Skip to content
Threat Feed
high threat

Oracle Security Updates - September 2026

Roundup of Oracle security advisories published in September 2026.

CVE search metadata

CVE search record: CVE-2026-70748. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-70756. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-70757. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-70913. Severity: critical. CVSS: 9.8. KEV: no. Product: Identity Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-71133. Severity: critical. CVSS: 10.0. KEV: no. Product: Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-71163. Severity: critical. CVSS: 9.9. KEV: no. Product: Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73940. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73944. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73945. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73946. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73947. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73948. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73950. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73952. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73953. Severity: critical. CVSS: 9.8. KEV: no. Product: WebCenter Portal (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73956. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73957. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73961. Severity: critical. CVSS: 9.8. KEV: no. Product: JDeveloper (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73962. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73963. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82994. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82995. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82997. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82998. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82999. Severity: critical. CVSS: 9.9. KEV: no. Product: Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83000. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83001. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83006. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83020. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83021. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83027. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83029. Severity: critical. CVSS: 9.6. KEV: no. Product: Managed File Transfer (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83031. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83035. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83036. Severity: critical. CVSS: 9.8. KEV: no. Product: WebCenter Sites (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83037. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83038. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83039. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83040. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83042. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83043. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83054. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83055. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83056. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83057. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83058. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83059. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83060. Severity: critical. CVSS: 9.8. KEV: no. Product: Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83061. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83062. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83064. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83066. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83094. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83095. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83098. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83099. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83100. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83103. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83104. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83105. Severity: critical. CVSS: 9.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83107. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83108. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83149. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83151. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83154. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83196. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83197. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83201. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83202. Severity: critical. CVSS: 9.1. KEV: no. Product: Siebel CRM (17.0-26.7). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83229. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83232. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83260. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83261. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83268. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83269. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83282. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83283. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83327. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83339. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83355. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83452. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83462. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87128. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87129. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87170. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87173. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87175. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87184. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87186. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87188. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87189. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87214. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87217. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-87223. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-70915. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73926. Severity: high. CVSS: 8.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73941. Severity: high. CVSS: 8.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73942. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73943. Severity: high. CVSS: 7.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73949. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73951. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73954. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73955. Severity: high. CVSS: 7.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-73966. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82992. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82993. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-82996. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83002. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83004. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83005. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83007. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83008. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83009. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83010. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83012. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83014. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83016. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83019. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83024. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83026. Severity: high. CVSS: 8.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83028. Severity: high. CVSS: 7.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83034. Severity: high. CVSS: 7.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83045. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83048. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83049. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83050. Severity: high. CVSS: 7.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83052. Severity: high. CVSS: 7.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83053. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83068. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83070. Severity: high. CVSS: 7.7. KEV: no. Product: PeopleSoft Enterprise PRTL Interaction Hub (9.1). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83072. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83074. Severity: high. CVSS: 8.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83101. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83112. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

CVE search record: CVE-2026-83113. Severity: high. CVSS: 7.1. KEV: no. Product: Oracle E-Business Suite (12.2.3-12.2.15). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/

What's new

  • 1. added CVE-2026-83052 +2 Sep 15, 23:49 via nvd
  • 2. added CVE-2026-83012 +1 Sep 15, 23:49 via nvd
  • 3. added CVE-2026-83049 +2 Sep 15, 23:49 via nvd
  • 4. added CVE-2026-83113 Sep 15, 23:49 via nvd
  • 5. added CVE-2026-83034 Sep 15, 23:48 via nvd

This roundup covers 191 Oracle security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Agile PLM, Application Testing Suite, BI Publisher, Database Server, E-Business Suite, Forms Services, Fusion Middleware, Hyperion Data Relationship Management, Hyperion Financial Management, Identity Manager, Identity Manager Connector, Internet Directory, JDeveloper, Managed File Transfer, Oracle Access Manager, Oracle BI Publisher, Oracle Banking Branch, Oracle Banking Corporate Lending, Oracle Business Intelligence Enterprise Edition, Oracle Data Integrator, Oracle E-Business Suite, Oracle Enterprise Manager for Oracle Database, Oracle Field Service, Oracle Forms, Oracle Fusion Middleware, Oracle Fusion Middleware Control, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle Platform Security for Java, Oracle WebCenter Portal, PeopleSoft Enterprise PRTL Interaction Hub, PeopleSoft Enterprise PeopleTools, Service Delivery Platform, Siebel CRM, Siebel CRM Cloud Applications, Siebel CRM Deployment, WebCenter Enterprise Capture, WebCenter Portal, WebCenter Sites, WebLogic Server.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-70748WebLogic ServerCritical9.8noNVD (authoritative)
CVE-2026-70756WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.8noNVD (authoritative)
CVE-2026-70757WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.8noNVD (authoritative)
CVE-2026-70913Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-71133Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical10.0noNVD (authoritative)
CVE-2026-71163Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-73940Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-73944Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.1noNVD (authoritative)
CVE-2026-73945n/aCritical9.9noNVD (authoritative)
CVE-2026-73946Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.1noNVD (authoritative)
CVE-2026-73947Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-73948WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-73950Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-73952WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-73953WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-73956WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-73957n/aCritical9.3noNVD (authoritative)
CVE-2026-73961JDeveloper (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-73962Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.6noNVD (authoritative)
CVE-2026-73963n/aCritical9.8noNVD (authoritative)
CVE-2026-82994n/aCritical9.8noNVD (authoritative)
CVE-2026-82995n/aCritical9.8noNVD (authoritative)
CVE-2026-82997Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-82998Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-82999Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-83000Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83001Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.1noNVD (authoritative)
CVE-2026-83006WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-83020Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)Critical10.0noNVD (authoritative)
CVE-2026-83021WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)Critical10.0noNVD (authoritative)
CVE-2026-83027Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)Critical9.3noNVD (authoritative)
CVE-2026-83029Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)Critical9.6noNVD (authoritative)
CVE-2026-83031WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-83035WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83036WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83037WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83038WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)Critical9.9noNVD (authoritative)
CVE-2026-83039WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)Critical9.9noNVD (authoritative)
CVE-2026-83040n/aCritical9.6noNVD (authoritative)
CVE-2026-83042Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83043n/aCritical9.6noNVD (authoritative)
CVE-2026-83054Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83055n/aCritical9.9noNVD (authoritative)
CVE-2026-83056Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-83057Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.9noNVD (authoritative)
CVE-2026-83058n/aCritical9.9noNVD (authoritative)
CVE-2026-83059Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical10.0noNVD (authoritative)
CVE-2026-83060Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83061Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83062Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83064n/aCritical9.1noNVD (authoritative)
CVE-2026-83066Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)Critical9.8noNVD (authoritative)
CVE-2026-83094Oracle Forms (12.2.1.19.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83095n/aCritical9.8noNVD (authoritative)
CVE-2026-83098n/aCritical9.8noNVD (authoritative)
CVE-2026-83099Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)Critical10.0noNVD (authoritative)
CVE-2026-83100Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83103Forms Services (12.2.1.19.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-83104Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)Critical9.1noNVD (authoritative)
CVE-2026-83105n/aCritical9.0noNVD (authoritative)
CVE-2026-83107Oracle Fusion MiddlewareCritical9.1noNVD (authoritative)
CVE-2026-83108Oracle Fusion MiddlewareCritical9.8noNVD (authoritative)
CVE-2026-83149Application Testing Suite (13.3.0.1)Critical9.1noNVD (authoritative)
CVE-2026-83151Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83154Siebel CRM (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83196Siebel CRM Deployment (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83197Siebel CRM (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83201Siebel CRM (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83202Siebel CRM (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83229Siebel CRM (17.0-26.7)Critical9.1noNVD (authoritative)
CVE-2026-83232Oracle Data Integrator (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83260Agile PLM (9.3.6)Critical9.1noNVD (authoritative)
CVE-2026-83261n/aCritical9.8noNVD (authoritative)
CVE-2026-83268BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)Critical9.1noNVD (authoritative)
CVE-2026-83269Oracle BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83282Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)Critical9.9noNVD (authoritative)
CVE-2026-83283Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)Critical9.8noNVD (authoritative)
CVE-2026-83327E-Business Suite (12.2.3-12.2.15)Critical9.8noNVD (authoritative)
CVE-2026-83339WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)Critical9.8noNVD (authoritative)
CVE-2026-83355n/aCritical9.8noNVD (authoritative)
CVE-2026-83452Oracle E-Business Suite (12.2.3-12.2.15)Critical9.8noNVD (authoritative)
CVE-2026-83462E-Business Suite (12.2.3-12.2.15)Critical9.8noNVD (authoritative)
CVE-2026-87128Hyperion Data Relationship Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87129Hyperion Data Relationship Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87170Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87172Hyperion Financial Management (11.2.26.0.000)noNVD (authoritative)
CVE-2026-87173Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87175Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87176Hyperion Financial Management (11.2.26.0.000)noNVD (authoritative)
CVE-2026-87184Hyperion Financial Management (11.2.26.0.000)Critical9.8noNVD (authoritative)
CVE-2026-87186Hyperion Financial Management (11.2.26.0.000)Critical9.6noNVD (authoritative)
CVE-2026-87188Hyperion Financial Management (11.2.26.0.000)Critical9.8noNVD (authoritative)
CVE-2026-87189Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87214Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87217Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87223Hyperion Financial Management (11.2.26.0.000)Critical9.1noNVD (authoritative)
CVE-2026-87230Hyperion Financial Management (11.2.26.0.000)noNVD (authoritative)
CVE-2026-70915Identity Manager (12.2.1.4.0, 14.1.2.1.0)High8.8noNVD (authoritative)
CVE-2026-71047Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-73926Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)High8.7noNVD (authoritative)
CVE-2026-73941n/aHigh8.6noNVD (authoritative)
CVE-2026-73942Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)High8.8noNVD (authoritative)
CVE-2026-73943Identity Manager (12.2.1.4.0, 14.1.2.1.0)High7.6noNVD (authoritative)
CVE-2026-73949n/aHigh8.8noNVD (authoritative)
CVE-2026-73951WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High8.1noNVD (authoritative)
CVE-2026-73954PeopleSoft Enterprise PeopleTools (8.61-8.63)High8.1noNVD (authoritative)
CVE-2026-73955n/aHigh7.3noNVD (authoritative)
CVE-2026-73958Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-73959Oracle WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-73960PeopleSoft Enterprise PeopleTools (8.61-8.63)noNVD (authoritative)
CVE-2026-73966Siebel CRM (17.0-26.7)High7.2noNVD (authoritative)
CVE-2026-82992Siebel CRM (17.0-26.7)High7.8noNVD (authoritative)
CVE-2026-82993PeopleSoft Enterprise PeopleTools (8.61-8.63)High8.5noNVD (authoritative)
CVE-2026-82996n/aHigh7.8noNVD (authoritative)
CVE-2026-83002Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)High8.5noNVD (authoritative)
CVE-2026-83003n/anoNVD (authoritative)
CVE-2026-83004WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High7.2noNVD (authoritative)
CVE-2026-83005WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High8.8noNVD (authoritative)
CVE-2026-83007WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High8.5noNVD (authoritative)
CVE-2026-83008WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High8.8noNVD (authoritative)
CVE-2026-83009WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High8.8noNVD (authoritative)
CVE-2026-83010WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High8.1noNVD (authoritative)
CVE-2026-83011Oracle Platform Security for Java (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83012WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)High7.7noNVD (authoritative)
CVE-2026-83013WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83014PeopleSoft Enterprise PeopleTools (8.61-8.63)High8.1noNVD (authoritative)
CVE-2026-83015PeopleSoft Enterprise PeopleTools (8.61-8.63)noNVD (authoritative)
CVE-2026-83016PeopleSoft Enterprise PeopleTools (8.61-8.63)High7.2noNVD (authoritative)
CVE-2026-83017PeopleSoft Enterprise PeopleTools (8.61-8.63)noNVD (authoritative)
CVE-2026-83018n/anoNVD (authoritative)
CVE-2026-83019PeopleSoft Enterprise PeopleTools (8.61-8.63)High8.1noNVD (authoritative)
CVE-2026-83022WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83023Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-83024n/aHigh7.8noNVD (authoritative)
CVE-2026-83025Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-83026Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)High8.3noNVD (authoritative)
CVE-2026-83028Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)High7.5noNVD (authoritative)
CVE-2026-83030Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83032WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83033WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83034WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)High7.5noNVD (authoritative)
CVE-2026-83041WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83044E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83045WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High8.5noNVD (authoritative)
CVE-2026-83046WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83047WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83048WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High7.7noNVD (authoritative)
CVE-2026-83049WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High8.5noNVD (authoritative)
CVE-2026-83050WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High7.1noNVD (authoritative)
CVE-2026-83051WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83052WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83053WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)High8.8noNVD (authoritative)
CVE-2026-83063Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)noNVD (authoritative)
CVE-2026-83065Oracle WebCenter Portal (14.1.2.0.0)noNVD (authoritative)
CVE-2026-83067JDeveloper (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83068Oracle Enterprise Manager for Oracle Database (24.1)noNVD (authoritative)
CVE-2026-83069Oracle Fusion Middleware Control (12.2.1.4.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83070PeopleSoft Enterprise PRTL Interaction Hub (9.1)High7.7noNVD (authoritative)
CVE-2026-83071Oracle Business Intelligence Enterprise Edition (8.2.0.0.0, 26.01.0.0.0)noNVD (authoritative)
CVE-2026-83072E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83073Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83074Siebel CRM Cloud Applications (22.3-26.7)High8.6noNVD (authoritative)
CVE-2026-83075Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83078Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83079Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83080Oracle Banking Branch (14.5.0.0.0-14.9.0.0.0)noNVD (authoritative)
CVE-2026-83081Oracle Banking Corporate Lending (14.5.0.0.0-14.9.0.0.0)noNVD (authoritative)
CVE-2026-83082Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83083E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83084E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83085Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83086n/anoNVD (authoritative)
CVE-2026-83087Siebel CRM Cloud Applications (22.3-26.7)noNVD (authoritative)
CVE-2026-83088Database Server (23.4.0-23.26.3)noNVD (authoritative)
CVE-2026-83089Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83090E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83091Oracle Field Service (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83092Oracle Field Service (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83093n/anoNVD (authoritative)
CVE-2026-83096Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83101Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)High8.1noNVD (authoritative)
CVE-2026-83102Oracle Forms (12.2.1.19.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83106Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)noNVD (authoritative)
CVE-2026-83110E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83111Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83112Oracle E-Business Suite (12.2.7-12.2.15)High7.2noNVD (authoritative)
CVE-2026-83113Oracle E-Business Suite (12.2.3-12.2.15)High7.1noNVD (authoritative)
CVE-2026-83114Oracle E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83115E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)
CVE-2026-83116Oracle E-Business Suite (12.2.5-12.2.15)noNVD (authoritative)
CVE-2026-83117E-Business Suite (12.2.3-12.2.15)noNVD (authoritative)

CVE-2026-70748

Oracle WebLogic Server, specifically within the Core component, is vulnerable to an unauthenticated remote code execution exploit via T3 or IIOP protocols. Attackers can leverage this vulnerability to gain complete control over the affected server. The vulnerability is network-exploitable with low attack complexity, carrying a CVSS base score of 9.8.

Affected products:

  • WebLogic Server

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70748

Related in this roundup: CVE-2026-70756, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038.

CVE-2026-70756

CVE-2026-70756 is a critical vulnerability in the Core component of Oracle WebLogic Server. It allows an unauthenticated attacker with network access to exploit the T3 or IIOP protocols to achieve a full takeover of the server. With a CVSS score of 9.8, this flaw impacts confidentiality, integrity, and availability, and it is considered easily exploitable without user interaction.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70756

Related in this roundup: CVE-2026-70748, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038.

CVE-2026-70757

CVE-2026-70757 is a critical vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker to take control of the server over the network via the T3 or IIOP protocols. The flaw is easily exploitable and carries a CVSS 3.1 base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70757

Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-83021, CVE-2026-83038.

CVE-2026-70913

CVE-2026-70913 is a critical vulnerability in the Core component of Oracle Identity Manager within Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. With a CVSS base score of 9.8, this vulnerability poses a severe risk to confidentiality, integrity, and availability.

Affected products:

  • Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70913

Related in this roundup: CVE-2026-70915, CVE-2026-73943.

CVE-2026-71133

CVE-2026-71133 is a critical vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. An unauthenticated attacker with network access can exploit this flaw via HTTP to achieve full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 10.0 and allows for a scope change, potentially impacting other integrated products.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71133

Related in this roundup: CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-71163

CVE-2026-71163 is a critical vulnerability affecting the Authentication Engine component of Oracle Access Manager in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can exploit this flaw to perform unauthorized data modification, deletion, and access, as well as trigger a partial denial of service. The vulnerability supports scope change (S:C), significantly impacting the security posture of the affected environment.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71163

Related in this roundup: CVE-2026-71133, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73940

CVE-2026-73940 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker to gain unauthorized control over the system via T3 or IIOP network protocols. With a CVSS base score of 9.8, this vulnerability poses a severe risk, as successful exploitation results in full compromise of the application's confidentiality, integrity, and availability.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73940

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73944

CVE-2026-73944 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to or modify critical data within the Oracle Access Manager environment via HTTP requests. This issue carries a CVSS 3.1 base score of 9.1 and represents a significant risk to data confidentiality and integrity.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73944

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73945

CVE-2026-73945 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this via HTTP to achieve a full takeover of the Oracle Access Manager instance, potentially affecting other products due to a scope change. The vulnerability carries a CVSS base score of 9.9 and impacts confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73945

CVE-2026-73946

CVE-2026-73946 is a high-severity vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. An attacker with high privileges can exploit this vulnerability over HTTP to achieve a full takeover of the Oracle Access Manager service, with potential for scope change impacting additional connected products. The vulnerability has a CVSS 3.1 base score of 9.1.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73946

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73947

A critical vulnerability exists in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the target system, resulting in a complete takeover. Given the high CVSS base score of 9.8, the vulnerability is easily exploitable without user interaction.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73947

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73948

CVE-2026-73948 is a critical vulnerability in Oracle WebCenter Portal (part of Oracle Fusion Middleware) that allows a low-privileged, network-based attacker to gain full control of the application. The vulnerability features a scope change (S:C), indicating that successful exploitation can impact other connected products and infrastructure. Detection engineers should monitor for unauthorized HTTP traffic targeting the Composer component of the WebCenter Portal, as successful exploitation results in total system compromise with high confidentiality, integrity, and availability impact.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73948

Related in this roundup: CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-73950

Oracle Access Manager, a component of Oracle Fusion Middleware, contains a critical vulnerability in its Authentication Engine that allows an unauthenticated, remote attacker to gain full control of the application via HTTP. The vulnerability is highly exploitable, requiring no user interaction or elevated privileges, resulting in a CVSS score of 9.8.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73950

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73952

CVE-2026-73952 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. The flaw allows an unauthenticated attacker with network access to leverage HTTP requests to achieve unauthorized creation, deletion, or modification of critical data within the application. With a CVSS base score of 9.1, it represents a significant risk to data confidentiality and integrity, necessitating immediate patching of affected 12.2.1.4.0 and 14.1.2.0.0 versions.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73952

Related in this roundup: CVE-2026-73948, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-73953

CVE-2026-73953 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. The flaw is remotely exploitable without authentication, allowing an attacker with network access to achieve full system takeover via HTTP requests. With a CVSS base score of 9.8, it represents a high risk for complete loss of confidentiality, integrity, and availability of the affected portal instance.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73953

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-73956

CVE-2026-73956 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, potentially leading to a full takeover of the affected product. With a CVSS 3.1 base score of 9.8, this flaw impacts confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73956

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-73957

CVE-2026-73957 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. It allows an unauthenticated, network-adjacent attacker to perform unauthorized data manipulation or access through a specifically crafted HTTP request that requires user interaction. The vulnerability has a scope change impact, potentially affecting other integrated products.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73957

CVE-2026-73961

CVE-2026-73961 is a critical vulnerability in the ADF Faces component of Oracle JDeveloper. The flaw allows an unauthenticated remote attacker with network access to achieve a complete takeover of the application via HTTP. Given the CVSS score of 9.8 and the lack of required authentication or user interaction, this vulnerability presents a significant risk for remote code execution.

Affected products:

  • JDeveloper (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73961

Related in this roundup: CVE-2026-83067.

CVE-2026-73962

CVE-2026-73962 is a critical vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. A low-privileged attacker with network access over HTTPS can exploit this flaw to bypass security controls, resulting in unauthorized access to, creation, deletion, or modification of critical data within the application. The vulnerability carries a CVSS score of 9.6 and involves a scope change, meaning it can impact other integrated products.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73962

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73963

Oracle WebCenter Portal, a component of Oracle Fusion Middleware, contains a critical vulnerability in its Portlet Services that allows unauthenticated attackers to compromise the application via network access over HTTP. Successful exploitation can lead to a full takeover of the Oracle WebCenter Portal, with high impact to confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73963

CVE-2026-82994

CVE-2026-82994 is a critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. An unauthenticated attacker can exploit this vulnerability over a network via LDAP to achieve a full takeover of the application, impacting confidentiality, integrity, and availability with a CVSS 3.1 base score of 9.8.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82994

CVE-2026-82995

CVE-2026-82995 is a critical RCE vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. The vulnerability allows an unauthenticated attacker with network access to exploit the system via SOAP requests, potentially leading to a full takeover of the affected service.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82995

CVE-2026-82997

CVE-2026-82997 is a critical RCE vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. A low-privileged attacker can exploit this via network access using T3 or IIOP protocols to achieve full system takeover. The vulnerability allows for scope change, potentially impacting other products integrated with the affected platform.

Affected products:

  • Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82997

Related in this roundup: CVE-2026-82999, CVE-2026-83000.

CVE-2026-82998

CVE-2026-82998 is a critical RCE vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. An attacker with low privileges can exploit the vulnerability via network protocols T3 or IIOP to achieve a full takeover of the platform. Due to the scope change, successful exploitation may also impact additional products within the environment.

Affected products:

  • Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82998

Related in this roundup: CVE-2026-83020, CVE-2026-83151.

CVE-2026-82999

CVE-2026-82999 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. A low-privileged attacker with network access can exploit this vulnerability via HTTP to achieve full takeover of the platform. The vulnerability is characterized by a scope change, allowing the compromise to impact additional products, and carries a CVSS base score of 9.9.

Affected products:

  • Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82999

Related in this roundup: CVE-2026-82997, CVE-2026-83000.

CVE-2026-83000

CVE-2026-83000 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform. An unauthenticated attacker with network access can exploit this via HTTP to achieve full compromise of the platform. The vulnerability carries a CVSS base score of 9.8, indicating significant risks to confidentiality, integrity, and availability.

Affected products:

  • Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83000

Related in this roundup: CVE-2026-82997, CVE-2026-82999.

CVE-2026-83001

CVE-2026-83001 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP and allows a high-privileged attacker to achieve a complete takeover of the Oracle Access Manager product. The exploit carries a scope change, potentially impacting additional products beyond the primary target, with significant implications for confidentiality, integrity, and availability.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83001

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.

CVE-2026-83006

CVE-2026-83006 is a high-severity, easily exploitable vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A high-privileged attacker with network access can leverage HTTP requests to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 9.1 and involves a scope change, potentially impacting additional products within the environment.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83006

Related in this roundup: CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83020

CVE-2026-83020 is a critical vulnerability in the Centralized Thirdparty Jars component of Oracle Fusion Middleware's Platform Security for Java. It allows an unauthenticated, remote attacker to achieve full system takeover via HTTP. Given the scope change impact and maximum CVSS score of 10.0, this represents a severe risk that likely facilitates remote code execution or complete compromise of the underlying platform.

Affected products:

  • Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83020

Related in this roundup: CVE-2026-82998, CVE-2026-83151.

CVE-2026-83021

CVE-2026-83021 is a critical vulnerability in the Web Container component of Oracle WebLogic Server. The flaw allows an unauthenticated attacker with network access to achieve complete compromise (takeover) of the server via HTTP. Due to the scope change impact, the vulnerability can affect additional products in the environment, resulting in high confidentiality, integrity, and availability impacts.

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83021

Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83038.

CVE-2026-83027

CVE-2026-83027 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to information within the connector, due to an insecure design or implementation in the core component. The impact is elevated due to a scope change, potentially affecting broader integrated systems.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83027

Related in this roundup: CVE-2026-83023, CVE-2026-83025, CVE-2026-83028.

CVE-2026-83029

CVE-2026-83029 is a vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware. The vulnerability is network-exploitable over HTTP by low-privileged attackers. Successful exploitation allows for unauthorized modification, deletion, or access to critical data within the Managed File Transfer system, with potential for scope change impacting additional associated products.

Affected products:

  • Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83029

Related in this roundup: CVE-2026-83030.

CVE-2026-83031

CVE-2026-83031 is a critical vulnerability affecting Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is network-exploitable over HTTP by low-privileged attackers and can lead to a full takeover of the application. Due to a scope change, successful exploitation may also impact additional products, resulting in complete compromise of confidentiality, integrity, and availability.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83031

Related in this roundup: CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.

CVE-2026-83035

A critical vulnerability exists in Oracle WebCenter Sites, part of the Oracle Fusion Middleware stack. The flaw allows an unauthenticated attacker with network access to achieve a full takeover of the application via HTTP. Given the CVSS score of 9.8 and the lack of authentication required, this vulnerability represents a high risk of complete system compromise.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83035

Related in this roundup: CVE-2026-83031, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.

CVE-2026-83036

CVE-2026-83036 is a critical, easily exploitable vulnerability in Oracle WebCenter Sites (part of Oracle Fusion Middleware). The flaw allows an unauthenticated remote attacker with network access via HTTP to fully compromise the target application, leading to a complete takeover. Given the CVSS score of 9.8, this represents a high-risk vector requiring immediate patching.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83036

Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.

CVE-2026-83037

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to an unauthenticated, network-exploitable issue that allows a complete takeover of the application. The vulnerability carries a CVSS base score of 9.8, indicating critical impact on confidentiality, integrity, and availability, and can be exploited via HTTP without user interaction.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83037

Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.

CVE-2026-83038

Oracle WebLogic Server, specifically the TopLink Integration component, contains a critical vulnerability (CVE-2026-83038) that allows a low-privileged attacker with network access via HTTP to compromise the server. Successful exploitation results in a full system takeover and impacts additional products due to a scope change (CVSS 9.9).

Affected products:

  • WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83038

Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83021.

CVE-2026-83039

CVE-2026-83039 is a critical vulnerability within the Composer component of Oracle WebCenter Portal. The flaw is remotely exploitable over HTTP by a low-privileged attacker, potentially leading to a full system takeover. The vulnerability carries a CVSS 3.1 score of 9.9 and involves a scope change that can impact integrated products, indicating a significant risk to confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83039

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83040

CVE-2026-83040 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. It allows an unauthenticated attacker with network access to exploit the system via SOAP requests. The attack requires user interaction and can lead to a full system takeover and unauthorized access, with impacts extending to other products due to scope change.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83040

CVE-2026-83042

CVE-2026-83042 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The vulnerability allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83042

Related in this roundup: CVE-2026-71047, CVE-2026-73942.

CVE-2026-83043

CVE-2026-83043 is a critical vulnerability in Oracle WebCenter Portal, part of the Oracle Fusion Middleware suite. It allows an unauthenticated attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability requires human interaction to succeed and results in a scope change, potentially impacting additional integrated products. It is highly exploitable, carrying a CVSS 3.1 base score of 9.6.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83043

CVE-2026-83054

Oracle Internet Directory within Oracle Fusion Middleware contains a critical vulnerability in the OID LDAP Server component. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83054

Related in this roundup: CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83055

CVE-2026-83055 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. A low-privileged attacker with network access via the LDAP protocol can exploit this flaw to achieve a full takeover of the Oracle Internet Directory service. The vulnerability supports scope changes, potentially impacting other integrated products, and carries a CVSS base score of 9.9.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83055

CVE-2026-83056

Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 are vulnerable to a remote, easily exploitable vulnerability in the LDAP server component. A low-privileged attacker with network access can leverage this flaw to achieve a full takeover of the directory service, resulting in a complete compromise of confidentiality, integrity, and availability with scope change impact.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83056

Related in this roundup: CVE-2026-83054, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83057

A critical vulnerability (CVSS 9.9) exists in the OID LDAP Server component of Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is remotely exploitable over the network by a low-privileged attacker using the LDAP protocol. Successful exploitation allows for a full takeover of the Oracle Internet Directory and can result in a scope change, potentially impacting other integrated Oracle Fusion Middleware products.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83057

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83058

CVE-2026-83058 is a critical vulnerability in the OID LDAP Server component of Oracle Internet Directory. An attacker with low privileges and network access can exploit this flaw via LDAP to achieve a full system takeover, with potential for scope change impacting broader infrastructure. The vulnerability scores 9.9 on the CVSS scale, indicating high risk to confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83058

CVE-2026-83059

CVE-2026-83059 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is network-exploitable by an unauthenticated attacker via the LDAP protocol. Successful exploitation allows for the full takeover of the directory service and can result in a scope change, potentially impacting other integrated products with a CVSS 3.1 base score of 10.0.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83059

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83060

CVE-2026-83060 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over the network via LDAP to achieve full system takeover, posing a severe risk to confidentiality, integrity, and availability.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83060

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83061

CVE-2026-83061 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve a full takeover of the directory service. The vulnerability impacts the confidentiality, integrity, and availability of the affected system.

Affected products:

  • Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83061

CVE-2026-83062

CVE-2026-83062 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the OID LDAP server. With a CVSS score of 9.8, this exploit targets the LDAP service, impacting confidentiality, integrity, and availability without requiring user interaction.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83062

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83066, CVE-2026-83063.

CVE-2026-83064

Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 contains a vulnerability in the Runtime Tools component that allows a high-privileged attacker with network access via HTTP to perform a full system takeover. The vulnerability has a CVSS 3.1 base score of 9.1 and supports a scope change, meaning exploitation can lead to impact beyond the vulnerable product itself.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83064

CVE-2026-83066

CVE-2026-83066 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this via network access using T3 or IIOP protocols to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83066

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83063.

CVE-2026-83094

Oracle Forms in Oracle Fusion Middleware contains a critical vulnerability in the Forms Services component that allows an unauthenticated, network-adjacent attacker to achieve a full system takeover. The vulnerability is highly exploitable via HTTP and carries a CVSS base score of 9.8, indicating severe impacts on confidentiality, integrity, and availability.

Affected products:

  • Oracle Forms (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83094

Related in this roundup: CVE-2026-83102.

CVE-2026-83095

CVE-2026-83095 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker to gain full control over the Forms Services through HTTP-based network access, leading to a complete takeover of the service. The vulnerability carries a CVSS base score of 9.8, indicating severe confidentiality, integrity, and availability impact.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83095

CVE-2026-83098

CVE-2026-83098 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve a full system takeover via HTTP requests. It is rated with a CVSS 3.1 base score of 9.8, indicating high confidentiality, integrity, and availability impacts.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83098

CVE-2026-83099

CVE-2026-83099 is a critical vulnerability in Oracle Fusion Middleware, specifically within the Oracle Forms component. The flaw allows an unauthenticated remote attacker with network access to achieve full takeover of the Oracle Forms service via HTTP. Due to its impact on Confidentiality, Integrity, and Availability and the potential for scope change, it has been assigned a CVSS v3.1 base score of 10.0.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83099

Related in this roundup: CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83100

CVE-2026-83100 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. It allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the affected service via HTTP. Due to the lack of required authentication and low attack complexity, this flaw poses a severe risk of full system compromise.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83100

Related in this roundup: CVE-2026-83099, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83103

Oracle Forms in Fusion Middleware is vulnerable to a remote, easily exploitable flaw that allows a highly privileged attacker with network access via HTTP to fully compromise the service. The vulnerability impacts confidentiality, integrity, and availability, and because of a scope change, it can also lead to the compromise of additional products within the environment.

Affected products:

  • Forms Services (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83103

CVE-2026-83104

CVE-2026-83104 is a high-severity, easily exploitable vulnerability in the Oracle Forms component of Oracle Fusion Middleware. An unauthenticated attacker with network access via TCP can compromise the service, leading to unauthorized read, write, and deletion access to critical data managed by the application.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83104

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83105

CVE-2026-83105 is a high-severity vulnerability in the Oracle Forms component of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can exploit this flaw to achieve full takeover of the Forms Services. The vulnerability has a scope change (S:C) impact, meaning successful exploitation can compromise the integrity, confidentiality, and availability of other connected systems.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83105

CVE-2026-83107

CVE-2026-83107 is a critical vulnerability in Oracle Fusion Middleware's Forms Services component. It allows a high-privileged attacker with network access via HTTP to perform an unauthorized takeover of the Oracle Forms product. Due to the nature of the flaw, it allows for scope change, potentially impacting other integrated products. Successful exploitation results in full compromise of Confidentiality, Integrity, and Availability.

Affected products:

  • Oracle Fusion Middleware
  • Oracle Forms (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83107

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83108

CVE-2026-83108 is a critical vulnerability in Oracle Fusion Middleware (specifically Oracle Forms Services). The flaw allows an unauthenticated, network-adjacent attacker to compromise the service via HTTP requests. Successful exploitation grants the attacker full control over the affected Oracle Forms instance, impacting confidentiality, integrity, and availability with a CVSS 3.1 base score of 9.8. Affected versions include 12.2.1.19.0 and 14.1.2.0.0.

Affected products:

  • Oracle Fusion Middleware
  • Oracle Forms

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83108

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83149

CVE-2026-83149 is a critical vulnerability in Oracle Application Testing Suite version 13.3.0.1 that allows an authenticated, low-privileged attacker with 'Test Manager for Web Apps' permissions to perform unauthorized data access, modification, and partial denial of service. The vulnerability supports scope changes, meaning it can facilitate impacts beyond the initial application. It is exploitable via HTTP over the network with low attack complexity.

Affected products:

  • Application Testing Suite (13.3.0.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83149

CVE-2026-83151

CVE-2026-83151 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. The flaw is remotely exploitable without authentication via SOAP requests, allowing an attacker to achieve a full system takeover. Given the CVSS 3.1 score of 9.8, detection engineers should monitor for unauthorized or malformed SOAP traffic directed at the Service Delivery Platform component.

Affected products:

  • Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83151

Related in this roundup: CVE-2026-82998, CVE-2026-83020.

CVE-2026-83154

CVE-2026-83154 is a critical vulnerability in the Open UI component of Oracle Siebel CRM versions 17.0 through 26.7. An unauthenticated, remote attacker can exploit the vulnerability via SOAP requests to perform unauthorized read, write, or delete operations on critical system data, resulting in significant impacts to confidentiality and integrity.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83154

Related in this roundup: CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.

CVE-2026-83196

CVE-2026-83196 is a high-severity vulnerability within the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting versions 17.0 through 26.7. The vulnerability is network-exploitable via HTTP by an attacker with high privileges, potentially leading to a full system compromise with a scope change impact on other products.

Affected products:

  • Siebel CRM Deployment (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83196

CVE-2026-83197

CVE-2026-83197 is a critical vulnerability in the Financial Accounts component of Oracle Siebel CRM Financial Services. The flaw allows unauthenticated remote attackers to exploit the system over HTTP, leading to unauthorized access to critical data and potential denial-of-service (DOS) conditions through system crashes. The vulnerability is characterized by high confidentiality and availability impacts.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83197

Related in this roundup: CVE-2026-83154, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.

CVE-2026-83201

CVE-2026-83201 is a critical vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, modification, or deletion of critical data, as well as gain unauthorized access to data via HTTP, due to a lack of authentication requirements.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83201

Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.

CVE-2026-83202

CVE-2026-83202 is a critical vulnerability in the Server Infrastructure component of Oracle Siebel CRM versions 17.0 through 26.7. An unauthenticated attacker can exploit this via HTTP network access to gain unauthorized access to or modify critical data within the Siebel CRM Deployment. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting its high impact on confidentiality and integrity.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83202

Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.

CVE-2026-83229

CVE-2026-83229 is a critical vulnerability in the Siebel Management Console component of Oracle Siebel CRM versions 17.0 through 26.7. An attacker with high privileges can exploit this vulnerability over HTTP to achieve a full system compromise. The vulnerability is characterized by a high impact on confidentiality, integrity, and availability, and permits scope change, potentially affecting integrated products beyond the immediate deployment.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83229

Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-73966, CVE-2026-82992.

CVE-2026-83232

CVE-2026-83232 is a critical vulnerability in the Console and Repository Explorer components of Oracle Data Integrator within Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over the network via HTTP to achieve full compromise of the application, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle Data Integrator (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83232

CVE-2026-83260

CVE-2026-83260 is a critical vulnerability in the Event Java PX component of Oracle Agile PLM version 9.3.6. The flaw is remotely exploitable over the network via T3 or IIOP protocols by a high-privileged attacker, potentially leading to a full system takeover and impacting other integrated products due to scope change.

Affected products:

  • Agile PLM (9.3.6)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83260

CVE-2026-83261

Oracle Product Lifecycle Analytics version 3.6.1 contains a critical vulnerability that allows an unauthenticated remote attacker to gain full control of the application via HTTP. With a CVSS score of 9.8, the flaw permits complete compromise of confidentiality, integrity, and availability, likely indicating an RCE or similar high-impact vulnerability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83261

CVE-2026-83268

CVE-2026-83268 is a critical vulnerability in Oracle BI Publisher within Oracle Analytics, specifically involving the BI Platform Security component. The flaw is remotely exploitable over HTTP by a high-privileged attacker and allows for a full takeover of the product. The vulnerability involves a change of scope, potentially impacting additional products integrated with the BI Publisher environment.

Affected products:

  • BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83268

CVE-2026-83269

CVE-2026-83269 is a critical vulnerability in the BI Platform Security component of Oracle BI Publisher. The flaw allows an unauthenticated attacker with network access to achieve a full system takeover via HTTP. Due to its high CVSS score of 9.8 and the lack of required authentication or user interaction, this vulnerability represents a significant risk for remote code execution or complete compromise of the affected analytics platform.

Affected products:

  • Oracle BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83269

CVE-2026-83282

CVE-2026-83282 is a critical vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (version 12.2.1.4.0). The flaw is remotely exploitable over HTTP by a low-privileged attacker and allows for a complete takeover of the affected product with a significant impact on system confidentiality, integrity, and availability. Due to the scope change vector, successful exploitation may also affect additional integrated products.

Affected products:

  • Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83282

Related in this roundup: CVE-2026-83283, CVE-2026-83071.

CVE-2026-83283

CVE-2026-83283 is a critical vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. The vulnerability allows an unauthenticated, remote attacker to gain full control of the application via HTTP. Given the high CVSS score of 9.8 and the ability for total system takeover, this represents a significant risk to the integrity and availability of the affected environment.

Affected products:

  • Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83283

Related in this roundup: CVE-2026-83282, CVE-2026-83071.

CVE-2026-83327

CVE-2026-83327 is a critical vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated, remote attacker to gain full control of the framework via SOAP requests, resulting in a complete compromise of confidentiality, integrity, and availability.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83327

Related in this roundup: CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83339

CVE-2026-83339 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via HTTP requests. Given the high CVSS score of 9.8 and the ease of exploitation, this represents a significant risk for remote code execution or unauthorized access to the application.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83339

Related in this roundup: CVE-2026-83006, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83355

CVE-2026-83355 is a critical vulnerability in the Oracle Enterprise Manager for Fusion Middleware component 'Metrics', allowing unauthenticated, network-adjacent attackers to achieve full system takeover via HTTP. With a CVSS 3.1 base score of 9.8, this flaw impacts confidentiality, integrity, and availability, and requires immediate patching of affected versions 13.5 and 24.1.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83355

CVE-2026-83452

CVE-2026-83452 is a critical vulnerability affecting the Oracle Document Management and Collaboration component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker to gain full control of the component via a network-accessible HTTP request, resulting in total compromise of confidentiality, integrity, and availability.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83452

Related in this roundup: CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83462

CVE-2026-83462 is a critical vulnerability in the Oracle Mobile Application Server component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw allows an unauthenticated attacker with network access via TCP to fully compromise the server, leading to impacts on confidentiality, integrity, and availability. With a CVSS base score of 9.8, the vulnerability is classified as easily exploitable due to the lack of required authentication or user interaction.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)
  • Mobile Application Server (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83462

Related in this roundup: CVE-2026-83327, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-87128

CVE-2026-87128 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability is easily exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized read, write, or modification access to critical application data.

Affected products:

  • Hyperion Data Relationship Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87128

Related in this roundup: CVE-2026-87129.

CVE-2026-87129

CVE-2026-87129 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability allows an unauthenticated, network-adjacent attacker to exploit the application via HTTP. Successful exploitation grants unauthorized access to modify, delete, or create critical data, as well as read sensitive information, leading to high impacts on confidentiality and integrity.

Affected products:

  • Hyperion Data Relationship Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87129

Related in this roundup: CVE-2026-87128.

CVE-2026-87170

CVE-2026-87170 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated remote attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data, as well as gain unauthorized access to data stored within the application.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87170

Related in this roundup: CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87172

CVE-2026-87172 is a critical vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) that allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP. The vulnerability has a CVSS 3.1 base score of 9.9 and possesses a scope change (S:C) characteristic, meaning exploitation can potentially impact other integrated products or infrastructure.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87172

Related in this roundup: CVE-2026-87170, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87173

CVE-2026-87173 is a critical security vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated, network-adjacent attacker to gain unauthorized access to or modify critical data via TCP, without requiring user interaction or elevated privileges.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87173

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87175

CVE-2026-87175 is an easily exploitable, unauthenticated vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An attacker with network access via TCP can leverage this vulnerability to gain unauthorized access to, modify, or delete critical data within the application, leading to severe impacts on confidentiality and integrity.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87175

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87176

CVE-2026-87176 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An unauthenticated attacker with network access via TCP can remotely compromise the application, leading to unauthorized modification, deletion, or full access to critical data. The vulnerability carries a CVSS 3.1 base score of 9.1.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87176

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87184

CVE-2026-87184 is a critical SQL injection vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is remotely exploitable without authentication, allowing an attacker to achieve full takeover of the application by compromising confidentiality, integrity, and availability.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87184

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87186

CVE-2026-87186 is a critical security vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated attacker with local network access (adjacent segment) to gain full control over the application. Given the high CVSS score of 9.6 and the potential for a full system takeover and cross-product impact (scope change), this represents a significant risk to enterprise financial systems.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87186

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87188

CVE-2026-87188 is a critical vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000, specifically within the Security component. The vulnerability allows an unauthenticated, remote attacker to compromise the application via HTTP. Given the CVSS score of 9.8 and the full impact on Confidentiality, Integrity, and Availability, this vulnerability facilitates a complete takeover of the affected product.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87188

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87189

CVE-2026-87189 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An attacker with high privileges and network access via Oracle Net can exploit this vulnerability to achieve a full system takeover. The vulnerability carries a CVSS base score of 9.1 and supports scope changes, meaning successful exploitation can lead to a compromise of additional products within the environment.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87189

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87214

CVE-2026-87214 is a critical vulnerability in Oracle Hyperion Financial Management (v11.2.26.0.000) that allows a highly privileged attacker to achieve full system takeover via network-based HTTP exploitation. The vulnerability carries a CVSS 3.1 base score of 9.1 and involves a scope change, meaning exploitation can potentially impact other integrated products within the environment.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87214

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87217

CVE-2026-87217 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management (version 11.2.26.0.000). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application, resulting in the unauthorized creation, deletion, modification, or full access to sensitive data.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87217

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87223, CVE-2026-87230.

CVE-2026-87223

CVE-2026-87223 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated, network-adjacent attacker to exploit the system via HTTP, potentially leading to unauthorized modification or deletion of critical data, as well as causing a denial-of-service (DoS) condition.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87223

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87230.

CVE-2026-87230

CVE-2026-87230 is a critical, unauthenticated remote vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable over the network via HTTP and allows for a scope change, enabling an attacker to achieve unauthorized access to, modification of, or deletion of critical data, resulting in a CVSS base score of 10.0.

Affected products:

  • Hyperion Financial Management (11.2.26.0.000)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87230

Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223.

CVE-2026-70915

CVE-2026-70915 is a critical vulnerability in the Core component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw allows a low-privileged, network-adjacent attacker to achieve full system takeover via T3 or IIOP protocols. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70915

Related in this roundup: CVE-2026-70913, CVE-2026-73943.

CVE-2026-71047

CVE-2026-71047 is a critical vulnerability within the Core component of Oracle Identity Manager in Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this via HTTP to achieve a full system takeover, impacting confidentiality, integrity, and availability. The vulnerability is rated with a CVSS score of 8.8 and is considered easily exploitable without requiring user interaction.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71047

Related in this roundup: CVE-2026-83042, CVE-2026-73942.

CVE-2026-73926

Oracle Access Manager, a component of Oracle Fusion Middleware, contains a vulnerability in the Authentication Engine that allows a high-privileged attacker with network access to compromise the system. This vulnerability allows for unauthorized creation, deletion, or modification of critical data, as well as full unauthorized access to data stored within the product, with a scope change impacting other products as well.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73926

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73958, CVE-2026-83002.

CVE-2026-73941

CVE-2026-73941 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager. The flaw allows an unauthenticated, network-adjacent attacker to exploit the system via HTTP. Successful exploitation can lead to a scope change and unauthorized access to critical data managed by the application. The vulnerability carries a CVSS 3.1 base score of 8.6, specifically impacting confidentiality.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73941

CVE-2026-73942

CVE-2026-73942 is a critical vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware. An attacker with low-level network access can exploit this vulnerability via HTTP to achieve full takeover of the Identity Manager application. The vulnerability impacts confidentiality, integrity, and availability, and is considered easily exploitable by a low-privileged user without requiring user interaction.

Affected products:

  • Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73942

Related in this roundup: CVE-2026-83042, CVE-2026-71047.

CVE-2026-73943

Oracle Identity Manager contains a vulnerability in the OIM Legacy UI component that allows a high-privileged attacker with network access via HTTP to perform unauthorized operations, including accessing or modifying critical data. The vulnerability has a scope change (S:C), indicating that successful exploitation can impact other products integrated with the identity manager.

Affected products:

  • Identity Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73943

Related in this roundup: CVE-2026-70913, CVE-2026-70915.

CVE-2026-73949

CVE-2026-73949 is a high-severity vulnerability in Oracle WebCenter Portal's Portlet Services component, allowing low-privileged attackers with network access to perform a full system takeover via HTTP. The vulnerability has a CVSS score of 8.8 and impacts the confidentiality, integrity, and availability of the affected Oracle Fusion Middleware products.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73949

CVE-2026-73951

CVE-2026-73951 is a vulnerability in the Portlet Services component of Oracle WebCenter Portal that allows an unauthenticated, remote attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability has a CVSS base score of 8.1, indicating high impacts on confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73951

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-73954

CVE-2026-73954 is a high-severity vulnerability in the Oracle PeopleSoft Enterprise PeopleTools component 'Business Interlink'. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to achieve a full system compromise. The vulnerability is characterized by a CVSS 3.1 base score of 8.1, indicating significant impacts on confidentiality, integrity, and availability.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73954

Related in this roundup: CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.

CVE-2026-73955

CVE-2026-73955 is a vulnerability in the Charting component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. A low-privileged attacker with network access can exploit this flaw via HTTP, requiring user interaction to succeed. The vulnerability allows for unauthorized access, creation, deletion, or modification of critical data within the PeopleSoft environment.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73955

CVE-2026-73958

CVE-2026-73958 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager. The flaw allows an unauthenticated attacker with network access via HTTP to potentially take over the affected service. The vulnerability is characterized as difficult to exploit and carries a CVSS 3.1 base score of 8.1, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73958

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-83002.

CVE-2026-73959

CVE-2026-73959 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially allowing for a full takeover of the application. It carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73959

Related in this roundup: CVE-2026-83065.

CVE-2026-73960

CVE-2026-73960 is a vulnerability in the Ren Server component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability allows an unauthenticated, network-adjacent attacker to perform a denial-of-service attack via HTTP, resulting in a system hang or repeatable crash.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73960

Related in this roundup: CVE-2026-73954, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.

CVE-2026-73966

A high-privileged remote code execution vulnerability exists in the Marketing component of Oracle Siebel CRM, allowing an attacker with network access via HTTP to fully compromise the product. The vulnerability is rated with a CVSS 3.1 base score of 7.2.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73966

Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-82992.

CVE-2026-82992

CVE-2026-82992 is a high-severity vulnerability in the Installation component of Oracle Siebel CRM, affecting versions 17.0 through 26.7. The flaw allows a low-privileged authenticated user with local access to the deployment infrastructure to achieve a full takeover of the Siebel CRM Deployment component. The vulnerability is considered easily exploitable and impacts the confidentiality, integrity, and availability of the system.

Affected products:

  • Siebel CRM (17.0-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82992

Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966.

CVE-2026-82993

CVE-2026-82993 is a vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve unauthorized access to, or modification of, critical data within the PeopleSoft environment. The vulnerability impacts the scope of the application, potentially affecting integrated systems as well.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82993

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.

CVE-2026-82996

CVE-2026-82996 is a vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. A low-privileged attacker with local logon access can exploit this flaw to gain unauthorized control (takeover) of the component, leading to full compromise of confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82996

CVE-2026-83002

CVE-2026-83002 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.5 and impacts Confidentiality, Integrity, and Availability, with the potential for scope change affecting additional products.

Affected products:

  • Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83002

Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958.

CVE-2026-83003

CVE-2026-83003 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this vulnerability via SOAP to gain unauthorized access to critical data or perform unauthorized modification/deletion of data. The vulnerability features a scope change, meaning it can impact additional products beyond the primary target.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83003

CVE-2026-83004

CVE-2026-83004 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture that allows a low-privileged, authenticated attacker to perform unauthorized creation, modification, or deletion of critical data. Exploitation is difficult and requires human interaction; however, it can result in a scope change impacting additional products within the Oracle Fusion Middleware environment.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83004

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83005

CVE-2026-83005 is a critical vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by low-privileged attackers. Successful exploitation allows for complete takeover of the affected product, with high impacts on confidentiality, integrity, and availability.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83005

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83007

CVE-2026-83007 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker can exploit this flaw over HTTP to gain unauthorized access to critical data, as well as perform unauthorized modifications or deletions of data within the application. The vulnerability allows for scope change, potentially impacting other integrated products.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83007

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83008

Oracle WebCenter Enterprise Capture contains a critical vulnerability in the Client Bundle component that can be exploited by a low-privileged attacker with network access via T3 or IIOP protocols. Successful exploitation results in a full system takeover, posing significant risks to confidentiality, integrity, and availability.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83008

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83009

CVE-2026-83009 is a critical vulnerability in Oracle WebCenter Enterprise Capture that allows a low-privileged attacker with network access via HTTP to fully compromise the product. The flaw affects versions 12.2.1.4.0 and 14.1.2.0.0, enabling unauthorized access to confidentiality, integrity, and availability of the system.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83009

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83010

CVE-2026-83010 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is remotely exploitable over HTTP by a high-privileged attacker, though it requires human interaction to succeed. Successful exploitation allows for unauthorized modification, deletion, or access to critical data and exhibits a scope change impact on additional products.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83010

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83011

CVE-2026-83011 is a vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full system takeover, posing a critical security risk. It has a CVSS 3.1 base score of 8.1, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle Platform Security for Java (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83011

CVE-2026-83012

CVE-2026-83012 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker can exploit this vulnerability over HTTP to gain unauthorized access to critical data. The vulnerability has a scope change (S:C) and is categorized with a high confidentiality impact.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83012

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83013, CVE-2026-83022.

CVE-2026-83013

CVE-2026-83013 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by a low-privileged attacker and can lead to a full system compromise (takeover) of the product. The vulnerability has a CVSS 3.1 base score of 8.8.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83013

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83022.

CVE-2026-83014

CVE-2026-83014 is a vulnerability in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. A low-privileged attacker with network access via HTTP can exploit this flaw to perform unauthorized data modification or deletion, and trigger a denial-of-service condition affecting the availability of the product.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83014

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.

CVE-2026-83015

CVE-2026-83015 is a vulnerability in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability allows a low-privileged attacker with local logon access to the underlying infrastructure to achieve a full takeover of the PeopleSoft Enterprise PeopleTools application. The exploit is characterized as difficult to perform but results in high impacts to confidentiality, integrity, and availability.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83015

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.

CVE-2026-83016

CVE-2026-83016 is a high-severity vulnerability within the SQR component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw requires a highly privileged local attacker to perform successful exploitation, necessitating human interaction from another user. Exploitation can lead to a complete system takeover and impact additional products via scope change, representing a significant risk to the integrity and confidentiality of the PeopleSoft environment.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83016

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83017, CVE-2026-83019.

CVE-2026-83017

CVE-2026-83017 is a vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full compromise of the application, resulting in impacts to confidentiality, integrity, and availability.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83017

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83019.

CVE-2026-83018

A vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools (versions 8.61-8.63) allows a low-privileged authenticated attacker with local access to the execution infrastructure to achieve a full takeover of the application. The vulnerability is easily exploitable and carries a high impact on the confidentiality, integrity, and availability of the system.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83018

CVE-2026-83019

CVE-2026-83019 is a vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. The vulnerability is network-exploitable via HTTP by a low-privileged attacker, potentially leading to unauthorized access to critical data and causing a Denial of Service (DoS) through repeatable crashes.

Affected products:

  • PeopleSoft Enterprise PeopleTools (8.61-8.63)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83019

Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017.

CVE-2026-83022

Oracle WebCenter Enterprise Capture in Oracle Fusion Middleware contains a vulnerability in the Client Bundle component that allows an unauthenticated attacker with local network access to perform a full system takeover. The attack requires human interaction and is difficult to exploit, but it allows for scope change, potentially impacting additional products within the environment.

Affected products:

  • WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83022

Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013.

CVE-2026-83023

CVE-2026-83023 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated remote attacker over HTTP, allowing for unauthorized access to sensitive data and potential scope escalation, resulting in a CVSS base score of 8.6.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83023

Related in this roundup: CVE-2026-83027, CVE-2026-83025, CVE-2026-83028.

CVE-2026-83024

CVE-2026-83024 is a vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with local access to the infrastructure where the connector executes can exploit this flaw to gain unauthorized control over the component, resulting in a full takeover. The vulnerability carries a CVSS base score of 7.8, indicating significant impact on confidentiality, integrity, and availability.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83024

CVE-2026-83025

CVE-2026-83025 is a high-severity, unauthenticated network-accessible vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. An attacker can exploit this flaw to gain unauthorized access to or perform unauthorized modification/deletion of critical data, with a scope change that may impact other products.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83025

Related in this roundup: CVE-2026-83027, CVE-2026-83023, CVE-2026-83028.

CVE-2026-83026

CVE-2026-83026 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. An unauthenticated attacker with access to the physical communication segment where the connector resides can exploit this vulnerability to achieve full takeover of the component. The vulnerability has a scope change (S:C) impact, potentially affecting other connected products, and carries a CVSS 3.1 base score of 8.3.

Affected products:

  • Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83026

CVE-2026-83028

Oracle Identity Manager Connector within Oracle Fusion Middleware is vulnerable to an unauthenticated, physical adjacent network-based attack. An attacker with access to the physical communication segment can exploit this vulnerability to achieve full takeover of the component, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83028

Related in this roundup: CVE-2026-83027, CVE-2026-83023, CVE-2026-83025.

CVE-2026-83030

Oracle Managed File Transfer (MFT) within Oracle Fusion Middleware is vulnerable to a remote exploitation via T3 or IIOP protocols. A low-privileged attacker with network access can leverage this flaw to gain unauthorized read, write, or delete access to critical data, as well as trigger a denial-of-service (DoS) condition via a crash of the MFT Runtime Server.

Affected products:

  • Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83030

Related in this roundup: CVE-2026-83029.

CVE-2026-83032

CVE-2026-83032 is a critical vulnerability in Oracle WebCenter Sites (part of Fusion Middleware) that allows a low-privileged, network-adjacent attacker to perform a full system takeover via HTTP. The vulnerability carries a CVSS 3.1 base score of 8.8 and impacts the confidentiality, integrity, and availability of the affected application.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83032

Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83033, CVE-2026-83034.

CVE-2026-83033

CVE-2026-83033 is a vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially leading to a full system takeover of the affected component.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83033

Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83034.

CVE-2026-83034

CVE-2026-83034 is a vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware, allowing an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data. The vulnerability is easily exploitable and carries a CVSS base score of 7.5, primarily affecting data confidentiality.

Affected products:

  • WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83034

Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033.

CVE-2026-83041

CVE-2026-83041 is a vulnerability in the Portlet Services component of Oracle WebCenter Portal within Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this vulnerability via HTTP to achieve unauthorized access to critical data. The vulnerability impacts the confidentiality of the system and involves a scope change, potentially affecting integrated products.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83041

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83044

CVE-2026-83044 is a vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially allowing unauthorized access to sensitive data and triggering a partial denial of service (DoS) condition.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83044

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83045

CVE-2026-83045 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is remotely exploitable over HTTP by a low-privileged attacker, allowing for unauthorized read, write, or deletion of sensitive data and potentially impacting other products through scope change.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83045

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83046

CVE-2026-83046 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal. A low-privileged attacker with network access can exploit this flaw via HTTP to gain unauthorized access to critical data or perform a partial denial of service (DoS) against the application.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83046

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83047

CVE-2026-83047 is an easily exploitable vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform unauthorized read, update, insert, or delete operations on critical data via HTTP requests, resulting in significant impact to confidentiality and integrity.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83047

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83048

CVE-2026-83048 is a security vulnerability in Oracle WebCenter Portal's Runtime Tools component. It allows a low-privileged attacker with network access via HTTP to exploit the system, potentially leading to a scope change and unauthorized access to critical data. The vulnerability is rated with a CVSS 3.1 base score of 7.7.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83048

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83049

CVE-2026-83049 is an easily exploitable vulnerability in the Security Framework component of Oracle WebCenter Portal. The flaw allows a low-privileged network-based attacker to perform unauthorized read, update, insert, or delete operations on critical data. The vulnerability supports scope change and carries a CVSS 3.1 base score of 8.5, indicating significant impacts on confidentiality and integrity.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83049

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83050

A vulnerability in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged network attacker to compromise the application via HTTP. Successful exploitation grants unauthorized access to critical data, including the ability to read, update, insert, or delete data within the portal, impacting both confidentiality and integrity.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83050

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83051

CVE-2026-83051 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal that allows an unauthenticated, network-adjacent attacker to gain unauthorized access to sensitive data via HTTP requests. The vulnerability is easily exploitable with low complexity, affecting versions 12.2.1.4.0 and 14.1.2.0.0, and carries a CVSS 3.1 base score of 7.5.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83051

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83052, CVE-2026-83053.

CVE-2026-83052

CVE-2026-83052 is an easily exploitable vulnerability in the Runtime Tools component of Oracle WebCenter Portal. The vulnerability allows a high-privileged attacker with network access via HTTP to perform unauthorized operations, including accessing, updating, inserting, or deleting critical data. Due to a scope change (S:C), the impact of a successful exploitation may extend to additional products integrated with the affected WebCenter Portal instance.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83052

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83053.

CVE-2026-83053

CVE-2026-83053 is a high-severity vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full takeover of the affected product, impacting confidentiality, integrity, and availability.

Affected products:

  • WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83053

Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052.

CVE-2026-83063

A vulnerability exists in the Oracle Internet Directory component of Oracle Fusion Middleware, specifically within the LDAP server functionality. The flaw is remotely exploitable over the network by a high-privileged attacker, potentially leading to a full takeover of the Oracle Internet Directory service. The vulnerability impacts confidentiality, integrity, and availability.

Affected products:

  • Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83063

Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066.

CVE-2026-83065

Oracle WebCenter Portal version 14.1.2.0.0 is vulnerable to an unauthenticated takeover attack. Exploitation requires the attacker to have access to the physical communication segment of the hardware where the application is hosted. A successful exploit results in a total compromise of the Oracle WebCenter Portal instance, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle WebCenter Portal (14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83065

Related in this roundup: CVE-2026-73959.

CVE-2026-83067

A vulnerability in the ADF Shared Components of Oracle JDeveloper allows a low-privileged, network-adjacent attacker to compromise the integrity and availability of the application. The flaw can be exploited via HTTP to perform unauthorized data modification, deletion, or creation, and to trigger a denial-of-service condition through application crashing or hanging.

Affected products:

  • JDeveloper (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83067

Related in this roundup: CVE-2026-73961.

CVE-2026-83068

CVE-2026-83068 is a vulnerability in the Core component of Oracle Enterprise Manager for Oracle Database version 24.1. The vulnerability allows a low-privileged, network-adjacent attacker to perform unauthorized access to critical data. Due to a scope change, exploitation can impact additional products beyond the vulnerable component. The vulnerability is highly exploitable via HTTP and specifically impacts confidentiality.

Affected products:

  • Oracle Enterprise Manager for Oracle Database (24.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83068

CVE-2026-83069

CVE-2026-83069 is a critical vulnerability in the Framework component of Oracle Fusion Middleware Control that allows a low-privileged, network-adjacent attacker to achieve a complete takeover of the product via HTTP. The vulnerability carries a CVSS base score of 8.8, indicating high impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware Control (12.2.1.4.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83069

CVE-2026-83070

CVE-2026-83070 is a vulnerability in Oracle PeopleSoft Enterprise PRTL Interaction Hub (component: Enterprise Portal) version 9.1 that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data. Due to a scope change, successful exploitation can result in complete access to all data within the affected application, resulting in a CVSS 3.1 base score of 7.7.

Affected products:

  • PeopleSoft Enterprise PRTL Interaction Hub (9.1)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83070

CVE-2026-83071

CVE-2026-83071 is a vulnerability in the Machine Learning component of Oracle Business Intelligence Enterprise Edition. The flaw allows a locally authenticated, low-privileged attacker to achieve full takeover of the application. It is highly exploitable and impacts the confidentiality, integrity, and availability of the system.

Affected products:

  • Oracle Business Intelligence Enterprise Edition (8.2.0.0.0, 26.01.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83071

Related in this roundup: CVE-2026-83282, CVE-2026-83283.

CVE-2026-83072

CVE-2026-83072 is a vulnerability within the Search Bean component of the Oracle Applications Framework in Oracle E-Business Suite. The flaw is remotely exploitable over HTTP by a low-privileged attacker, allowing for the unauthorized creation, modification, deletion, or access of critical data within the framework. The vulnerability carries a CVSS 3.1 base score of 8.1, indicating significant impact to both confidentiality and integrity.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83072

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83073

CVE-2026-83073 is an unauthenticated, easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability allows an attacker with access to the physical communication segment of the underlying hardware to bypass authentication and gain unauthorized access, modification, or deletion privileges over critical application data.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)
  • Siebel Cloud Manager (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83073

Related in this roundup: CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.

CVE-2026-83074

CVE-2026-83074 is a vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. An unauthenticated attacker with network access via SSH can exploit this flaw to gain unauthorized access to sensitive data, potentially impacting other products within the same scope. The vulnerability has a CVSS score of 8.6, reflecting its high impact on confidentiality.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83074

Related in this roundup: CVE-2026-83073, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.

CVE-2026-83075

CVE-2026-83075 is an easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability allows an unauthenticated attacker with network access via HTTP to perform unauthorized access to critical data. The vulnerability impacts confidentiality and does not require user interaction.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83075

Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.

CVE-2026-83078

CVE-2026-83078 is an easily exploitable, unauthenticated vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability is accessible via HTTP over the network, allowing an attacker to gain unauthorized access to critical data, including the ability to read, update, insert, or delete information within the application.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83078

Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.

CVE-2026-83079

CVE-2026-83079 is a vulnerability in Oracle Siebel CRM Cloud Applications (specifically the Siebel Cloud Manager component) affecting versions 22.3 through 26.7. The vulnerability allows a high-privileged attacker with local access to the infrastructure to achieve unauthorized access to, or modification of, critical data within the CRM application. The vulnerability has a scope change (S:C) and is characterized by significant confidentiality and integrity impacts.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83079

Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83085, CVE-2026-83087.

CVE-2026-83080

CVE-2026-83080 is a vulnerability in the Reports component of Oracle Banking Branch (versions 14.5.0.0.0 through 14.9.0.0.0) that allows a low-privileged, network-adjacent attacker to achieve full system takeover. The attack requires human interaction and is exploitable via HTTP. Given the reported impact on confidentiality, integrity, and availability, this represents a significant risk to the integrity of the banking application.

Affected products:

  • Oracle Banking Branch (14.5.0.0.0-14.9.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83080

CVE-2026-83081

CVE-2026-83081 is a vulnerability in the Core component of Oracle Banking Corporate Lending versions 14.5.0.0.0 through 14.9.0.0.0. An unauthenticated attacker with physical access to the network segment of the hosting hardware can exploit this flaw to gain unauthorized access to or modify critical data. The vulnerability supports scope change and carries a CVSS 3.1 base score of 8.0.

Affected products:

  • Oracle Banking Corporate Lending (14.5.0.0.0-14.9.0.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83081

CVE-2026-83082

CVE-2026-83082 is a critical vulnerability within the Audience component of Oracle Marketing, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP, potentially allowing for a full takeover of the Oracle Marketing product. It carries a CVSS 3.1 base score of 7.2, impacting confidentiality, integrity, and availability.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83082

Related in this roundup: CVE-2026-83452, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83083

Oracle Marketing, a component of Oracle E-Business Suite versions 12.2.3 through 12.2.15, is vulnerable to a network-based attack by low-privileged users. The vulnerability allows an attacker to gain unauthorized access to critical data and perform unauthorized modifications or deletions of data within the Audience component, with the potential for impact to additional products via scope change.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83083

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83084

CVE-2026-83084 is a critical vulnerability in the Audience component of Oracle Marketing within the Oracle E-Business Suite. The vulnerability allows a low-privileged, network-adjacent attacker to perform unauthorized access to critical data. The vulnerability has a scope change (S:C) and specifically impacts the confidentiality of the targeted system, carrying a CVSS 3.1 base score of 7.7.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83084

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83085

CVE-2026-83085 is a vulnerability in Oracle Siebel Cloud Manager within Siebel CRM Cloud Applications versions 22.3 through 26.7. An attacker with low-level privileges and access to the local physical communication segment can perform unauthorized data access, modification, deletion, and cause a partial denial of service. The vulnerability has a scope change (S:C) impact, potentially affecting other products within the environment.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83085

Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83087.

CVE-2026-83086

CVE-2026-83086 is a high-severity vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. A low-privileged attacker with network access can exploit this flaw via HTTP to achieve a full system takeover, impacting the confidentiality, integrity, and availability of the application. The vulnerability is considered easily exploitable and does not require user interaction.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83086

CVE-2026-83087

CVE-2026-83087 is a vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting versions 22.3 through 26.7. The vulnerability is exploitable over the network via HTTP by a low-privileged attacker. Successful exploitation allows for unauthorized modification, deletion, or access to critical data and carries a scope change, potentially impacting other integrated products.

Affected products:

  • Siebel CRM Cloud Applications (22.3-26.7)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83087

Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085.

CVE-2026-83088

CVE-2026-83088 is a vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0 through 23.26.3. A low-privileged, authenticated attacker with network access via Oracle Net can exploit this flaw to cause a complete denial-of-service (DoS) resulting in a hang or repeatable crash of the RDBMS. The vulnerability impacts the broader scope of the system and is considered easily exploitable with high availability impacts.

Affected products:

  • Database Server (23.4.0-23.26.3)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83088

CVE-2026-83089

CVE-2026-83089 is a vulnerability in the Oracle Alert component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an authenticated, low-privileged attacker with network access to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to data within the Oracle Alert system. The vulnerability is classified as easily exploitable and carries a CVSS 3.1 base score of 8.1.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83089

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83090

CVE-2026-83090 is a critical vulnerability in the Oracle Spares Management component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by a low-privileged attacker, potentially leading to a full system takeover, impacting confidentiality, integrity, and availability.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83090

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83091

CVE-2026-83091 is a vulnerability in the Internal Operations component of Oracle Field Service (Oracle E-Business Suite) that allows a low-privileged, network-adjacent attacker to gain unauthorized access to data, modify or delete information, and trigger a partial denial-of-service condition via HTTP. The flaw is considered easily exploitable and carries a CVSS 3.1 base score of 7.6.

Affected products:

  • Oracle Field Service (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83091

Related in this roundup: CVE-2026-83092.

CVE-2026-83092

CVE-2026-83092 is a vulnerability in the Internal Operations component of Oracle Field Service (within Oracle E-Business Suite) that allows a low-privileged attacker with network access via HTTP to perform unauthorized data modification, deletion, or access, as well as cause a partial denial of service. The vulnerability is difficult to exploit but carries a CVSS 3.1 base score of 7.1.

Affected products:

  • Oracle Field Service (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83092

Related in this roundup: CVE-2026-83091.

CVE-2026-83093

An unauthenticated, network-accessible vulnerability exists in the Forms Services component of Oracle Fusion Middleware. The flaw allows remote attackers to compromise the Oracle Forms environment via HTTP, potentially leading to unauthorized access to critical data. The vulnerability is characterized by a scope change, allowing the impact to extend beyond the affected component, and is rated with a CVSS 3.1 base score of 8.6 due to its ease of exploitation and high confidentiality impact.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83093

CVE-2026-83096

Oracle Fusion Middleware Forms Services contains a vulnerability that allows an authenticated, low-privileged attacker with network access to perform unauthorized data manipulation, access sensitive information, or cause a partial denial of service. The attack requires user interaction and is characterized by a scope change, potentially impacting other integrated products.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83096

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83101, CVE-2026-83106.

CVE-2026-83101

Oracle Fusion Middleware Oracle Forms component (Forms Services) contains a vulnerability that allows an unauthenticated, network-adjacent attacker to achieve full takeover of the Oracle Forms application via HTTP requests. The vulnerability is difficult to exploit but results in high impact to confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83101

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83106.

CVE-2026-83102

CVE-2026-83102 is a vulnerability in the Forms Services component of Oracle Fusion Middleware's Oracle Forms. The vulnerability allows an unauthenticated, remote attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data. Exploitation requires high complexity and impacts the confidentiality and integrity of the affected Oracle Forms environment.

Affected products:

  • Oracle Forms (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83102

Related in this roundup: CVE-2026-83094.

CVE-2026-83106

CVE-2026-83106 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware (specifically Forms Services, C/S, Charmode). A low-privileged attacker with network access via HTTP can exploit this flaw to achieve a full takeover of the Oracle Forms application. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant impacts on confidentiality, integrity, and availability.

Affected products:

  • Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83106

Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101.

CVE-2026-83110

CVE-2026-83110 is a critical vulnerability in the Audience component of Oracle Marketing within Oracle E-Business Suite. The vulnerability allows an unauthenticated, network-adjacent attacker to gain unauthorized access to critical data through HTTP requests. It is rated with a CVSS score of 7.5, focusing on information disclosure (confidentiality impact) without requiring authentication or user interaction.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83110

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83115, CVE-2026-83117.

CVE-2026-83111

CVE-2026-83111 is a vulnerability in the Oracle Partner Management component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the component. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, and features a scope change impacting additional products within the suite.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83111

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83112

CVE-2026-83112 is a vulnerability within the Oracle Lease and Finance Management component of the Oracle E-Business Suite. The flaw is remotely exploitable over HTTP by a high-privileged attacker, potentially leading to a full system takeover. The vulnerability carries a CVSS 3.1 base score of 7.2.

Affected products:

  • Oracle E-Business Suite (12.2.7-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83112

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83113

CVE-2026-83113 is a vulnerability in the Oracle Quality component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by low-privileged attackers. Successful exploitation allows unauthorized access, modification, or deletion of critical data within the Oracle Quality module.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83113

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83114, CVE-2026-83116.

CVE-2026-83114

Oracle Quality, a component of Oracle E-Business Suite versions 12.2.3 through 12.2.15, contains a vulnerability that allows a low-privileged, network-adjacent attacker to achieve full takeover of the application via HTTP. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant impact on confidentiality, integrity, and availability.

Affected products:

  • Oracle E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83114

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83116.

CVE-2026-83115

CVE-2026-83115 is an unauthenticated, network-exploitable vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (RapidClone). The vulnerability allows a remote attacker to gain unauthorized access to critical data or complete access to all data managed by the Oracle Applications Manager, posing a significant confidentiality risk.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83115

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83117.

CVE-2026-83116

CVE-2026-83116 is a vulnerability in the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite. The vulnerability is network-exploitable via HTTP by low-privileged attackers. It exhibits a scope change and allows for unauthorized access to critical data, resulting in a CVSS 3.1 base score of 7.7. The vulnerability impacts confidentiality but does not affect integrity or availability.

Affected products:

  • Oracle E-Business Suite (12.2.5-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83116

Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114.

CVE-2026-83117

CVE-2026-83117 is a vulnerability in the AD Utilities component of Oracle E-Business Suite Applications DBA, rated with a CVSS score of 7.2. The vulnerability is easily exploitable over the network via HTTP by a high-privileged attacker, potentially leading to a full takeover of the Applications DBA component.

Affected products:

  • E-Business Suite (12.2.3-12.2.15)

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83117

Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115.