-2026-70862Application Testing Suite (13.3.0.1)Critical9.1noNVD (authoritative)
CVE-2026-70871Oracle Hyperion Data Relationship Management (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-70872Hyperion Data Relationship Management (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70873Hyperion Data Relationship Management (11.2.25.0.000)Critical9.8noNVD (authoritative)
CVE-2026-70876Hyperion Data Relationship Management (11.2.25.0.000)Critical9.1noNVD (authoritative)
CVE-2026-70880Hyperion Data Relationship Management (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70883Hyperion Data Relationship Management (11.2.25.0.000)noNVD (authoritative)
CVE-2026-70884Hyperion Data Relationship Management (11.2.25.0.000)Critical9.1noNVD (authoritative)
CVE-2026-70905Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-70920Hyperion Financial Management (11.2.25.0.000)Critical9.9noNVD (authoritative)
CVE-2026-70921Hyperion Financial Management (11.2.25.0.000)Critical10.0noNVD (authoritative)
CVE-2026-70926Oracle E-Business Suite (12.2.3-12.2.15)Critical9.8noNVD (authoritative)
CVE-2026-70953Oracle Commerce Platform (11.4.0)noNVD (authoritative)
CVE-2026-70954Oracle Commerce Platform (11.4.0)Critical9.8noNVD (authoritative)
CVE-2026-70958Hyperion Infrastructure Technology (11.2.25.0.000)Critical9.6noNVD (authoritative)
CVE-2026-70970WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-70976Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70977Oracle Commerce Guided Search (11.4.0)Critical9.1noNVD (authoritative)
CVE-2026-70978Oracle Commerce Guided SearchCritical9.1noNVD (authoritative)
CVE-2026-70979Oracle Commerce Guided Search (11.4.0)Critical9.1noNVD (authoritative)
CVE-2026-70980Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70981Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70984Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70994Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70995Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-70997Oracle Commerce Guided Search (11.4.0)Critical9.1noNVD (authoritative)
CVE-2026-70998Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-71014Oracle Commerce Guided Search (11.4.0)Critical9.1noNVD (authoritative)
CVE-2026-71015Oracle Commerce Guided Search (11.4.0)Critical9.1noNVD (authoritative)
CVE-2026-71026Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-71036Oracle Commerce Guided Search (11.4.0)noNVD (authoritative)
CVE-2026-71037Oracle Commerce Guided SearchnoNVD (authoritative)
CVE-2026-71040Agile PLM (9.3.6)noNVD (authoritative)
CVE-2026-71059BI Publisher (8.2.0.0.0, 26.1.0.0.0)noNVD (authoritative)
CVE-2026-71063Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)noNVD (authoritative)
CVE-2026-71064Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)noNVD (authoritative)
CVE-2026-71065Helidon (3.2.18)Critical9.3noNVD (authoritative)
CVE-2026-71074n/anoNVD (authoritative)
CVE-2026-71102Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)noNVD (authoritative)
CVE-2026-71152Helidon (4.5.0)Critical9.8noNVD (authoritative)
CVE-2026-71164Helidon (3.2.18)noNVD (authoritative)
CVE-2026-71166Helidon (3.2.18)noNVD (authoritative)
CVE-2026-71167Helidon (4.5.0)noNVD (authoritative)
CVE-2026-73865Helidon (3.2.18)Critical9.1noNVD (authoritative)
CVE-2026-73866Helidon (4.5.0)noNVD (authoritative)
CVE-2026-73905Helidon (4.5.0)Critical9.8noNVD (authoritative)
CVE-2026-73912Helidon (4.5.0)Critical9.8noNVD (authoritative)
CVE-2026-73916Helidon (3.2.18)noNVD (authoritative)
CVE-2026-73917Helidon (4.5.0)noNVD (authoritative)
CVE-2026-73920Helidon (4.5.0)Critical9.4noNVD (authoritative)
CVE-2026-73921Helidon (1.4.20)Critical9.8noNVD (authoritative)
CVE-2026-73922Helidon (1.4.19)noNVD (authoritative)
CVE-2026-73924Helidon (1.4.19)noNVD (authoritative)
CVE-2026-73930Helidon (4.5.3)noNVD (authoritative)
CVE-2026-60391Oracle Hyperion Financial Reporting (11.2.25.0.000)noNVD (authoritative)
CVE-2026-60392Outside In Technology (8.5.8)High7.8noNVD (authoritative)
CVE-2026-60393Hyperion Infrastructure Technology (11.2.25.0.000)noNVD (authoritative)
CVE-2026-60412Outside In Technology (8.5.8)noNVD (authoritative)
CVE-2026-60413Outside In Technology (8.5.8)High7.8noNVD (authoritative)
CVE-2026-60414Oracle Fusion Middleware (8.5.8)noNVD (authoritative)
CVE-2026-60415WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)High8.1noNVD (authoritative)
CVE-2026-60590Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)noNVD (authoritative)
CVE-2026-60592MySQL Cluster (8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1)noNVD (authoritative)
CVE-2026-60679WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)noNVD (authoritative)
CVE-2026-60680WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)noNVD (authoritative)
CVE-2026-60693Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-60699WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)noNVD (authoritative)
CVE-2026-60707Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-60715Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-60716Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-60722Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-60726Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-60729WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-60731WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High8.8noNVD (authoritative)
CVE-2026-60733WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-60742PeopleSoft Enterprise PeopleTools (8.61-8.63)noNVD (authoritative)
CVE-2026-60748Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-60751Siebel CRM (17.0-26.6)noNVD (authoritative)
CVE-2026-60752Siebel CRM (17.0-26.6)High7.1noNVD (authoritative)
CVE-2026-60753Siebel CRM (17.0-26.6)High7.8noNVD (authoritative)
CVE-2026-60757Siebel CRM (17.0-26.6)noNVD (authoritative)
CVE-2026-60758Siebel CRM (25.12-26.6)noNVD (authoritative)
CVE-2026-60759E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-60765Siebel CRM (17.0-26.6)noNVD (authoritative)
CVE-2026-60766Siebel CRM (17.0-26.6)noNVD (authoritative)
CVE-2026-60767Siebel CRM (17.0-26.6)noNVD (authoritative)
CVE-2026-60769n/anoNVD (authoritative)

CVE-2026-60591

Oracle Hospitality Simphony contains a high-severity vulnerability that allows an unauthenticated attacker to perform unauthorized data modification or deletion and trigger a denial-of-service condition via network-based HTTP requests. The vulnerability affects multiple versions of the POS component.

Affected products:

  • Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60591

Related in this roundup: CVE-2026-60590.

CVE-2026-60672

CVE-2026-60672 is a critical vulnerability in Oracle WebLogic Server (Core component) that allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full server takeover. The vulnerability is remotely exploitable without user interaction and carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60672

Related in this roundup: CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60696

Oracle WebLogic Server contains a critical vulnerability in its Core component that allows unauthenticated, network-adjacent attackers to achieve full system takeover via T3 or IIOP protocols. The flaw is easily exploitable, requiring no user interaction or authentication, and impacts confidentiality, integrity, and availability.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60696

Related in this roundup: CVE-2026-60672, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60698

CVE-2026-60698 is a critical vulnerability affecting the Core component of Oracle WebLogic Server. An unauthenticated attacker can exploit this via the IIOP protocol over the network to achieve full system takeover. The vulnerability carries a CVSS 3.1 score of 9.8 and impacts the confidentiality, integrity, and availability of the affected server.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60698

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60702

CVE-2026-60702 is a critical vulnerability in Oracle WebLogic Server (Core component) that allows a low-privileged attacker with network access via T3 or IIOP protocols to perform a full takeover of the server. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting other integrated products in the Fusion Middleware environment.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60702

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60720

CVE-2026-60720 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw allows a low-privileged attacker with network access via HTTP to achieve full compromise of the application. Due to a scope change, this vulnerability can also impact additional products, warranting a CVSS 3.1 base score of 9.9.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60720

Related in this roundup: CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.

CVE-2026-60721

CVE-2026-60721 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full takeover of the application. It is classified as easily exploitable and carries a CVSS 3.1 base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60721

Related in this roundup: CVE-2026-60720, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.

CVE-2026-60727

CVE-2026-60727 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to a full system takeover. It carries a CVSS base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60727

CVE-2026-60728

Oracle WebCenter Portal, specifically the Portlet Services component in versions 12.2.1.4.0 and 14.1.2.0.0, contains an unauthenticated vulnerability exploitable via HTTP network access. Successful exploitation allows an attacker to gain unauthorized access to sensitive data and cause a complete denial-of-service by crashing the application.

Affected products:

  • WebCenter Portal

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60728

Related in this roundup: CVE-2026-70970, CVE-2026-60729, CVE-2026-60731, CVE-2026-60733.

CVE-2026-60730

CVE-2026-60730 is a critical vulnerability within the Composer component of Oracle WebCenter Portal. The flaw is remotely exploitable via HTTP by low-privileged attackers, potentially leading to a complete system takeover and impacting the confidentiality, integrity, and availability of the affected environment. The vulnerability is characterized by a scope change, indicating that successful exploitation can impact associated systems beyond the target product.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60730

CVE-2026-60737

CVE-2026-60737 is a critical vulnerability in the Oracle Web Services Manager component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, remote attacker with HTTP network access to perform unauthorized read, write, or deletion operations on critical data managed by the service. Given the high CVSS base score and lack of required authentication or user interaction, this flaw represents a significant risk for data integrity and confidentiality.

Affected products:

  • Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60737

Related in this roundup: CVE-2026-61001.

CVE-2026-60754

CVE-2026-60754 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. The flaw is remotely exploitable by an unauthenticated attacker over HTTP, potentially leading to unauthorized access to sensitive data and complete denial-of-service via application crashes.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60754

Related in this roundup: CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60782

CVE-2026-60782 is a critical vulnerability in the Oracle Payments component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is remotely exploitable without authentication via HTTP and allows an attacker to achieve full takeover of the Oracle Payments service, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60782

Related in this roundup: CVE-2026-70926, CVE-2026-60693, CVE-2026-60748.

CVE-2026-60821

CVE-2026-60821 is a critical vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, allowing for a complete takeover of the PeopleTools environment. With a CVSS base score of 9.8, it poses a high risk to confidentiality, integrity, and availability.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60821

Related in this roundup: CVE-2026-60742.

CVE-2026-60858

CVE-2026-60858 is a critical vulnerability in Oracle Hyperion Calculation Manager, version 11.2.25.0.000. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve full system takeover via unauthenticated HTTP requests, resulting in total loss of confidentiality, integrity, and availability.

Affected products:

  • Hyperion Calculation Manager (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60858

Related in this roundup: CVE-2026-61206, CVE-2026-62582.

CVE-2026-60861

CVE-2026-60861 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. An attacker with low privileges and network access via Oracle Net can exploit this vulnerability to achieve unauthorized access to, creation of, deletion of, or modification of critical data. Due to a change in scope, a successful exploit can impact additional products beyond the Service Delivery Platform itself.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60861

CVE-2026-60905

CVE-2026-60905 is a high-severity vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to compromise the system via HTTP, provided they can induce human interaction. Successful exploitation permits unauthorized access, modification, or deletion of critical data, as well as the ability to cause a partial denial of service. The vulnerability involves a scope change, meaning impacts may extend to other products within the environment.

Affected products:

  • WebCenter Content (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60905

CVE-2026-60916

CVE-2026-60916 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is remotely exploitable without authentication via HTTP, allowing an attacker to impact confidentiality, integrity, and availability. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, as well as a partial denial-of-service, with potential for scope change affecting additional products.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60916

Related in this roundup: CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.

CVE-2026-60921

CVE-2026-60921 is a critical vulnerability in Oracle WebCenter Enterprise Capture (Client Bundle component) allowing unauthenticated attackers to achieve full system takeover via T3 or IIOP network protocols. The vulnerability carries a CVSS 3.1 base score of 9.8 and impacts confidentiality, integrity, and availability.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60921

Related in this roundup: CVE-2026-60916, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.

CVE-2026-60946

CVE-2026-60946 is a critical vulnerability in Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) involving the Client Bundle component. The vulnerability allows an unauthenticated attacker to execute code remotely via RMI with network access, leading to a full takeover of the application. It is highly exploitable and impacts the confidentiality, integrity, and availability of the system.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60946

Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971.

CVE-2026-60947

CVE-2026-60947 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve full system takeover via RMI requests. Detection engineers should monitor for unauthorized or unusual RMI traffic patterns directed at the WebCenter Enterprise Capture application, as successful exploitation results in complete compromise of confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60947

CVE-2026-60958

CVE-2026-60958 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is remotely exploitable without authentication via HTTP and can lead to a full system takeover, indicating a high risk of remote code execution or significant privilege manipulation.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60958

Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60970, CVE-2026-60971.

CVE-2026-60970

CVE-2026-60970 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8 and impacts the confidentiality, integrity, and availability of the affected system.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60970

Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60971.

CVE-2026-60971

CVE-2026-60971 is a critical vulnerability (CVSS 9.8) affecting Oracle WebCenter Enterprise Capture within Oracle Fusion Middleware. An unauthenticated attacker with network access via T3 or IIOP protocols can exploit this flaw to fully compromise the target application. Successful exploitation leads to a complete takeover of the service, impacting confidentiality, integrity, and availability.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60971

Related in this roundup: CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60958, CVE-2026-60970.

CVE-2026-60977

CVE-2026-60977 is a critical remote code execution vulnerability in the WLS Core Components of Oracle WebLogic Server. The vulnerability allows unauthenticated attackers with network access to the server to gain full control via RMI, resulting in a complete takeover of the affected component. It is rated with a CVSS 3.1 base score of 9.8.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60977

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60990

CVE-2026-60990 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with network access over TLS can exploit this vulnerability to achieve full compromise (takeover) of the component. The vulnerability carries a CVSS base score of 9.9 and allows for scope change, indicating the potential to impact additional products within the environment.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60990

Related in this roundup: CVE-2026-60995.

CVE-2026-60995

CVE-2026-60995 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with network access via TLS can exploit this flaw to achieve full system takeover. The vulnerability allows for scope change, potentially impacting additional products in the environment, and carries a CVSS base score of 9.9.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60995

Related in this roundup: CVE-2026-60990.

CVE-2026-61001

CVE-2026-61001 is a critical vulnerability in Oracle Web Services Manager within Oracle Fusion Middleware, allowing a low-privileged attacker with network access via HTTP to compromise the service. Due to a scope change (S:C), the vulnerability can result in unauthorized creation, deletion, or modification of critical data. It carries a CVSS 3.1 base score of 9.6, indicating significant impact to confidentiality and integrity.

Affected products:

  • Oracle Web Services Manager (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61001

Related in this roundup: CVE-2026-60737.

CVE-2026-61003

A critical vulnerability exists in the Oracle Managed File Transfer component of Oracle Fusion Middleware, allowing a low-privileged, network-adjacent attacker to achieve full takeover of the MFT Runtime Server via T3 or IIOP protocols. The flaw supports scope change, meaning exploitation can potentially lead to the compromise of additional products within the environment, warranting immediate patching.

Affected products:

  • Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61003

CVE-2026-61008

CVE-2026-61008 is a critical vulnerability in Oracle WebCenter Sites (part of Fusion Middleware) that allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, deletion, or modification of critical data. With a CVSS 3.1 score of 9.1, this flaw is highly exploitable via HTTP and impacts the confidentiality and integrity of the application data.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61008

Related in this roundup: CVE-2026-61018, CVE-2026-61021, CVE-2026-61029, CVE-2026-61034.

CVE-2026-61018

CVE-2026-61018 is a critical vulnerability affecting Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 within the Oracle Fusion Middleware suite. The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to a full system takeover. It carries a CVSS 3.1 base score of 9.8, indicating severe confidentiality, integrity, and availability impacts.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61018

Related in this roundup: CVE-2026-61008, CVE-2026-61021, CVE-2026-61029, CVE-2026-61034.

CVE-2026-61021

A critical vulnerability exists in Oracle WebCenter Sites within the Oracle Fusion Middleware suite, allowing low-privileged, network-adjacent attackers to achieve complete system takeover via HTTP. The vulnerability has a CVSS 3.1 base score of 9.9 and impacts confidentiality, integrity, and availability, with an associated scope change that may affect secondary products.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61021

Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61029, CVE-2026-61034.

CVE-2026-61029

Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to an unauthenticated, remote code execution or takeover attack. The vulnerability is accessible over the network via HTTP and allows for significant impact across the environment due to a change in scope, carrying a CVSS 3.1 base score of 9.0.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61029

Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61021, CVE-2026-61034.

CVE-2026-61034

CVE-2026-61034 is a critical vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware. The flaw is remotely exploitable over HTTP by a high-privileged attacker, potentially leading to a full system takeover and impacting additional products through scope change. The vulnerability carries a CVSS 3.1 base score of 9.1.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61034

Related in this roundup: CVE-2026-61008, CVE-2026-61018, CVE-2026-61021, CVE-2026-61029.

CVE-2026-61066

CVE-2026-61066 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. An attacker with low privileges can exploit this vulnerability via RMI over the network to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 score of 9.9 and involves a scope change, meaning it can facilitate broader compromise beyond the Oracle Identity Manager environment.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61066

Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.

CVE-2026-61206

CVE-2026-61206 is a critical vulnerability in the Security component of Oracle Hyperion Calculation Manager version 11.2.25.0.000. It allows a low-privileged, network-based attacker to execute a successful takeover of the application via HTTP. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting additional products within the environment.

Affected products:

  • Hyperion Calculation Manager (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61206

Related in this roundup: CVE-2026-60858, CVE-2026-62582.

CVE-2026-61241

CVE-2026-61241 is a critical vulnerability in the OID LDAP Server component of Oracle Internet Directory. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve a complete takeover of the directory service. The vulnerability carries a CVSS base score of 10.0 and impacts the confidentiality, integrity, and availability of the system with an increased scope.

Affected products:

  • Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61241

Related in this roundup: CVE-2026-61258.

CVE-2026-61248

CVE-2026-61248 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. A low-privileged attacker with network access via the LDAP protocol can achieve a full takeover of the Oracle Internet Directory. Due to the scope change (S:C), successful exploitation impacts the confidentiality, integrity, and availability of the directory service and potentially associated systems.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61248

CVE-2026-61258

CVE-2026-61258 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw via the LDAP protocol over the network to achieve a full takeover of the affected service. The vulnerability has a CVSS base score of 9.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61258

Related in this roundup: CVE-2026-61241.

CVE-2026-61272

CVE-2026-61272 is a critical vulnerability in the Web Runtime SEC component of Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.4. The vulnerability allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. Given the CVSS score of 9.8 and the lack of required authentication, this flaw represents a significant risk for RCE or full application compromise.

Affected products:

  • JD Edwards EnterpriseOne Tools (9.2.0.0-9.2.26.4)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61272

CVE-2026-61317

CVE-2026-61317 is a critical vulnerability in the Oracle Siebel Cloud Manager component of Siebel CRM Cloud Applications (versions 22.3-26.6). A low-privileged attacker with network access can exploit this via HTTP to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.9 and involves a scope change, allowing impacts to propagate to other products.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61317

Related in this roundup: CVE-2026-62452, CVE-2026-62512.

CVE-2026-61318

CVE-2026-61318 is a critical vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via HTTP requests. With a CVSS 3.1 base score of 9.8, this vulnerability poses a severe risk to confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM (22.3-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-61318

Related in this roundup: CVE-2026-60754, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-62452

CVE-2026-62452 is a critical, easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.6). An unauthenticated attacker with network access can leverage HTTP to achieve unauthorized access to critical data, perform unauthorized modifications (update, insert, or delete) on accessible data, and trigger a partial denial of service. The vulnerability impacts the confidentiality, integrity, and availability of the application with a CVSS 3.1 base score of 9.9.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62452

Related in this roundup: CVE-2026-61317, CVE-2026-62512.

CVE-2026-62457

CVE-2026-62457 is a critical vulnerability in the Common Events component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The flaw is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover by compromising confidentiality, integrity, and availability. With a CVSS base score of 9.8, it represents a high-risk entry point for unauthorized remote access.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62457

Related in this roundup: CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.

CVE-2026-62463

Oracle Hyperion Infrastructure Technology version 11.2.25.0.000 is vulnerable to an easily exploitable flaw in the Lifecycle Management component. A low-privileged attacker with network access via HTTP can trigger a scope change to perform unauthorized data modification, deletion, or access to critical system data. The vulnerability carries a high CVSS base score of 9.6, indicating significant impact on data confidentiality and integrity.

Affected products:

  • Oracle Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62463

Related in this roundup: CVE-2026-62544.

CVE-2026-62512

CVE-2026-62512 is a critical vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. The vulnerability allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP requests. Due to the high CVSS score of 9.9 and the potential for a scope change affecting downstream products, this vulnerability represents a significant risk to confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62512

Related in this roundup: CVE-2026-61317, CVE-2026-62452.

CVE-2026-62539

CVE-2026-62539 is a critical vulnerability affecting the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. An unauthenticated attacker can exploit this flaw over the network via HTTP to achieve full compromise of the application, resulting in impacts to confidentiality, integrity, and availability with a CVSS base score of 9.8.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62539

Related in this roundup: CVE-2026-62457, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.

CVE-2026-62541

A critical vulnerability exists in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology version 11.2.25.0.000. The flaw is remotely exploitable over HTTP by an unauthenticated attacker without user interaction, potentially leading to a full system takeover. Given the high CVSS score of 9.8, this represents a severe risk to the confidentiality, integrity, and availability of the affected infrastructure.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62541

Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62543, CVE-2026-70958, CVE-2026-60393.

CVE-2026-62543

CVE-2026-62543 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology component 'Installation and Configuration' (version 11.2.25.0.000). The flaw allows an unauthenticated attacker to achieve full system takeover via network-accessible HTTP requests, resulting in high impact to confidentiality, integrity, and availability.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62543

Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-70958, CVE-2026-60393.

CVE-2026-62544

CVE-2026-62544 is a critical vulnerability in the Installation and Configuration component of Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000. The flaw is remotely exploitable over HTTP by an unauthenticated attacker, potentially leading to a full system takeover. Given the CVSS 9.8 score and lack of required authentication, detection efforts should focus on anomalous HTTP requests targeting the installation or configuration endpoints of the Hyperion suite.

Affected products:

  • Oracle Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62544

Related in this roundup: CVE-2026-62463.

CVE-2026-62582

Oracle Hyperion Calculation Manager version 11.2.25.0.000 contains a vulnerability in its Security component that allows a low-privileged, network-adjacent attacker to perform unauthorized actions, including the creation, deletion, or modification of critical data. Due to a scope change, successful exploitation can result in complete access to sensitive data managed by the application, with a high CVSS base score of 9.6.

Affected products:

  • Hyperion Calculation Manager (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62582

Related in this roundup: CVE-2026-60858, CVE-2026-61206.

CVE-2026-62585

CVE-2026-62585 is a critical vulnerability in the Data Archival component of Oracle Siebel CRM Administration versions 25.12 through 26.6. The flaw is remotely exploitable without authentication via HTTP, potentially allowing a full system takeover. Security teams should prioritize patching affected instances due to the high CVSS score of 9.8.

Affected products:

  • Siebel CRM (25.12-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62585

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-62588

CVE-2026-62588 is a critical vulnerability within the Open Integration component of Oracle Siebel CRM, allowing a low-privileged attacker with network access via HTTP to achieve a full takeover of the Siebel CRM Integration product. The vulnerability carries a CVSS base score of 9.9 and involves a scope change, potentially impacting additional integrated products.

Affected products:

  • Siebel CRM (25.12-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62588

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-62592

CVE-2026-62592 is a critical vulnerability in the Open Integration component of Oracle Siebel CRM, affecting versions 25.12 through 26.6. The flaw allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the Siebel CRM Integration product via crafted HTTP requests, resulting in full impact to confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM (25.12-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62592

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-62608

CVE-2026-62608 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this flaw via CORBA to achieve a full takeover of the application. The vulnerability allows for scope change, potentially impacting additional products, with a CVSS 3.1 base score of 9.9.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62608

Related in this roundup: CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.

CVE-2026-62609

CVE-2026-62609 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The vulnerability is remotely exploitable without authentication via TCP, allowing an attacker to achieve full takeover of the affected product with significant impacts on confidentiality, integrity, and availability.

Affected products:

  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62609

Related in this roundup: CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62610

CVE-2026-62610 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The flaw is remotely exploitable by an unauthenticated attacker over HTTP, allowing for unauthorized access to, or modification/deletion of, critical data. The vulnerability possesses a CVSS 3.1 base score of 9.1.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62610

Related in this roundup: CVE-2026-62608, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.

CVE-2026-62611

CVE-2026-62611 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware. The vulnerability allows an unauthenticated, remote attacker to gain full control of the application via the IIOP protocol. Due to the lack of required authentication and low complexity of the exploit, this vulnerability poses a severe risk of complete system compromise.

Affected products:

  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62611

Related in this roundup: CVE-2026-62609, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62613

CVE-2026-62613 is a vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The vulnerability is network-adjacent (accessible via the physical communication segment), allowing an unauthenticated attacker to compromise the product and access or modify critical data. The vulnerability involves a scope change and carries a CVSS 3.1 base score of 9.3.

Affected products:

  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62613

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62614

Oracle Reports Developer in Oracle Fusion Middleware version 12.2.1.19.0 contains a critical, easily exploitable vulnerability in the Security and Authentication component. An unauthenticated attacker can leverage network access via HTTP to achieve full compromise (takeover) of the application. The vulnerability carries a CVSS base score of 9.8.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62614

CVE-2026-62617

CVE-2026-62617 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware version 12.2.1.19.0. An unauthenticated attacker can exploit this flaw via network access over UDP to gain full control of the affected product, leading to total compromise of confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62617

CVE-2026-62618

CVE-2026-62618 is a critical vulnerability in Oracle Reports Developer (part of Oracle Fusion Middleware) that allows unauthenticated, network-based attackers to compromise the system via HTTP. The vulnerability has a high CVSS score of 9.3 and exhibits a scope change, meaning successful exploitation can lead to unauthorized access, modification, or deletion of critical data across the target application and potentially impacted secondary products.

Affected products:

  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62618

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62621

CVE-2026-62621 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware version 12.2.1.19.0. An unauthenticated attacker can exploit this flaw via network access over TCP to achieve a complete takeover of the affected product. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating severe impacts to confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0)
  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62621

Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62622, CVE-2026-62624, CVE-2026-60414.

CVE-2026-62622

CVE-2026-62622 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware version 12.2.1.19.0. The vulnerability is easily exploitable by an unauthenticated attacker over a network via the IIOP protocol. Successful exploitation allows for a full takeover of the Oracle Reports Developer instance, resulting in complete compromise of confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0)
  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62622

Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62624, CVE-2026-60414.

CVE-2026-62624

CVE-2026-62624 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (within Oracle Fusion Middleware) that allows an unauthenticated, network-adjacent attacker to achieve full system takeover via IIOP. The vulnerability is easily exploitable and carries a CVSS base score of 9.8, necessitating immediate patching of the affected 12.2.1.19.0 version.

Affected products:

  • Oracle Fusion Middleware
  • Oracle Reports Developer (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62624

Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-60414.

CVE-2026-62626

CVE-2026-62626 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 12.2.1.19.0. The flaw allows unauthenticated remote attackers to achieve full system takeover via HTTP requests, resulting in high impact across confidentiality, integrity, and availability.

Affected products:

  • Fusion Middleware (12.2.1.19.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62626

CVE-2026-62629

CVE-2026-62629 is a critical vulnerability in Oracle Reports Developer (Oracle Fusion Middleware) that allows an unauthenticated attacker to exploit the application via HTTP. The vulnerability enables unauthorized read/write access to data and can trigger a denial-of-service (DoS) condition, impacting system availability and data integrity.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62629

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62630

CVE-2026-62630 describes a critical, easily exploitable vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 14.1.2.0.0. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via TCP, resulting in high impact to confidentiality, integrity, and availability.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62630

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62632

CVE-2026-62632 is a critical vulnerability within the Security and Authentication component of Oracle Reports Developer, part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over HTTP to gain full control of the application, resulting in a complete compromise of confidentiality, integrity, and availability. Given the CVSS score of 9.8 and the lack of required authentication, this vulnerability represents a severe RCE risk to exposed instances.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62632

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62633

A critical vulnerability exists in the Oracle Reports Developer component of Oracle Fusion Middleware version 14.1.2.0.0. The vulnerability allows an unauthenticated attacker with network access to execute an exploit via HTTP, potentially leading to a full takeover of the application. The flaw carries a CVSS 3.1 base score of 9.8, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62633

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62634

CVE-2026-62634 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware version 14.1.2.0.0. The vulnerability allows an unauthenticated attacker with network access to the CORBA interface to achieve full system takeover, with a CVSS base score of 9.8 representing complete impact on confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62634

CVE-2026-62635

CVE-2026-62635 is a critical vulnerability in Oracle Reports Developer within Oracle Fusion Middleware, specifically affecting the Security and Authentication component. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for full system takeover. With a CVSS base score of 9.8, it represents a high-risk remote code execution scenario requiring immediate patching.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62635

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62637

CVE-2026-62637 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with local network access (physical communication segment) to perform unauthorized data access, modification, or deletion. The vulnerability affects version 14.1.2.0.0 and allows for scope change, potentially impacting other products in the environment.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62637

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62638

CVE-2026-62638 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with network access via HTTP to perform unauthorized modifications to critical data and cause a denial-of-service condition, impacting system integrity and availability.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62638

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62639

CVE-2026-62639 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer within Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to exploit CORBA interfaces, leading to a complete takeover of the application. The vulnerability carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62639

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-62640

CVE-2026-62640 is a critical vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware, specifically within the Security and Authentication module. The flaw allows an unauthenticated remote attacker with network access to the IIOP interface to achieve full system compromise, including the takeover of the application. The vulnerability carries a CVSS 3.1 base score of 9.8.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62640

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-70668, CVE-2026-70669, CVE-2026-70673.

CVE-2026-70668

Oracle Reports Developer in Oracle Fusion Middleware contains a vulnerability in the Security and Authentication component that allows unauthenticated attackers to gain unauthorized access to critical data. The vulnerability is exploitable over the network via SOAP requests, resulting in potential unauthorized creation, deletion, or modification of accessible data with a CVSS base score of 9.1.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70668

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70669, CVE-2026-70673.

CVE-2026-70669

CVE-2026-70669 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (part of Oracle Fusion Middleware). The flaw allows an unauthenticated remote attacker with network access to achieve a complete takeover of the application via HTTP. With a CVSS base score of 9.8, it represents a high-impact risk to confidentiality, integrity, and availability.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70669

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70673.

CVE-2026-70670

CVE-2026-70670 is a critical vulnerability in the Security and Authentication component of Oracle Reports Developer (version 14.1.2.0.0). The vulnerability is easily exploitable by an unauthenticated attacker with local network access to the physical communication segment where the software resides. Successful exploitation allows for a full system takeover and impacts the confidentiality, integrity, and availability of the affected product, with potential for scope change affecting other systems.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70670

CVE-2026-70673

CVE-2026-70673 is a high-severity, easily exploitable vulnerability in Oracle Reports Developer within Oracle Fusion Middleware. It allows unauthenticated attackers with network access via HTTP to compromise the application, potentially leading to unauthorized access, modification, or deletion of critical data. Due to the scope change, successful exploitation may have broader impacts beyond the component itself.

Affected products:

  • Oracle Reports Developer (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70673

Related in this roundup: CVE-2026-62609, CVE-2026-62611, CVE-2026-62613, CVE-2026-62618, CVE-2026-62629, CVE-2026-62630, CVE-2026-62632, CVE-2026-62633, CVE-2026-62635, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669.

CVE-2026-70689

CVE-2026-70689 is a critical remote code execution vulnerability in the Infrastructure component of Oracle Essbase, specifically version 21.8.1.0.0. The vulnerability allows an unauthenticated remote attacker to gain full control of the application via a network-based HTTP request, leading to a complete system takeover.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70689

CVE-2026-70730

CVE-2026-70730 is a critical vulnerability in the Deployment component of Oracle Hyperion Profitability and Cost Management version 11.2.25.0.000. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized data modification, creation, or deletion via HTTP requests, leading to full unauthorized access to critical data. The vulnerability is easily exploitable and carries a CVSS 3.1 base score of 9.1.

Affected products:

  • Hyperion Profitability and Cost Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70730

CVE-2026-70739

CVE-2026-70739 is a critical vulnerability in the Oracle Hyperion Financial Reporting server component, specifically version 11.2.25.0.000. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the application, leading to a complete takeover of confidentiality, integrity, and availability. The vulnerability is rated with a CVSS 3.1 base score of 9.8.

Affected products:

  • Hyperion Financial Reporting (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70739

Related in this roundup: CVE-2026-70740, CVE-2026-70741, CVE-2026-70745.

CVE-2026-70740

Oracle Hyperion Financial Reporting version 11.2.25.0.000 contains a critical vulnerability allowing unauthenticated remote attackers to compromise the application via HTTP network access. Successful exploitation leads to a full takeover of the Financial Reporting server, impacting confidentiality, integrity, and availability with a CVSS base score of 9.8.

Affected products:

  • Hyperion Financial Reporting (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70740

Related in this roundup: CVE-2026-70739, CVE-2026-70741, CVE-2026-70745.

CVE-2026-70741

CVE-2026-70741 is a critical vulnerability in Oracle Hyperion Financial Reporting (version 11.2.25.0.000) allowing an unauthenticated remote attacker with network access to leverage RMI to gain unauthorized access to or modify critical data. The vulnerability has a CVSS 3.1 score of 9.1, reflecting high confidentiality and integrity risks.

Affected products:

  • Hyperion Financial Reporting (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70741

Related in this roundup: CVE-2026-70739, CVE-2026-70740, CVE-2026-70745.

CVE-2026-70745

CVE-2026-70745 is a critical vulnerability in the Oracle Hyperion Financial Reporting server component (version 11.2.25.0.000). The flaw is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover. With a CVSS score of 9.8, this vulnerability poses significant risks to the confidentiality, integrity, and availability of the affected system.

Affected products:

  • Hyperion Financial Reporting (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70745

Related in this roundup: CVE-2026-70739, CVE-2026-70740, CVE-2026-70741.

CVE-2026-70817

CVE-2026-70817 is a critical vulnerability in the security component of Oracle Hyperion Financial Management (version 11.2.25.0.000) that allows an unauthenticated attacker to gain full control of the application via network-accessible HTTP requests. Due to the high CVSS base score of 9.8, the vulnerability likely involves an RCE or similar takeover primitive reachable without credentials.

Affected products:

  • Hyperion Financial Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70817

Related in this roundup: CVE-2026-70920, CVE-2026-70921.

CVE-2026-70846

CVE-2026-70846 is a critical vulnerability in the Internal Operations component of Oracle Demand Planning versions 12.1 and 12.2. The flaw is remotely exploitable via HTTP by low-privileged attackers without user interaction. Successful exploitation allows for unauthorized modification, deletion, or access to critical application data, and carries a scope-change impact that may affect other integrated products.

Affected products:

  • Demand Planning (12.1, 12.2)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70846

CVE-2026-70854

CVE-2026-70854 is an easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.25.0.000. It allows an unauthenticated, network-adjacent attacker to perform unauthorized data modification or deletion, and to induce a persistent denial of service (DoS) crash via HTTP requests.

Affected products:

  • Oracle Hyperion Financial Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70854

CVE-2026-70855

CVE-2026-70855 is a critical vulnerability in the Helpdesk/Training component of Oracle Siebel CRM's Self Service product. An unauthenticated attacker with network access can leverage this flaw via HTTP to achieve unauthorized access to, or modification of, critical data. The exploit requires human interaction from a legitimate user and results in a scope change, allowing the attacker to impact additional products within the Siebel ecosystem.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70855

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-70862

CVE-2026-70862 is an unauthenticated, network-exploitable vulnerability in Oracle Application Testing Suite version 13.3.0.1. An attacker can leverage HTTP requests to achieve unauthorized creation, deletion, or modification of critical data within the application, leading to significant impacts on data confidentiality and integrity.

Affected products:

  • Application Testing Suite (13.3.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70862

CVE-2026-70871

CVE-2026-70871 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An unauthenticated attacker with network access via TCP can exploit this flaw to achieve full system takeover. The vulnerability has a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70871

CVE-2026-70872

CVE-2026-70872 is a critical vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to, or modify/delete, critical data within the application. The vulnerability carries a CVSS 3.1 base score of 9.1.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70872

Related in this roundup: CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.

CVE-2026-70873

Oracle Hyperion Data Relationship Management version 11.2.25.0.000 contains a critical vulnerability in the Access and security component. An unauthenticated, network-adjacent attacker can exploit this flaw to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8, indicating severe impacts on confidentiality, integrity, and availability.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70873

Related in this roundup: CVE-2026-70872, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.

CVE-2026-70876

CVE-2026-70876 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An attacker with high-level privileges and network access can exploit this vulnerability via HTTPS to achieve a full takeover of the application. The vulnerability carries a high CVSS score of 9.1 and includes a scope change, meaning exploitation can negatively impact other connected systems.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70876

Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70880, CVE-2026-70883, CVE-2026-70884.

CVE-2026-70880

CVE-2026-70880 is a critical, easily exploitable vulnerability in the Oracle Hyperion Data Relationship Management product's Access and Security component. An unauthenticated attacker with network access via TCP can achieve full system takeover. The vulnerability carries a CVSS base score of 10.0 and impacts the confidentiality, integrity, and availability of the system, with the potential for scope change affecting additional products.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70880

Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70883, CVE-2026-70884.

CVE-2026-70883

CVE-2026-70883 is an easily exploitable, unauthenticated vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management version 11.2.25.0.000. An attacker with network access via HTTP can compromise the application, resulting in unauthorized access to, modification of, or deletion of critical data. The vulnerability carries a CVSS 3.1 base score of 9.1.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70883

Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70884.

CVE-2026-70884

CVE-2026-70884 is a critical vulnerability in Oracle Hyperion Data Relationship Management (version 11.2.25.0.000) affecting the Access and security component. The vulnerability is network-exploitable via SOAP by an unauthenticated attacker, allowing for unauthorized read, modification, or deletion of critical data, resulting in significant confidentiality and integrity impact.

Affected products:

  • Hyperion Data Relationship Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70884

Related in this roundup: CVE-2026-70872, CVE-2026-70873, CVE-2026-70876, CVE-2026-70880, CVE-2026-70883.

CVE-2026-70905

CVE-2026-70905 is a critical vulnerability in the Agent infrastructure component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this via SAML over the network to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70905

Related in this roundup: CVE-2026-60726.

CVE-2026-70920

Oracle Hyperion Financial Management version 11.2.25.0.000 is vulnerable to a critical SQL injection-based flaw in its Security component. A low-privileged attacker with network access can exploit this vulnerability to achieve a full takeover of the application. The vulnerability carries a high CVSS 3.1 score of 9.9, and because of a scope change, successful exploitation may have cascading impacts on other integrated products.

Affected products:

  • Hyperion Financial Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70920

Related in this roundup: CVE-2026-70817, CVE-2026-70921.

CVE-2026-70921

CVE-2026-70921 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management (v11.2.25.0.000). The flaw allows unauthenticated remote attackers to compromise the application over TLS, leading to unauthorized access, modification, or deletion of critical data. Due to its scope-changing nature, the vulnerability poses a high risk to the confidentiality and integrity of all data accessible within the environment.

Affected products:

  • Hyperion Financial Management (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70921

Related in this roundup: CVE-2026-70817, CVE-2026-70920.

CVE-2026-70926

CVE-2026-70926 is a critical vulnerability (CVSS 9.8) in the Oracle Workflow component of Oracle E-Business Suite. The flaw allows an unauthenticated attacker with network access via SMTP to achieve full compromise (takeover) of the Oracle Workflow product. Detection engineers should monitor SMTP traffic patterns to affected Oracle E-Business Suite instances for malformed or unexpected payloads.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70926

Related in this roundup: CVE-2026-60782, CVE-2026-60693, CVE-2026-60748.

CVE-2026-70953

CVE-2026-70953 is a critical vulnerability in the Oracle Commerce Platform's Dynamo Application Framework component (version 11.4.0). The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via TCP, resulting in high impact to confidentiality, integrity, and availability.

Affected products:

  • Oracle Commerce Platform (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70953

Related in this roundup: CVE-2026-70954.

CVE-2026-70954

CVE-2026-70954 is a critical vulnerability in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0. The vulnerability is remotely exploitable without authentication via HTTP, potentially allowing an attacker to achieve full system takeover. Detection engineers should monitor for anomalous HTTP traffic targeting the Dynamo Application Framework or unexpected administrative activity originating from unauthenticated sessions.

Affected products:

  • Oracle Commerce Platform (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70954

Related in this roundup: CVE-2026-70953.

CVE-2026-70958

CVE-2026-70958 is a critical vulnerability in the Oracle Hyperion Infrastructure Technology component 'Installation and Configuration' (version 11.2.25.0.000). The flaw is remotely exploitable via HTTP by an unauthenticated attacker, though it requires human interaction. Successful exploitation results in a full takeover of the affected component and may impact other products due to a scope change, achieving high confidentiality, integrity, and availability impact.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70958

Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-60393.

CVE-2026-70970

CVE-2026-70970 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal. The flaw is remotely exploitable without authentication via HTTP, allowing a threat actor to achieve full system compromise (takeover) of the affected portal instance. It holds a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70970

Related in this roundup: CVE-2026-60728, CVE-2026-60729, CVE-2026-60731, CVE-2026-60733.

CVE-2026-70976

CVE-2026-70976 is an unauthenticated, network-exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an attacker to gain unauthorized access to modify or delete critical data and cause a denial-of-service (DoS) condition via repeatable crashes, impacting data integrity and service availability.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70976

Related in this roundup: CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70977

CVE-2026-70977 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized modification or deletion of critical data, as well as trigger a complete denial-of-service condition via HTTP requests. The vulnerability is considered easily exploitable with no user interaction required.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70977

Related in this roundup: CVE-2026-70976, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70978

CVE-2026-70978 is a critical, easily exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.4.0). An unauthenticated attacker with network access can leverage this flaw via HTTP to achieve unauthorized access to, or modification/deletion of, critical data.

Affected products:

  • Oracle Commerce Guided Search
  • Oracle Commerce Experience Manager

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70978

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70979

CVE-2026-70979 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is easily exploitable by an unauthenticated attacker over HTTP, allowing for unauthorized modification or deletion of critical data, as well as the ability to cause a denial-of-service (DoS) condition.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70979

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70980

CVE-2026-70980 is a high-severity, remotely exploitable vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated attacker with network access via HTTP to achieve full compromise of the application with a high impact on confidentiality, integrity, and availability, and it is capable of causing a scope change impacting additional products.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70980

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70981

An unauthenticated remote attacker can exploit a vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search / Experience Manager version 11.4.0 via HTTP. Successful exploitation allows for unauthorized modification, deletion, or creation of critical data, as well as the ability to cause a complete denial-of-service (DoS) condition.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70981

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70984

CVE-2026-70984 is a critical vulnerability in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized manipulation of critical data and causing a complete denial-of-service (DoS) condition.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70984

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70994

CVE-2026-70994 is a vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data and cause a denial-of-service condition through an HTTP-based attack vector.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70994

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70995

CVE-2026-70995 describes a critical, easily exploitable vulnerability within the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated attacker with network access via HTTP to fully compromise the target application, resulting in a complete takeover of confidentiality, integrity, and availability (CVSS 9.8).

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70995

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70997

CVE-2026-70997 is a critical vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data and cause a denial-of-service (DoS) condition via crafted HTTP requests. The vulnerability is highly exploitable, requiring no authentication or user interaction.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70997

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-70998

CVE-2026-70998 is a critical, unauthenticated remote vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. An attacker with network access can exploit this flaw over HTTP to achieve unauthorized access, modification, or deletion of critical data, with a scope change impact that may affect other products.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70998

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-71014

CVE-2026-71014 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Experience Manager version 11.4.0. The vulnerability allows an unauthenticated attacker with network access via HTTP to gain unauthorized read/write access to critical data. This flaw is remotely exploitable without user interaction.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71014

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-71015

CVE-2026-71015 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized read and write access to critical application data.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71015

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71026, CVE-2026-71036, CVE-2026-71037.

CVE-2026-71026

CVE-2026-71026 is a critical vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The flaw allows an unauthenticated remote attacker with network access via HTTP to perform unauthorized modification, deletion, or disclosure of critical system data.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71026

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71036, CVE-2026-71037.

CVE-2026-71036

CVE-2026-71036 is an easily exploitable, unauthenticated remote access vulnerability in Oracle Commerce Guided Search and Experience Manager version 11.4.0. The vulnerability allows an attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information within the application.

Affected products:

  • Oracle Commerce Guided Search (11.4.0)
  • Oracle Commerce Experience Manager (11.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71036

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71037.

CVE-2026-71037

CVE-2026-71037 is a critical vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.4.0) that allows an unauthenticated, remote attacker to compromise the system via HTTP. The vulnerability requires user interaction and facilitates unauthorized access to, modification of, or deletion of critical data, representing a significant scope change impact.

Affected products:

  • Oracle Commerce Guided Search
  • Oracle Commerce Experience Manager

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71037

Related in this roundup: CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70984, CVE-2026-70994, CVE-2026-70995, CVE-2026-70997, CVE-2026-70998, CVE-2026-71014, CVE-2026-71015, CVE-2026-71026, CVE-2026-71036.

CVE-2026-71040

CVE-2026-71040 is a critical vulnerability in the Security component of Oracle Agile PLM version 9.3.6. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via crafted HTTP requests. Due to the high CVSS score of 9.8 and the ease of exploitation, this represents a significant risk for complete compromise of the product's confidentiality, integrity, and availability.

Affected products:

  • Agile PLM (9.3.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71040

CVE-2026-71059

CVE-2026-71059 is a critical vulnerability in the Oracle BI Publisher component of Oracle Analytics. A low-privileged attacker with network access can exploit the Web Service API via SOAP to achieve full takeover of the affected product. The vulnerability has a CVSS base score of 9.9 and involves a scope change, potentially impacting additional products within the environment.

Affected products:

  • BI Publisher (8.2.0.0.0, 26.1.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71059

CVE-2026-71063

A critical vulnerability exists in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated attacker with physical network segment access to achieve a full system compromise. The vulnerability is characterized by a CVSS 3.1 score of 9.6 with a scope change, indicating that successful exploitation can impact broader system integrity and availability beyond the clusterware itself.

Affected products:

  • Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71063

Related in this roundup: CVE-2026-71064, CVE-2026-71102.

CVE-2026-71064

CVE-2026-71064 is a critical vulnerability in the Portable Clusterware component of Oracle Database Server. The flaw allows an unauthenticated attacker with access to the physical network segment where the component resides to achieve a full compromise of the service. Due to its impact on Confidentiality, Integrity, and Availability, and its potential for scope change affecting additional products, it is rated with a CVSS score of 9.6.

Affected products:

  • Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71064

Related in this roundup: CVE-2026-71063, CVE-2026-71102.

CVE-2026-71065

CVE-2026-71065 is a critical vulnerability affecting the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows unauthenticated remote attackers with network access to compromise the application via HTTP requests. Due to a scope change, successful exploitation enables unauthorized access, modification, or deletion of critical data, resulting in a CVSS 3.1 score of 9.3.

Affected products:

  • Helidon (3.2.18)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71065

Related in this roundup: CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-71074

CVE-2026-71074 is a critical vulnerability (CVSS 9.8) in the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated, network-adjacent attacker to achieve a complete takeover of the Helidon instance via crafted HTTP requests.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71074

CVE-2026-71102

CVE-2026-71102 is a critical vulnerability in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated, network-adjacent attacker to perform unauthorized data modifications and trigger a denial-of-service condition via HTTP. The vulnerability is highly exploitable, requiring no privileges or user interaction, impacting both system integrity and availability.

Affected products:

  • Database Server (19.3-19.32, 21.3-21.23, 23.4.0-23.26.3)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71102

Related in this roundup: CVE-2026-71063, CVE-2026-71064.

CVE-2026-71152

CVE-2026-71152 is a critical RCE vulnerability in the Imperative Web Server component of Oracle Helidon version 4.5.0. An unauthenticated attacker can exploit this via HTTP network access to achieve a full takeover of the Helidon instance, impacting confidentiality, integrity, and availability.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71152

Related in this roundup: CVE-2026-71065, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-71164

CVE-2026-71164 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated attacker to execute a remote takeover of the Helidon server via network-accessible HTTP requests, resulting in full impact on confidentiality, integrity, and availability.

Affected products:

  • Helidon (3.2.18)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71164

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-71166

CVE-2026-71166 is a critical vulnerability in the Oracle Fusion Middleware Helidon component (Imperative Web Server), specifically affecting version 3.2.18. The vulnerability is network-exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized data manipulation, unauthorized access to critical data, and partial denial-of-service conditions.

Affected products:

  • Helidon (3.2.18)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71166

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-71167

CVE-2026-71167 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon 4.5.0. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to or modify critical data, and trigger a partial denial of service. The vulnerability impacts the confidentiality, integrity, and availability of the system.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71167

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73865

CVE-2026-73865 is a critical vulnerability within the Imperative Web Server component of Oracle Helidon version 3.2.18. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, modification, or deletion of critical data via HTTP requests, posing a high risk to data confidentiality and integrity.

Affected products:

  • Helidon (3.2.18)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73865

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73866

CVE-2026-73866 is a critical vulnerability affecting the Imperative Web Server component of Oracle Helidon version 4.5.0. The flaw is remotely exploitable by an unauthenticated attacker over HTTP without user interaction, allowing for unauthorized read, modification, or deletion of critical data accessible by the application.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73866

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73905

CVE-2026-73905 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw allows an unauthenticated attacker to remotely compromise the application via network-accessible HTTP requests, potentially leading to a full takeover of the Helidon instance.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73905

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73912

CVE-2026-73912 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw is remotely exploitable without authentication, allowing an attacker to achieve full system takeover via standard HTTP requests. Given the CVSS 3.1 score of 9.8, this represents a significant risk to the availability, integrity, and confidentiality of the affected service.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73912

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73916

CVE-2026-73916 is a critical vulnerability in the Oracle Fusion Middleware Helidon component, specifically the Imperative Web Server. An unauthenticated attacker with network access can exploit this via HTTP to gain unauthorized access to or modify critical data. The vulnerability is remotely exploitable without authentication, resulting in high confidentiality and integrity impacts.

Affected products:

  • Helidon (3.2.18)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73916

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73917

CVE-2026-73917 is a high-severity vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 4.5.0). The flaw allows an unauthenticated remote attacker with network access to perform unauthorized creation, deletion, or modification of critical data. The vulnerability has a CVSS 3.1 base score of 9.1 and directly impacts both data confidentiality and integrity via HTTP-based exploitation.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73917

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73920

CVE-2026-73920 is a critical vulnerability in the Oracle Helidon Imperative Web Server (version 4.5.0) that allows an unauthenticated remote attacker to compromise the application via HTTP. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, as well as a partial denial-of-service condition.

Affected products:

  • Helidon (4.5.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73920

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73921

CVE-2026-73921 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework, affecting version 1.4.20. An unauthenticated attacker with network access can exploit this flaw via HTTP to achieve full takeover of the Helidon instance, impacting confidentiality, integrity, and availability. The vulnerability is rated with a CVSS 3.1 base score of 9.8.

Affected products:

  • Helidon (1.4.20)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73921

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73922, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73922

CVE-2026-73922 is a critical vulnerability in the Imperative Web Server component of Oracle's Helidon framework (version 1.4.19). An unauthenticated remote attacker can exploit this via HTTP to gain unauthorized access to or perform unauthorized modifications of critical data, resulting in a CVSS score of 9.1.

Affected products:

  • Helidon (1.4.19)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73922

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73924, CVE-2026-73930.

CVE-2026-73924

CVE-2026-73924 is a critical vulnerability in the Imperative Web Server component of Oracle Helidon version 1.4.19. The flaw allows an unauthenticated remote attacker to gain unauthorized access to or perform unauthorized modifications of critical data via network-based HTTP requests.

Affected products:

  • Helidon (1.4.19)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73924

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73930.

CVE-2026-73930

CVE-2026-73930 is a critical vulnerability in the Helidon component of Oracle Fusion Middleware. An unauthenticated attacker with network access can exploit the Imperative Web Server via HTTP to perform unauthorized modification, deletion, or creation of critical data, as well as unauthorized data reading and partial denial-of-service, with a CVSS base score of 9.9 and scope change.

Affected products:

  • Helidon (4.5.3)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73930

Related in this roundup: CVE-2026-71065, CVE-2026-71152, CVE-2026-71164, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73905, CVE-2026-73912, CVE-2026-73916, CVE-2026-73917, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73924.

CVE-2026-60391

CVE-2026-60391 is a critical vulnerability in the Server component of Oracle Hyperion Financial Reporting version 11.2.25.0.000. The flaw allows an unauthenticated remote attacker to gain unauthorized access to critical data through the network via HTTP, resulting in significant confidentiality impact.

Affected products:

  • Oracle Hyperion Financial Reporting (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60391

CVE-2026-60392

Oracle Outside In Technology, specifically the PDF Export SDK version 8.5.8, is vulnerable to a flaw that allows an unauthenticated attacker with local access to compromise the product. Successful exploitation requires user interaction and can lead to a full takeover of the technology, impacting confidentiality, integrity, and availability.

Affected products:

  • Outside In Technology (8.5.8)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60392

Related in this roundup: CVE-2026-60412, CVE-2026-60413.

CVE-2026-60393

CVE-2026-60393 is a vulnerability in the Oracle Hyperion Infrastructure Technology Lifecycle Management component. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, allowing for unauthorized access to sensitive or critical data. The flaw has a CVSS 3.1 base score of 7.5, reflecting a significant impact on data confidentiality.

Affected products:

  • Hyperion Infrastructure Technology (11.2.25.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60393

Related in this roundup: CVE-2026-62457, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-70958.

CVE-2026-60412

CVE-2026-60412 is a vulnerability in the Oracle Outside In Core component of Oracle Fusion Middleware version 8.5.8. An unauthenticated attacker can exploit this vulnerability with local access and human interaction to take over the component, resulting in full impact on confidentiality, integrity, and availability.

Affected products:

  • Outside In Technology (8.5.8)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60412

Related in this roundup: CVE-2026-60392, CVE-2026-60413.

CVE-2026-60413

Oracle Outside In Technology 8.5.8 contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to the infrastructure to compromise the application. The attack requires user interaction and can result in a full takeover of the Oracle Outside In Technology component.

Affected products:

  • Outside In Technology (8.5.8)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60413

Related in this roundup: CVE-2026-60392, CVE-2026-60412.

CVE-2026-60414

CVE-2026-60414 is a critical vulnerability in Oracle Outside In Technology within Oracle Fusion Middleware, specifically version 8.5.8. An unauthenticated attacker with local access to the infrastructure can compromise the component, though the attack requires human interaction. Successful exploitation can lead to a complete takeover of the Outside In Technology component, resulting in significant impacts to confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware (8.5.8)
  • Outside In Technology (8.5.8)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60414

Related in this roundup: CVE-2026-62608, CVE-2026-62610, CVE-2026-62621, CVE-2026-62622, CVE-2026-62624.

CVE-2026-60415

Oracle WebLogic Server contains a vulnerability in the Core component that allows an unauthenticated attacker with network access via T3 or IIOP protocols to achieve full compromise of the server. The vulnerability is difficult to exploit but results in high impacts to confidentiality, integrity, and availability.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60415

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60679, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60590

CVE-2026-60590 is an unauthenticated, network-accessible vulnerability in the Oracle Hospitality Simphony POS component. An attacker can exploit this via HTTP to gain unauthorized access to critical data or achieve full access to data managed by the system. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant potential for unauthorized information disclosure.

Affected products:

  • Hospitality Simphony (19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60590

Related in this roundup: CVE-2026-60591.

CVE-2026-60592

CVE-2026-60592 is a vulnerability in the NDB Operator component of Oracle MySQL Cluster that allows unauthenticated, network-adjacent attackers to impact service availability and data integrity. Successful exploitation permits the attacker to trigger a denial-of-service (hang or crash) and perform unauthorized data modifications, including unauthorized updates, inserts, or deletions within the cluster.

Affected products:

  • MySQL Cluster (8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60592

CVE-2026-60679

CVE-2026-60679 is a vulnerability in the Core component of Oracle WebLogic Server that allows a low-privileged attacker to achieve a full system takeover via network access using the T3 or IIOP protocols. The vulnerability is characterized as difficult to exploit but carries a high impact on the confidentiality, integrity, and availability of the affected server.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60679

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60680, CVE-2026-60699.

CVE-2026-60680

Oracle WebLogic Server contains a vulnerability in the Core component that allows a low-privileged, network-adjacent attacker to perform unauthorized data manipulation (creation, deletion, or modification) and trigger a denial-of-service (hang or crash) via HTTP. The vulnerability is highly exploitable due to low attack complexity and does not require user interaction, impacting both data integrity and service availability.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60680

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60699.

CVE-2026-60693

CVE-2026-60693 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application, resulting in unauthorized access, modification, or deletion of critical data, as well as the ability to cause a partial denial of service (DoS).

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60693

Related in this roundup: CVE-2026-60782, CVE-2026-70926, CVE-2026-60748.

CVE-2026-60699

CVE-2026-60699 is a critical vulnerability in the Oracle WebLogic Server Core component that allows unauthenticated attackers to gain unauthorized access to data via T3 or IIOP network protocols. Due to the scope change vector, successful exploitation can result in significant impacts across integrated systems, with a CVSS base score of 8.6 targeting data confidentiality.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60699

Related in this roundup: CVE-2026-60672, CVE-2026-60696, CVE-2026-60698, CVE-2026-60702, CVE-2026-60977, CVE-2026-60415, CVE-2026-60679, CVE-2026-60680.

CVE-2026-60707

Oracle Identity Manager in Oracle Fusion Middleware contains a vulnerability that allows a high-privileged attacker with network access via HTTP to compromise the application. The vulnerability has a scope change (S:C) and enables unauthorized modification, deletion, or access to critical data, leading to significant impact on the affected instance and potentially additional integrated products.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60707

Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60715, CVE-2026-60716, CVE-2026-60722.

CVE-2026-60715

A critical vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is remotely exploitable over HTTP by an attacker with low privileges, potentially leading to a full takeover of the Identity Manager application.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60715

Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60716, CVE-2026-60722.

CVE-2026-60716

CVE-2026-60716 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager within Oracle Fusion Middleware. A low-privileged attacker with network access via T3 or IIOP protocols can successfully exploit this flaw to gain full control (takeover) of the Oracle Identity Manager instance. The vulnerability carries a CVSS base score of 8.8, reflecting significant impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60716

Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60722.

CVE-2026-60722

CVE-2026-60722 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager. An attacker with low-level privileges can leverage network access via T3 or IIOP protocols to achieve full system takeover. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 and carries a CVSS base score of 8.8, posing a high risk to the confidentiality, integrity, and availability of the identity management environment.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60722

Related in this roundup: CVE-2026-60720, CVE-2026-60721, CVE-2026-61066, CVE-2026-60707, CVE-2026-60715, CVE-2026-60716.

CVE-2026-60726

Oracle Access Manager (OAM) component of Oracle Fusion Middleware is vulnerable to a flaw in its Authentication Engine. A low-privileged attacker with network access can exploit this via HTTP to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60726

Related in this roundup: CVE-2026-70905.

CVE-2026-60729

A vulnerability in the Composer component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged network attacker to achieve a full takeover of the application via HTTP. The flaw carries a CVSS 3.1 score of 8.8 and impacts confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60729

Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60731, CVE-2026-60733.

CVE-2026-60731

CVE-2026-60731 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is remotely exploitable via RMI by a low-privileged attacker, potentially resulting in a complete takeover of the affected application. It carries a CVSS score of 8.8, reflecting high impact on confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60731

Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60729, CVE-2026-60733.

CVE-2026-60733

Oracle WebCenter Portal, a component of Oracle Fusion Middleware, contains a vulnerability in its Composer feature that allows a low-privileged network attacker to compromise the system. Exploitation can lead to unauthorized data access, unauthorized modification or deletion of critical data, and partial denial of service. The vulnerability supports scope change and is exploitable via HTTP.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60733

Related in this roundup: CVE-2026-60728, CVE-2026-70970, CVE-2026-60729, CVE-2026-60731.

CVE-2026-60742

CVE-2026-60742 is a critical vulnerability in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw allows an unauthenticated attacker with network access via HTTP to potentially take over the PeopleTools environment. Despite the difficulty of exploitation (AC:H), the vulnerability carries a CVSS base score of 8.1, impacting confidentiality, integrity, and availability.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60742

Related in this roundup: CVE-2026-60821.

CVE-2026-60748

CVE-2026-60748 is a high-severity vulnerability within the Internal Operations component of Oracle General Ledger in Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker with high privileges can exploit this flaw over HTTP to achieve unauthorized access to, or modification of, critical data. The vulnerability supports scope changes, meaning successful exploitation can compromise data beyond the General Ledger component.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60748

Related in this roundup: CVE-2026-60782, CVE-2026-70926, CVE-2026-60693.

CVE-2026-60751

CVE-2026-60751 is a vulnerability in the Marketing component of Oracle Siebel CRM versions 17.0 through 26.6. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60751

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60752

CVE-2026-60752 is a vulnerability in the Marketing component of Oracle Siebel CRM versions 17.0 through 26.6. The vulnerability is network-accessible via HTTP and allows a low-privileged attacker to achieve unauthorized access to critical data and cause a partial denial of service. The vulnerability impacts confidentiality and availability.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60752

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60753

CVE-2026-60753 is a vulnerability in the Installation component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. The flaw allows a low-privileged authenticated attacker with local access to the infrastructure to escalate privileges and perform a full takeover of the Siebel CRM Deployment product.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60753

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60757

CVE-2026-60757 is a vulnerability in the Search component of Oracle Siebel CRM, specifically affecting versions 17.0 through 26.6. The flaw allows an unauthenticated attacker with access to the local physical communication segment to perform unauthorized data modification, deletion, or access to critical system information. The vulnerability is characterized by high confidentiality and integrity impact, requiring proximity to the target hardware.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60757

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60758

CVE-2026-60758 is a high-severity vulnerability in the Oracle Siebel CRM AI component. A low-privileged attacker with network access can exploit this via HTTP to gain unauthorized access to data, including the ability to update, insert, or delete information. The vulnerability exhibits a changed scope, meaning successful exploitation can impact secondary products beyond just the Siebel AI component.

Affected products:

  • Siebel CRM (25.12-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60758

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60765, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60759

Oracle Internet Procurement Connector in Oracle E-Business Suite versions 12.2.3 through 12.2.15 contains an unauthenticated vulnerability accessible via HTTP. The vulnerability allows a remote attacker to achieve unauthorized access to, or modification of, critical data within the component. Due to the high impact on confidentiality and integrity, patching or applying vendor-supplied mitigation is critical for affected deployments.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60759

CVE-2026-60765

CVE-2026-60765 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, allowing a low-privileged attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability is difficult to exploit but carries high impact across confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60765

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60766, CVE-2026-60767.

CVE-2026-60766

A vulnerability in the REST component of Oracle Siebel CRM allows an unauthenticated remote attacker with network access to compromise the Siebel CRM Integration service via HTTPS. Exploitation results in unauthorized read, write, or deletion access to critical data managed by the integration layer.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60766

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60767.

CVE-2026-60767

CVE-2026-60767 is a critical vulnerability in the Marketing component of Oracle Siebel CRM, affecting versions 17.0 through 26.6. A low-privileged attacker with network access can exploit this via HTTP to achieve full takeover of the application. The vulnerability has a CVSS base score of 8.8, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Siebel CRM (17.0-26.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60767

Related in this roundup: CVE-2026-60754, CVE-2026-61318, CVE-2026-62585, CVE-2026-62588, CVE-2026-62592, CVE-2026-70855, CVE-2026-60751, CVE-2026-60752, CVE-2026-60753, CVE-2026-60757, CVE-2026-60758, CVE-2026-60765, CVE-2026-60766.

CVE-2026-60769

CVE-2026-60769 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw allows a low-privileged attacker with network access via HTTP to perform a full takeover of the Oracle General Ledger application. Exploitation requires high complexity but results in significant impacts to confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-60769