Oracle Security Updates - September 2026
Roundup of Oracle security advisories published in September 2026.
CVE search metadata
CVE search record: CVE-2026-70748. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-70756. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-70757. Severity: critical. CVSS: 9.8. KEV: no. Product: WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-70913. Severity: critical. CVSS: 9.8. KEV: no. Product: Identity Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-71133. Severity: critical. CVSS: 10.0. KEV: no. Product: Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-71163. Severity: critical. CVSS: 9.9. KEV: no. Product: Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73940. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73944. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73945. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73946. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73947. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73948. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73950. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73952. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73953. Severity: critical. CVSS: 9.8. KEV: no. Product: WebCenter Portal (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73956. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73957. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73961. Severity: critical. CVSS: 9.8. KEV: no. Product: JDeveloper (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73962. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73963. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82994. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82995. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82997. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82998. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82999. Severity: critical. CVSS: 9.9. KEV: no. Product: Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83000. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83001. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83006. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83020. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83021. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83027. Severity: critical. CVSS: 9.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83029. Severity: critical. CVSS: 9.6. KEV: no. Product: Managed File Transfer (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83031. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83035. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83036. Severity: critical. CVSS: 9.8. KEV: no. Product: WebCenter Sites (12.2.1.4.0, 14.1.2.0.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83037. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83038. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83039. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83040. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83042. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83043. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83054. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83055. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83056. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83057. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83058. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83059. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83060. Severity: critical. CVSS: 9.8. KEV: no. Product: Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83061. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83062. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83064. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83066. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83094. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83095. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83098. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83099. Severity: critical. CVSS: 10.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83100. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83103. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83104. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83105. Severity: critical. CVSS: 9.0. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83107. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83108. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83149. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83151. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83154. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83196. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83197. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83201. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83202. Severity: critical. CVSS: 9.1. KEV: no. Product: Siebel CRM (17.0-26.7). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83229. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83232. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83260. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83261. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83268. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83269. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83282. Severity: critical. CVSS: 9.9. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83283. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83327. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83339. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83355. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83452. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83462. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87128. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87129. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87170. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87173. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87175. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87184. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87186. Severity: critical. CVSS: 9.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87188. Severity: critical. CVSS: 9.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87189. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87214. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87217. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-87223. Severity: critical. CVSS: 9.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-70915. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73926. Severity: high. CVSS: 8.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73941. Severity: high. CVSS: 8.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73942. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73943. Severity: high. CVSS: 7.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73949. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73951. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73954. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73955. Severity: high. CVSS: 7.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-73966. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82992. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82993. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-82996. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83002. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83004. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83005. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83007. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83008. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83009. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83010. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83012. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83014. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83016. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83019. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83024. Severity: high. CVSS: 7.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83026. Severity: high. CVSS: 8.3. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83028. Severity: high. CVSS: 7.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83034. Severity: high. CVSS: 7.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83045. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83048. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83049. Severity: high. CVSS: 8.5. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83050. Severity: high. CVSS: 7.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83052. Severity: high. CVSS: 7.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83053. Severity: high. CVSS: 8.8. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83068. Severity: high. CVSS: 7.7. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83070. Severity: high. CVSS: 7.7. KEV: no. Product: PeopleSoft Enterprise PRTL Interaction Hub (9.1). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83072. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83074. Severity: high. CVSS: 8.6. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83101. Severity: high. CVSS: 8.1. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83112. Severity: high. CVSS: 7.2. KEV: no. Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
CVE search record: CVE-2026-83113. Severity: high. CVSS: 7.1. KEV: no. Product: Oracle E-Business Suite (12.2.3-12.2.15). Brief: Oracle Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-oracle-security-updates/
What's new
This roundup covers 191 Oracle security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Agile PLM, Application Testing Suite, BI Publisher, Database Server, E-Business Suite, Forms Services, Fusion Middleware, Hyperion Data Relationship Management, Hyperion Financial Management, Identity Manager, Identity Manager Connector, Internet Directory, JDeveloper, Managed File Transfer, Oracle Access Manager, Oracle BI Publisher, Oracle Banking Branch, Oracle Banking Corporate Lending, Oracle Business Intelligence Enterprise Edition, Oracle Data Integrator, Oracle E-Business Suite, Oracle Enterprise Manager for Oracle Database, Oracle Field Service, Oracle Forms, Oracle Fusion Middleware, Oracle Fusion Middleware Control, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle Platform Security for Java, Oracle WebCenter Portal, PeopleSoft Enterprise PRTL Interaction Hub, PeopleSoft Enterprise PeopleTools, Service Delivery Platform, Siebel CRM, Siebel CRM Cloud Applications, Siebel CRM Deployment, WebCenter Enterprise Capture, WebCenter Portal, WebCenter Sites, WebLogic Server.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-70748 | WebLogic Server | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70756 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70757 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-70913 | Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-71133 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-71163 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-73940 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73944 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-73945 | n/a | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-73946 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-73947 | Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73948 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-73950 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73952 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-73953 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73956 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73957 | n/a | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-73961 | JDeveloper (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-73962 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-73963 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-82994 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-82995 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-82997 | Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-82998 | Fusion Middleware (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-82999 | Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83000 | Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83001 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83006 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83020 | Fusion Middleware (12.2.1.4.0, 14.1.2.0.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-83021 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-83027 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-83029 | Managed File Transfer (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-83031 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83035 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83036 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83037 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83038 | WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83039 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83040 | n/a | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-83042 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83043 | n/a | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-83054 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83055 | n/a | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83056 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83057 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83058 | n/a | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83059 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-83060 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83061 | Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83062 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83064 | n/a | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83066 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83094 | Oracle Forms (12.2.1.19.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83095 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83098 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83099 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-83100 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83103 | Forms Services (12.2.1.19.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83104 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83105 | n/a | Critical | 9.0 | no | NVD (authoritative) | |
| CVE-2026-83107 | Oracle Fusion Middleware | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83108 | Oracle Fusion Middleware | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83149 | Application Testing Suite (13.3.0.1) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83151 | Fusion Middleware (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83154 | Siebel CRM (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83196 | Siebel CRM Deployment (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83197 | Siebel CRM (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83201 | Siebel CRM (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83202 | Siebel CRM (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83229 | Siebel CRM (17.0-26.7) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83232 | Oracle Data Integrator (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83260 | Agile PLM (9.3.6) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83261 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83268 | BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-83269 | Oracle BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83282 | Oracle Business Intelligence Enterprise Edition (12.2.1.4.0) | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-83283 | Oracle Business Intelligence Enterprise Edition (12.2.1.4.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83327 | E-Business Suite (12.2.3-12.2.15) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83339 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83355 | n/a | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83452 | Oracle E-Business Suite (12.2.3-12.2.15) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-83462 | E-Business Suite (12.2.3-12.2.15) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-87128 | Hyperion Data Relationship Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87129 | Hyperion Data Relationship Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87170 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87172 | Hyperion Financial Management (11.2.26.0.000) | no | NVD (authoritative) | |||
| CVE-2026-87173 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87175 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87176 | Hyperion Financial Management (11.2.26.0.000) | no | NVD (authoritative) | |||
| CVE-2026-87184 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-87186 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-87188 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-87189 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87214 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87217 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87223 | Hyperion Financial Management (11.2.26.0.000) | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-87230 | Hyperion Financial Management (11.2.26.0.000) | no | NVD (authoritative) | |||
| CVE-2026-70915 | Identity Manager (12.2.1.4.0, 14.1.2.1.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-71047 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-73926 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | High | 8.7 | no | NVD (authoritative) | |
| CVE-2026-73941 | n/a | High | 8.6 | no | NVD (authoritative) | |
| CVE-2026-73942 | Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-73943 | Identity Manager (12.2.1.4.0, 14.1.2.1.0) | High | 7.6 | no | NVD (authoritative) | |
| CVE-2026-73949 | n/a | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-73951 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-73954 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-73955 | n/a | High | 7.3 | no | NVD (authoritative) | |
| CVE-2026-73958 | Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-73959 | Oracle WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-73960 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | no | NVD (authoritative) | |||
| CVE-2026-73966 | Siebel CRM (17.0-26.7) | High | 7.2 | no | NVD (authoritative) | |
| CVE-2026-82992 | Siebel CRM (17.0-26.7) | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-82993 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | High | 8.5 | no | NVD (authoritative) | |
| CVE-2026-82996 | n/a | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-83002 | Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0) | High | 8.5 | no | NVD (authoritative) | |
| CVE-2026-83003 | n/a | no | NVD (authoritative) | |||
| CVE-2026-83004 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 7.2 | no | NVD (authoritative) | |
| CVE-2026-83005 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-83007 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 8.5 | no | NVD (authoritative) | |
| CVE-2026-83008 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-83009 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-83010 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-83011 | Oracle Platform Security for Java (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83012 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | High | 7.7 | no | NVD (authoritative) | |
| CVE-2026-83013 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83014 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-83015 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | no | NVD (authoritative) | |||
| CVE-2026-83016 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | High | 7.2 | no | NVD (authoritative) | |
| CVE-2026-83017 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | no | NVD (authoritative) | |||
| CVE-2026-83018 | n/a | no | NVD (authoritative) | |||
| CVE-2026-83019 | PeopleSoft Enterprise PeopleTools (8.61-8.63) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-83022 | WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83023 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-83024 | n/a | High | 7.8 | no | NVD (authoritative) | |
| CVE-2026-83025 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-83026 | Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | High | 8.3 | no | NVD (authoritative) | |
| CVE-2026-83028 | Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0) | High | 7.5 | no | NVD (authoritative) | |
| CVE-2026-83030 | Managed File Transfer (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83032 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83033 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83034 | WebCenter Sites (12.2.1.4.0, 14.1.2.0.0) | High | 7.5 | no | NVD (authoritative) | |
| CVE-2026-83041 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83044 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83045 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 8.5 | no | NVD (authoritative) | |
| CVE-2026-83046 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83047 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83048 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 7.7 | no | NVD (authoritative) | |
| CVE-2026-83049 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 8.5 | no | NVD (authoritative) | |
| CVE-2026-83050 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 7.1 | no | NVD (authoritative) | |
| CVE-2026-83051 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83052 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83053 | WebCenter Portal (12.2.1.4.0, 14.1.2.0.0) | High | 8.8 | no | NVD (authoritative) | |
| CVE-2026-83063 | Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0) | no | NVD (authoritative) | |||
| CVE-2026-83065 | Oracle WebCenter Portal (14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83067 | JDeveloper (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83068 | Oracle Enterprise Manager for Oracle Database (24.1) | no | NVD (authoritative) | |||
| CVE-2026-83069 | Oracle Fusion Middleware Control (12.2.1.4.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83070 | PeopleSoft Enterprise PRTL Interaction Hub (9.1) | High | 7.7 | no | NVD (authoritative) | |
| CVE-2026-83071 | Oracle Business Intelligence Enterprise Edition (8.2.0.0.0, 26.01.0.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83072 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83073 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83074 | Siebel CRM Cloud Applications (22.3-26.7) | High | 8.6 | no | NVD (authoritative) | |
| CVE-2026-83075 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83078 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83079 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83080 | Oracle Banking Branch (14.5.0.0.0-14.9.0.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83081 | Oracle Banking Corporate Lending (14.5.0.0.0-14.9.0.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83082 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83083 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83084 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83085 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83086 | n/a | no | NVD (authoritative) | |||
| CVE-2026-83087 | Siebel CRM Cloud Applications (22.3-26.7) | no | NVD (authoritative) | |||
| CVE-2026-83088 | Database Server (23.4.0-23.26.3) | no | NVD (authoritative) | |||
| CVE-2026-83089 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83090 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83091 | Oracle Field Service (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83092 | Oracle Field Service (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83093 | n/a | no | NVD (authoritative) | |||
| CVE-2026-83096 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83101 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | High | 8.1 | no | NVD (authoritative) | |
| CVE-2026-83102 | Oracle Forms (12.2.1.19.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83106 | Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0) | no | NVD (authoritative) | |||
| CVE-2026-83110 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83111 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83112 | Oracle E-Business Suite (12.2.7-12.2.15) | High | 7.2 | no | NVD (authoritative) | |
| CVE-2026-83113 | Oracle E-Business Suite (12.2.3-12.2.15) | High | 7.1 | no | NVD (authoritative) | |
| CVE-2026-83114 | Oracle E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83115 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83116 | Oracle E-Business Suite (12.2.5-12.2.15) | no | NVD (authoritative) | |||
| CVE-2026-83117 | E-Business Suite (12.2.3-12.2.15) | no | NVD (authoritative) |
CVE-2026-70748
Oracle WebLogic Server, specifically within the Core component, is vulnerable to an unauthenticated remote code execution exploit via T3 or IIOP protocols. Attackers can leverage this vulnerability to gain complete control over the affected server. The vulnerability is network-exploitable with low attack complexity, carrying a CVSS base score of 9.8.
Affected products:
- WebLogic Server
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70748
Related in this roundup: CVE-2026-70756, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038.
CVE-2026-70756
CVE-2026-70756 is a critical vulnerability in the Core component of Oracle WebLogic Server. It allows an unauthenticated attacker with network access to exploit the T3 or IIOP protocols to achieve a full takeover of the server. With a CVSS score of 9.8, this flaw impacts confidentiality, integrity, and availability, and it is considered easily exploitable without user interaction.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70756
Related in this roundup: CVE-2026-70748, CVE-2026-70757, CVE-2026-83021, CVE-2026-83038.
CVE-2026-70757
CVE-2026-70757 is a critical vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker to take control of the server over the network via the T3 or IIOP protocols. The flaw is easily exploitable and carries a CVSS 3.1 base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70757
Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-83021, CVE-2026-83038.
CVE-2026-70913
CVE-2026-70913 is a critical vulnerability in the Core component of Oracle Identity Manager within Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. With a CVSS base score of 9.8, this vulnerability poses a severe risk to confidentiality, integrity, and availability.
Affected products:
- Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70913
Related in this roundup: CVE-2026-70915, CVE-2026-73943.
CVE-2026-71133
CVE-2026-71133 is a critical vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. An unauthenticated attacker with network access can exploit this flaw via HTTP to achieve full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 10.0 and allows for a scope change, potentially impacting other integrated products.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71133
Related in this roundup: CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-71163
CVE-2026-71163 is a critical vulnerability affecting the Authentication Engine component of Oracle Access Manager in Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can exploit this flaw to perform unauthorized data modification, deletion, and access, as well as trigger a partial denial of service. The vulnerability supports scope change (S:C), significantly impacting the security posture of the affected environment.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71163
Related in this roundup: CVE-2026-71133, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73940
CVE-2026-73940 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker to gain unauthorized control over the system via T3 or IIOP network protocols. With a CVSS base score of 9.8, this vulnerability poses a severe risk, as successful exploitation results in full compromise of the application's confidentiality, integrity, and availability.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73940
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73944
CVE-2026-73944 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to or modify critical data within the Oracle Access Manager environment via HTTP requests. This issue carries a CVSS 3.1 base score of 9.1 and represents a significant risk to data confidentiality and integrity.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73944
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73945
CVE-2026-73945 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this via HTTP to achieve a full takeover of the Oracle Access Manager instance, potentially affecting other products due to a scope change. The vulnerability carries a CVSS base score of 9.9 and impacts confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73945
CVE-2026-73946
CVE-2026-73946 is a high-severity vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. An attacker with high privileges can exploit this vulnerability over HTTP to achieve a full takeover of the Oracle Access Manager service, with potential for scope change impacting additional connected products. The vulnerability has a CVSS 3.1 base score of 9.1.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73946
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73947
A critical vulnerability exists in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the target system, resulting in a complete takeover. Given the high CVSS base score of 9.8, the vulnerability is easily exploitable without user interaction.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73947
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73948
CVE-2026-73948 is a critical vulnerability in Oracle WebCenter Portal (part of Oracle Fusion Middleware) that allows a low-privileged, network-based attacker to gain full control of the application. The vulnerability features a scope change (S:C), indicating that successful exploitation can impact other connected products and infrastructure. Detection engineers should monitor for unauthorized HTTP traffic targeting the Composer component of the WebCenter Portal, as successful exploitation results in total system compromise with high confidentiality, integrity, and availability impact.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73948
Related in this roundup: CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-73950
Oracle Access Manager, a component of Oracle Fusion Middleware, contains a critical vulnerability in its Authentication Engine that allows an unauthenticated, remote attacker to gain full control of the application via HTTP. The vulnerability is highly exploitable, requiring no user interaction or elevated privileges, resulting in a CVSS score of 9.8.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73950
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73952
CVE-2026-73952 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. The flaw allows an unauthenticated attacker with network access to leverage HTTP requests to achieve unauthorized creation, deletion, or modification of critical data within the application. With a CVSS base score of 9.1, it represents a significant risk to data confidentiality and integrity, necessitating immediate patching of affected 12.2.1.4.0 and 14.1.2.0.0 versions.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73952
Related in this roundup: CVE-2026-73948, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-73953
CVE-2026-73953 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. The flaw is remotely exploitable without authentication, allowing an attacker with network access to achieve full system takeover via HTTP requests. With a CVSS base score of 9.8, it represents a high risk for complete loss of confidentiality, integrity, and availability of the affected portal instance.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73953
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-73956
CVE-2026-73956 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by an unauthenticated attacker, potentially leading to a full takeover of the affected product. With a CVSS 3.1 base score of 9.8, this flaw impacts confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73956
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-73957
CVE-2026-73957 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. It allows an unauthenticated, network-adjacent attacker to perform unauthorized data manipulation or access through a specifically crafted HTTP request that requires user interaction. The vulnerability has a scope change impact, potentially affecting other integrated products.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73957
CVE-2026-73961
CVE-2026-73961 is a critical vulnerability in the ADF Faces component of Oracle JDeveloper. The flaw allows an unauthenticated remote attacker with network access to achieve a complete takeover of the application via HTTP. Given the CVSS score of 9.8 and the lack of required authentication or user interaction, this vulnerability presents a significant risk for remote code execution.
Affected products:
- JDeveloper (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73961
Related in this roundup: CVE-2026-83067.
CVE-2026-73962
CVE-2026-73962 is a critical vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware. A low-privileged attacker with network access over HTTPS can exploit this flaw to bypass security controls, resulting in unauthorized access to, creation, deletion, or modification of critical data within the application. The vulnerability carries a CVSS score of 9.6 and involves a scope change, meaning it can impact other integrated products.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73962
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73963
Oracle WebCenter Portal, a component of Oracle Fusion Middleware, contains a critical vulnerability in its Portlet Services that allows unauthenticated attackers to compromise the application via network access over HTTP. Successful exploitation can lead to a full takeover of the Oracle WebCenter Portal, with high impact to confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73963
CVE-2026-82994
CVE-2026-82994 is a critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. An unauthenticated attacker can exploit this vulnerability over a network via LDAP to achieve a full takeover of the application, impacting confidentiality, integrity, and availability with a CVSS 3.1 base score of 9.8.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82994
CVE-2026-82995
CVE-2026-82995 is a critical RCE vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. The vulnerability allows an unauthenticated attacker with network access to exploit the system via SOAP requests, potentially leading to a full takeover of the affected service.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82995
CVE-2026-82997
CVE-2026-82997 is a critical RCE vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. A low-privileged attacker can exploit this via network access using T3 or IIOP protocols to achieve full system takeover. The vulnerability allows for scope change, potentially impacting other products integrated with the affected platform.
Affected products:
- Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82997
Related in this roundup: CVE-2026-82999, CVE-2026-83000.
CVE-2026-82998
CVE-2026-82998 is a critical RCE vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. An attacker with low privileges can exploit the vulnerability via network protocols T3 or IIOP to achieve a full takeover of the platform. Due to the scope change, successful exploitation may also impact additional products within the environment.
Affected products:
- Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82998
Related in this roundup: CVE-2026-83020, CVE-2026-83151.
CVE-2026-82999
CVE-2026-82999 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. A low-privileged attacker with network access can exploit this vulnerability via HTTP to achieve full takeover of the platform. The vulnerability is characterized by a scope change, allowing the compromise to impact additional products, and carries a CVSS base score of 9.9.
Affected products:
- Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82999
Related in this roundup: CVE-2026-82997, CVE-2026-83000.
CVE-2026-83000
CVE-2026-83000 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform. An unauthenticated attacker with network access can exploit this via HTTP to achieve full compromise of the platform. The vulnerability carries a CVSS base score of 9.8, indicating significant risks to confidentiality, integrity, and availability.
Affected products:
- Service Delivery Platform (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83000
Related in this roundup: CVE-2026-82997, CVE-2026-82999.
CVE-2026-83001
CVE-2026-83001 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP and allows a high-privileged attacker to achieve a complete takeover of the Oracle Access Manager product. The exploit carries a scope change, potentially impacting additional products beyond the primary target, with significant implications for confidentiality, integrity, and availability.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83001
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-73926, CVE-2026-73958, CVE-2026-83002.
CVE-2026-83006
CVE-2026-83006 is a high-severity, easily exploitable vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A high-privileged attacker with network access can leverage HTTP requests to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 9.1 and involves a scope change, potentially impacting additional products within the environment.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83006
Related in this roundup: CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83020
CVE-2026-83020 is a critical vulnerability in the Centralized Thirdparty Jars component of Oracle Fusion Middleware's Platform Security for Java. It allows an unauthenticated, remote attacker to achieve full system takeover via HTTP. Given the scope change impact and maximum CVSS score of 10.0, this represents a severe risk that likely facilitates remote code execution or complete compromise of the underlying platform.
Affected products:
- Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83020
Related in this roundup: CVE-2026-82998, CVE-2026-83151.
CVE-2026-83021
CVE-2026-83021 is a critical vulnerability in the Web Container component of Oracle WebLogic Server. The flaw allows an unauthenticated attacker with network access to achieve complete compromise (takeover) of the server via HTTP. Due to the scope change impact, the vulnerability can affect additional products in the environment, resulting in high confidentiality, integrity, and availability impacts.
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83021
Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83038.
CVE-2026-83027
CVE-2026-83027 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to information within the connector, due to an insecure design or implementation in the core component. The impact is elevated due to a scope change, potentially affecting broader integrated systems.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83027
Related in this roundup: CVE-2026-83023, CVE-2026-83025, CVE-2026-83028.
CVE-2026-83029
CVE-2026-83029 is a vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware. The vulnerability is network-exploitable over HTTP by low-privileged attackers. Successful exploitation allows for unauthorized modification, deletion, or access to critical data within the Managed File Transfer system, with potential for scope change impacting additional associated products.
Affected products:
- Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83029
Related in this roundup: CVE-2026-83030.
CVE-2026-83031
CVE-2026-83031 is a critical vulnerability affecting Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is network-exploitable over HTTP by low-privileged attackers and can lead to a full takeover of the application. Due to a scope change, successful exploitation may also impact additional products, resulting in complete compromise of confidentiality, integrity, and availability.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83031
Related in this roundup: CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.
CVE-2026-83035
A critical vulnerability exists in Oracle WebCenter Sites, part of the Oracle Fusion Middleware stack. The flaw allows an unauthenticated attacker with network access to achieve a full takeover of the application via HTTP. Given the CVSS score of 9.8 and the lack of authentication required, this vulnerability represents a high risk of complete system compromise.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83035
Related in this roundup: CVE-2026-83031, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.
CVE-2026-83036
CVE-2026-83036 is a critical, easily exploitable vulnerability in Oracle WebCenter Sites (part of Oracle Fusion Middleware). The flaw allows an unauthenticated remote attacker with network access via HTTP to fully compromise the target application, leading to a complete takeover. Given the CVSS score of 9.8, this represents a high-risk vector requiring immediate patching.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83036
Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.
CVE-2026-83037
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable to an unauthenticated, network-exploitable issue that allows a complete takeover of the application. The vulnerability carries a CVSS base score of 9.8, indicating critical impact on confidentiality, integrity, and availability, and can be exploited via HTTP without user interaction.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83037
Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83032, CVE-2026-83033, CVE-2026-83034.
CVE-2026-83038
Oracle WebLogic Server, specifically the TopLink Integration component, contains a critical vulnerability (CVE-2026-83038) that allows a low-privileged attacker with network access via HTTP to compromise the server. Successful exploitation results in a full system takeover and impacts additional products due to a scope change (CVSS 9.9).
Affected products:
- WebLogic Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83038
Related in this roundup: CVE-2026-70748, CVE-2026-70756, CVE-2026-70757, CVE-2026-83021.
CVE-2026-83039
CVE-2026-83039 is a critical vulnerability within the Composer component of Oracle WebCenter Portal. The flaw is remotely exploitable over HTTP by a low-privileged attacker, potentially leading to a full system takeover. The vulnerability carries a CVSS 3.1 score of 9.9 and involves a scope change that can impact integrated products, indicating a significant risk to confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83039
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83040
CVE-2026-83040 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal. It allows an unauthenticated attacker with network access to exploit the system via SOAP requests. The attack requires user interaction and can lead to a full system takeover and unauthorized access, with impacts extending to other products due to scope change.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83040
CVE-2026-83042
CVE-2026-83042 is a critical vulnerability in the OIM Legacy UI component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The vulnerability allows an unauthenticated attacker with network access via HTTP to perform a full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83042
Related in this roundup: CVE-2026-71047, CVE-2026-73942.
CVE-2026-83043
CVE-2026-83043 is a critical vulnerability in Oracle WebCenter Portal, part of the Oracle Fusion Middleware suite. It allows an unauthenticated attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability requires human interaction to succeed and results in a scope change, potentially impacting additional integrated products. It is highly exploitable, carrying a CVSS 3.1 base score of 9.6.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83043
CVE-2026-83054
Oracle Internet Directory within Oracle Fusion Middleware contains a critical vulnerability in the OID LDAP Server component. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve full system takeover. The vulnerability carries a CVSS base score of 9.8, indicating severe impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83054
Related in this roundup: CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83055
CVE-2026-83055 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. A low-privileged attacker with network access via the LDAP protocol can exploit this flaw to achieve a full takeover of the Oracle Internet Directory service. The vulnerability supports scope changes, potentially impacting other integrated products, and carries a CVSS base score of 9.9.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83055
CVE-2026-83056
Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 are vulnerable to a remote, easily exploitable vulnerability in the LDAP server component. A low-privileged attacker with network access can leverage this flaw to achieve a full takeover of the directory service, resulting in a complete compromise of confidentiality, integrity, and availability with scope change impact.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83056
Related in this roundup: CVE-2026-83054, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83057
A critical vulnerability (CVSS 9.9) exists in the OID LDAP Server component of Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is remotely exploitable over the network by a low-privileged attacker using the LDAP protocol. Successful exploitation allows for a full takeover of the Oracle Internet Directory and can result in a scope change, potentially impacting other integrated Oracle Fusion Middleware products.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83057
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83058
CVE-2026-83058 is a critical vulnerability in the OID LDAP Server component of Oracle Internet Directory. An attacker with low privileges and network access can exploit this flaw via LDAP to achieve a full system takeover, with potential for scope change impacting broader infrastructure. The vulnerability scores 9.9 on the CVSS scale, indicating high risk to confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83058
CVE-2026-83059
CVE-2026-83059 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is network-exploitable by an unauthenticated attacker via the LDAP protocol. Successful exploitation allows for the full takeover of the directory service and can result in a scope change, potentially impacting other integrated products with a CVSS 3.1 base score of 10.0.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83059
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83060
CVE-2026-83060 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over the network via LDAP to achieve full system takeover, posing a severe risk to confidentiality, integrity, and availability.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83060
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83062, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83061
CVE-2026-83061 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. The flaw is remotely exploitable without authentication via the LDAP protocol, allowing an attacker to achieve a full takeover of the directory service. The vulnerability impacts the confidentiality, integrity, and availability of the affected system.
Affected products:
- Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83061
CVE-2026-83062
CVE-2026-83062 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the OID LDAP server. With a CVSS score of 9.8, this exploit targets the LDAP service, impacting confidentiality, integrity, and availability without requiring user interaction.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83062
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83066, CVE-2026-83063.
CVE-2026-83064
Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 contains a vulnerability in the Runtime Tools component that allows a high-privileged attacker with network access via HTTP to perform a full system takeover. The vulnerability has a CVSS 3.1 base score of 9.1 and supports a scope change, meaning exploitation can lead to impact beyond the vulnerable product itself.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83064
CVE-2026-83066
CVE-2026-83066 is a critical vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware. An unauthenticated attacker can exploit this via network access using T3 or IIOP protocols to achieve full system takeover. The vulnerability carries a CVSS 3.1 base score of 9.8.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83066
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83063.
CVE-2026-83094
Oracle Forms in Oracle Fusion Middleware contains a critical vulnerability in the Forms Services component that allows an unauthenticated, network-adjacent attacker to achieve a full system takeover. The vulnerability is highly exploitable via HTTP and carries a CVSS base score of 9.8, indicating severe impacts on confidentiality, integrity, and availability.
Affected products:
- Oracle Forms (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83094
Related in this roundup: CVE-2026-83102.
CVE-2026-83095
CVE-2026-83095 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker to gain full control over the Forms Services through HTTP-based network access, leading to a complete takeover of the service. The vulnerability carries a CVSS base score of 9.8, indicating severe confidentiality, integrity, and availability impact.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83095
CVE-2026-83098
CVE-2026-83098 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to achieve a full system takeover via HTTP requests. It is rated with a CVSS 3.1 base score of 9.8, indicating high confidentiality, integrity, and availability impacts.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83098
CVE-2026-83099
CVE-2026-83099 is a critical vulnerability in Oracle Fusion Middleware, specifically within the Oracle Forms component. The flaw allows an unauthenticated remote attacker with network access to achieve full takeover of the Oracle Forms service via HTTP. Due to its impact on Confidentiality, Integrity, and Availability and the potential for scope change, it has been assigned a CVSS v3.1 base score of 10.0.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83099
Related in this roundup: CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83100
CVE-2026-83100 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware. It allows an unauthenticated, network-adjacent attacker to perform a complete takeover of the affected service via HTTP. Due to the lack of required authentication and low attack complexity, this flaw poses a severe risk of full system compromise.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83100
Related in this roundup: CVE-2026-83099, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83103
Oracle Forms in Fusion Middleware is vulnerable to a remote, easily exploitable flaw that allows a highly privileged attacker with network access via HTTP to fully compromise the service. The vulnerability impacts confidentiality, integrity, and availability, and because of a scope change, it can also lead to the compromise of additional products within the environment.
Affected products:
- Forms Services (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83103
CVE-2026-83104
CVE-2026-83104 is a high-severity, easily exploitable vulnerability in the Oracle Forms component of Oracle Fusion Middleware. An unauthenticated attacker with network access via TCP can compromise the service, leading to unauthorized read, write, and deletion access to critical data managed by the application.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83104
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83105
CVE-2026-83105 is a high-severity vulnerability in the Oracle Forms component of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can exploit this flaw to achieve full takeover of the Forms Services. The vulnerability has a scope change (S:C) impact, meaning successful exploitation can compromise the integrity, confidentiality, and availability of other connected systems.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83105
CVE-2026-83107
CVE-2026-83107 is a critical vulnerability in Oracle Fusion Middleware's Forms Services component. It allows a high-privileged attacker with network access via HTTP to perform an unauthorized takeover of the Oracle Forms product. Due to the nature of the flaw, it allows for scope change, potentially impacting other integrated products. Successful exploitation results in full compromise of Confidentiality, Integrity, and Availability.
Affected products:
- Oracle Fusion Middleware
- Oracle Forms (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83107
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83108
CVE-2026-83108 is a critical vulnerability in Oracle Fusion Middleware (specifically Oracle Forms Services). The flaw allows an unauthenticated, network-adjacent attacker to compromise the service via HTTP requests. Successful exploitation grants the attacker full control over the affected Oracle Forms instance, impacting confidentiality, integrity, and availability with a CVSS 3.1 base score of 9.8. Affected versions include 12.2.1.19.0 and 14.1.2.0.0.
Affected products:
- Oracle Fusion Middleware
- Oracle Forms
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83108
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83096, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83149
CVE-2026-83149 is a critical vulnerability in Oracle Application Testing Suite version 13.3.0.1 that allows an authenticated, low-privileged attacker with 'Test Manager for Web Apps' permissions to perform unauthorized data access, modification, and partial denial of service. The vulnerability supports scope changes, meaning it can facilitate impacts beyond the initial application. It is exploitable via HTTP over the network with low attack complexity.
Affected products:
- Application Testing Suite (13.3.0.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83149
CVE-2026-83151
CVE-2026-83151 is a critical vulnerability in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. The flaw is remotely exploitable without authentication via SOAP requests, allowing an attacker to achieve a full system takeover. Given the CVSS 3.1 score of 9.8, detection engineers should monitor for unauthorized or malformed SOAP traffic directed at the Service Delivery Platform component.
Affected products:
- Fusion Middleware (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83151
Related in this roundup: CVE-2026-82998, CVE-2026-83020.
CVE-2026-83154
CVE-2026-83154 is a critical vulnerability in the Open UI component of Oracle Siebel CRM versions 17.0 through 26.7. An unauthenticated, remote attacker can exploit the vulnerability via SOAP requests to perform unauthorized read, write, or delete operations on critical system data, resulting in significant impacts to confidentiality and integrity.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83154
Related in this roundup: CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.
CVE-2026-83196
CVE-2026-83196 is a high-severity vulnerability within the Server Infrastructure component of Oracle Siebel CRM Deployment, affecting versions 17.0 through 26.7. The vulnerability is network-exploitable via HTTP by an attacker with high privileges, potentially leading to a full system compromise with a scope change impact on other products.
Affected products:
- Siebel CRM Deployment (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83196
CVE-2026-83197
CVE-2026-83197 is a critical vulnerability in the Financial Accounts component of Oracle Siebel CRM Financial Services. The flaw allows unauthenticated remote attackers to exploit the system over HTTP, leading to unauthorized access to critical data and potential denial-of-service (DOS) conditions through system crashes. The vulnerability is characterized by high confidentiality and availability impacts.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83197
Related in this roundup: CVE-2026-83154, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.
CVE-2026-83201
CVE-2026-83201 is a critical vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment. The flaw allows an unauthenticated, network-adjacent attacker to perform unauthorized creation, modification, or deletion of critical data, as well as gain unauthorized access to data via HTTP, due to a lack of authentication requirements.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83201
Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.
CVE-2026-83202
CVE-2026-83202 is a critical vulnerability in the Server Infrastructure component of Oracle Siebel CRM versions 17.0 through 26.7. An unauthenticated attacker can exploit this via HTTP network access to gain unauthorized access to or modify critical data within the Siebel CRM Deployment. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting its high impact on confidentiality and integrity.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83202
Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83229, CVE-2026-73966, CVE-2026-82992.
CVE-2026-83229
CVE-2026-83229 is a critical vulnerability in the Siebel Management Console component of Oracle Siebel CRM versions 17.0 through 26.7. An attacker with high privileges can exploit this vulnerability over HTTP to achieve a full system compromise. The vulnerability is characterized by a high impact on confidentiality, integrity, and availability, and permits scope change, potentially affecting integrated products beyond the immediate deployment.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83229
Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-73966, CVE-2026-82992.
CVE-2026-83232
CVE-2026-83232 is a critical vulnerability in the Console and Repository Explorer components of Oracle Data Integrator within Oracle Fusion Middleware. An unauthenticated attacker can exploit this flaw over the network via HTTP to achieve full compromise of the application, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle Data Integrator (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83232
CVE-2026-83260
CVE-2026-83260 is a critical vulnerability in the Event Java PX component of Oracle Agile PLM version 9.3.6. The flaw is remotely exploitable over the network via T3 or IIOP protocols by a high-privileged attacker, potentially leading to a full system takeover and impacting other integrated products due to scope change.
Affected products:
- Agile PLM (9.3.6)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83260
CVE-2026-83261
Oracle Product Lifecycle Analytics version 3.6.1 contains a critical vulnerability that allows an unauthenticated remote attacker to gain full control of the application via HTTP. With a CVSS score of 9.8, the flaw permits complete compromise of confidentiality, integrity, and availability, likely indicating an RCE or similar high-impact vulnerability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83261
CVE-2026-83268
CVE-2026-83268 is a critical vulnerability in Oracle BI Publisher within Oracle Analytics, specifically involving the BI Platform Security component. The flaw is remotely exploitable over HTTP by a high-privileged attacker and allows for a full takeover of the product. The vulnerability involves a change of scope, potentially impacting additional products integrated with the BI Publisher environment.
Affected products:
- BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83268
CVE-2026-83269
CVE-2026-83269 is a critical vulnerability in the BI Platform Security component of Oracle BI Publisher. The flaw allows an unauthenticated attacker with network access to achieve a full system takeover via HTTP. Due to its high CVSS score of 9.8 and the lack of required authentication or user interaction, this vulnerability represents a significant risk for remote code execution or complete compromise of the affected analytics platform.
Affected products:
- Oracle BI Publisher (8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83269
CVE-2026-83282
CVE-2026-83282 is a critical vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition (version 12.2.1.4.0). The flaw is remotely exploitable over HTTP by a low-privileged attacker and allows for a complete takeover of the affected product with a significant impact on system confidentiality, integrity, and availability. Due to the scope change vector, successful exploitation may also affect additional integrated products.
Affected products:
- Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83282
Related in this roundup: CVE-2026-83283, CVE-2026-83071.
CVE-2026-83283
CVE-2026-83283 is a critical vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition version 12.2.1.4.0. The vulnerability allows an unauthenticated, remote attacker to gain full control of the application via HTTP. Given the high CVSS score of 9.8 and the ability for total system takeover, this represents a significant risk to the integrity and availability of the affected environment.
Affected products:
- Oracle Business Intelligence Enterprise Edition (12.2.1.4.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83283
Related in this roundup: CVE-2026-83282, CVE-2026-83071.
CVE-2026-83327
CVE-2026-83327 is a critical vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated, remote attacker to gain full control of the framework via SOAP requests, resulting in a complete compromise of confidentiality, integrity, and availability.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83327
Related in this roundup: CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83339
CVE-2026-83339 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The flaw allows an unauthenticated, network-adjacent attacker to achieve full system takeover via HTTP requests. Given the high CVSS score of 9.8 and the ease of exploitation, this represents a significant risk for remote code execution or unauthorized access to the application.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83339
Related in this roundup: CVE-2026-83006, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83355
CVE-2026-83355 is a critical vulnerability in the Oracle Enterprise Manager for Fusion Middleware component 'Metrics', allowing unauthenticated, network-adjacent attackers to achieve full system takeover via HTTP. With a CVSS 3.1 base score of 9.8, this flaw impacts confidentiality, integrity, and availability, and requires immediate patching of affected versions 13.5 and 24.1.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83355
CVE-2026-83452
CVE-2026-83452 is a critical vulnerability affecting the Oracle Document Management and Collaboration component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker to gain full control of the component via a network-accessible HTTP request, resulting in total compromise of confidentiality, integrity, and availability.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83452
Related in this roundup: CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83462
CVE-2026-83462 is a critical vulnerability in the Oracle Mobile Application Server component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw allows an unauthenticated attacker with network access via TCP to fully compromise the server, leading to impacts on confidentiality, integrity, and availability. With a CVSS base score of 9.8, the vulnerability is classified as easily exploitable due to the lack of required authentication or user interaction.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
- Mobile Application Server (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83462
Related in this roundup: CVE-2026-83327, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-87128
CVE-2026-87128 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability is easily exploitable by an unauthenticated attacker via HTTP, allowing for unauthorized read, write, or modification access to critical application data.
Affected products:
- Hyperion Data Relationship Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87128
Related in this roundup: CVE-2026-87129.
CVE-2026-87129
CVE-2026-87129 is a critical vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management version 11.2.26.0.000. The vulnerability allows an unauthenticated, network-adjacent attacker to exploit the application via HTTP. Successful exploitation grants unauthorized access to modify, delete, or create critical data, as well as read sensitive information, leading to high impacts on confidentiality and integrity.
Affected products:
- Hyperion Data Relationship Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87129
Related in this roundup: CVE-2026-87128.
CVE-2026-87170
CVE-2026-87170 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated remote attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data, as well as gain unauthorized access to data stored within the application.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87170
Related in this roundup: CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87172
CVE-2026-87172 is a critical vulnerability in Oracle Hyperion Financial Management (version 11.2.26.0.000) that allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP. The vulnerability has a CVSS 3.1 base score of 9.9 and possesses a scope change (S:C) characteristic, meaning exploitation can potentially impact other integrated products or infrastructure.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87172
Related in this roundup: CVE-2026-87170, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87173
CVE-2026-87173 is a critical security vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated, network-adjacent attacker to gain unauthorized access to or modify critical data via TCP, without requiring user interaction or elevated privileges.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87173
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87175
CVE-2026-87175 is an easily exploitable, unauthenticated vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An attacker with network access via TCP can leverage this vulnerability to gain unauthorized access to, modify, or delete critical data within the application, leading to severe impacts on confidentiality and integrity.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87175
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87176
CVE-2026-87176 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An unauthenticated attacker with network access via TCP can remotely compromise the application, leading to unauthorized modification, deletion, or full access to critical data. The vulnerability carries a CVSS 3.1 base score of 9.1.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87176
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87184
CVE-2026-87184 is a critical SQL injection vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is remotely exploitable without authentication, allowing an attacker to achieve full takeover of the application by compromising confidentiality, integrity, and availability.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87184
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87186
CVE-2026-87186 is a critical security vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated attacker with local network access (adjacent segment) to gain full control over the application. Given the high CVSS score of 9.6 and the potential for a full system takeover and cross-product impact (scope change), this represents a significant risk to enterprise financial systems.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87186
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87188
CVE-2026-87188 is a critical vulnerability in Oracle Hyperion Financial Management version 11.2.26.0.000, specifically within the Security component. The vulnerability allows an unauthenticated, remote attacker to compromise the application via HTTP. Given the CVSS score of 9.8 and the full impact on Confidentiality, Integrity, and Availability, this vulnerability facilitates a complete takeover of the affected product.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87188
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87189
CVE-2026-87189 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. An attacker with high privileges and network access via Oracle Net can exploit this vulnerability to achieve a full system takeover. The vulnerability carries a CVSS base score of 9.1 and supports scope changes, meaning successful exploitation can lead to a compromise of additional products within the environment.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87189
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87214
CVE-2026-87214 is a critical vulnerability in Oracle Hyperion Financial Management (v11.2.26.0.000) that allows a highly privileged attacker to achieve full system takeover via network-based HTTP exploitation. The vulnerability carries a CVSS 3.1 base score of 9.1 and involves a scope change, meaning exploitation can potentially impact other integrated products within the environment.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87214
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87217, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87217
CVE-2026-87217 is a critical, easily exploitable vulnerability in the Security component of Oracle Hyperion Financial Management (version 11.2.26.0.000). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application, resulting in the unauthorized creation, deletion, modification, or full access to sensitive data.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87217
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87223, CVE-2026-87230.
CVE-2026-87223
CVE-2026-87223 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The flaw allows an unauthenticated, network-adjacent attacker to exploit the system via HTTP, potentially leading to unauthorized modification or deletion of critical data, as well as causing a denial-of-service (DoS) condition.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87223
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87230.
CVE-2026-87230
CVE-2026-87230 is a critical, unauthenticated remote vulnerability in the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. The vulnerability is easily exploitable over the network via HTTP and allows for a scope change, enabling an attacker to achieve unauthorized access to, modification of, or deletion of critical data, resulting in a CVSS base score of 10.0.
Affected products:
- Hyperion Financial Management (11.2.26.0.000)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-87230
Related in this roundup: CVE-2026-87170, CVE-2026-87172, CVE-2026-87173, CVE-2026-87175, CVE-2026-87176, CVE-2026-87184, CVE-2026-87186, CVE-2026-87188, CVE-2026-87189, CVE-2026-87214, CVE-2026-87217, CVE-2026-87223.
CVE-2026-70915
CVE-2026-70915 is a critical vulnerability in the Core component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw allows a low-privileged, network-adjacent attacker to achieve full system takeover via T3 or IIOP protocols. The vulnerability carries a CVSS 3.1 base score of 8.8, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70915
Related in this roundup: CVE-2026-70913, CVE-2026-73943.
CVE-2026-71047
CVE-2026-71047 is a critical vulnerability within the Core component of Oracle Identity Manager in Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this via HTTP to achieve a full system takeover, impacting confidentiality, integrity, and availability. The vulnerability is rated with a CVSS score of 8.8 and is considered easily exploitable without requiring user interaction.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-71047
Related in this roundup: CVE-2026-83042, CVE-2026-73942.
CVE-2026-73926
Oracle Access Manager, a component of Oracle Fusion Middleware, contains a vulnerability in the Authentication Engine that allows a high-privileged attacker with network access to compromise the system. This vulnerability allows for unauthorized creation, deletion, or modification of critical data, as well as full unauthorized access to data stored within the product, with a scope change impacting other products as well.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73926
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73958, CVE-2026-83002.
CVE-2026-73941
CVE-2026-73941 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager. The flaw allows an unauthenticated, network-adjacent attacker to exploit the system via HTTP. Successful exploitation can lead to a scope change and unauthorized access to critical data managed by the application. The vulnerability carries a CVSS 3.1 base score of 8.6, specifically impacting confidentiality.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73941
CVE-2026-73942
CVE-2026-73942 is a critical vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware. An attacker with low-level network access can exploit this vulnerability via HTTP to achieve full takeover of the Identity Manager application. The vulnerability impacts confidentiality, integrity, and availability, and is considered easily exploitable by a low-privileged user without requiring user interaction.
Affected products:
- Oracle Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73942
Related in this roundup: CVE-2026-83042, CVE-2026-71047.
CVE-2026-73943
Oracle Identity Manager contains a vulnerability in the OIM Legacy UI component that allows a high-privileged attacker with network access via HTTP to perform unauthorized operations, including accessing or modifying critical data. The vulnerability has a scope change (S:C), indicating that successful exploitation can impact other products integrated with the identity manager.
Affected products:
- Identity Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73943
Related in this roundup: CVE-2026-70913, CVE-2026-70915.
CVE-2026-73949
CVE-2026-73949 is a high-severity vulnerability in Oracle WebCenter Portal's Portlet Services component, allowing low-privileged attackers with network access to perform a full system takeover via HTTP. The vulnerability has a CVSS score of 8.8 and impacts the confidentiality, integrity, and availability of the affected Oracle Fusion Middleware products.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73949
CVE-2026-73951
CVE-2026-73951 is a vulnerability in the Portlet Services component of Oracle WebCenter Portal that allows an unauthenticated, remote attacker with network access to achieve a full takeover of the application via HTTP. The vulnerability has a CVSS base score of 8.1, indicating high impacts on confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73951
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-73954
CVE-2026-73954 is a high-severity vulnerability in the Oracle PeopleSoft Enterprise PeopleTools component 'Business Interlink'. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to achieve a full system compromise. The vulnerability is characterized by a CVSS 3.1 base score of 8.1, indicating significant impacts on confidentiality, integrity, and availability.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73954
Related in this roundup: CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.
CVE-2026-73955
CVE-2026-73955 is a vulnerability in the Charting component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. A low-privileged attacker with network access can exploit this flaw via HTTP, requiring user interaction to succeed. The vulnerability allows for unauthorized access, creation, deletion, or modification of critical data within the PeopleSoft environment.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73955
CVE-2026-73958
CVE-2026-73958 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager. The flaw allows an unauthenticated attacker with network access via HTTP to potentially take over the affected service. The vulnerability is characterized as difficult to exploit and carries a CVSS 3.1 base score of 8.1, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73958
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-83002.
CVE-2026-73959
CVE-2026-73959 is a critical vulnerability in the Composer component of Oracle WebCenter Portal within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially allowing for a full takeover of the application. It carries a CVSS 3.1 base score of 8.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Oracle WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73959
Related in this roundup: CVE-2026-83065.
CVE-2026-73960
CVE-2026-73960 is a vulnerability in the Ren Server component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability allows an unauthenticated, network-adjacent attacker to perform a denial-of-service attack via HTTP, resulting in a system hang or repeatable crash.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73960
Related in this roundup: CVE-2026-73954, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.
CVE-2026-73966
A high-privileged remote code execution vulnerability exists in the Marketing component of Oracle Siebel CRM, allowing an attacker with network access via HTTP to fully compromise the product. The vulnerability is rated with a CVSS 3.1 base score of 7.2.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-73966
Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-82992.
CVE-2026-82992
CVE-2026-82992 is a high-severity vulnerability in the Installation component of Oracle Siebel CRM, affecting versions 17.0 through 26.7. The flaw allows a low-privileged authenticated user with local access to the deployment infrastructure to achieve a full takeover of the Siebel CRM Deployment component. The vulnerability is considered easily exploitable and impacts the confidentiality, integrity, and availability of the system.
Affected products:
- Siebel CRM (17.0-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82992
Related in this roundup: CVE-2026-83154, CVE-2026-83197, CVE-2026-83201, CVE-2026-83202, CVE-2026-83229, CVE-2026-73966.
CVE-2026-82993
CVE-2026-82993 is a vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve unauthorized access to, or modification of, critical data within the PeopleSoft environment. The vulnerability impacts the scope of the application, potentially affecting integrated systems as well.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82993
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.
CVE-2026-82996
CVE-2026-82996 is a vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. A low-privileged attacker with local logon access can exploit this flaw to gain unauthorized control (takeover) of the component, leading to full compromise of confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-82996
CVE-2026-83002
CVE-2026-83002 is a high-severity vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full takeover of the application. The vulnerability carries a CVSS 3.1 base score of 8.5 and impacts Confidentiality, Integrity, and Availability, with the potential for scope change affecting additional products.
Affected products:
- Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83002
Related in this roundup: CVE-2026-71133, CVE-2026-71163, CVE-2026-73940, CVE-2026-73944, CVE-2026-73946, CVE-2026-73947, CVE-2026-73950, CVE-2026-73962, CVE-2026-83001, CVE-2026-73926, CVE-2026-73958.
CVE-2026-83003
CVE-2026-83003 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this vulnerability via SOAP to gain unauthorized access to critical data or perform unauthorized modification/deletion of data. The vulnerability features a scope change, meaning it can impact additional products beyond the primary target.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83003
CVE-2026-83004
CVE-2026-83004 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture that allows a low-privileged, authenticated attacker to perform unauthorized creation, modification, or deletion of critical data. Exploitation is difficult and requires human interaction; however, it can result in a scope change impacting additional products within the Oracle Fusion Middleware environment.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83004
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83005
CVE-2026-83005 is a critical vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, within Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by low-privileged attackers. Successful exploitation allows for complete takeover of the affected product, with high impacts on confidentiality, integrity, and availability.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83005
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83007
CVE-2026-83007 is a critical vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker can exploit this flaw over HTTP to gain unauthorized access to critical data, as well as perform unauthorized modifications or deletions of data within the application. The vulnerability allows for scope change, potentially impacting other integrated products.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83007
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83008
Oracle WebCenter Enterprise Capture contains a critical vulnerability in the Client Bundle component that can be exploited by a low-privileged attacker with network access via T3 or IIOP protocols. Successful exploitation results in a full system takeover, posing significant risks to confidentiality, integrity, and availability.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83008
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83009
CVE-2026-83009 is a critical vulnerability in Oracle WebCenter Enterprise Capture that allows a low-privileged attacker with network access via HTTP to fully compromise the product. The flaw affects versions 12.2.1.4.0 and 14.1.2.0.0, enabling unauthorized access to confidentiality, integrity, and availability of the system.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83009
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83010
CVE-2026-83010 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is remotely exploitable over HTTP by a high-privileged attacker, though it requires human interaction to succeed. Successful exploitation allows for unauthorized modification, deletion, or access to critical data and exhibits a scope change impact on additional products.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83010
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83012, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83011
CVE-2026-83011 is a vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java within Oracle Fusion Middleware. The flaw allows an unauthenticated attacker with network access via HTTP to perform a full system takeover, posing a critical security risk. It has a CVSS 3.1 base score of 8.1, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle Platform Security for Java (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83011
CVE-2026-83012
CVE-2026-83012 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. A low-privileged attacker can exploit this vulnerability over HTTP to gain unauthorized access to critical data. The vulnerability has a scope change (S:C) and is categorized with a high confidentiality impact.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83012
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83013, CVE-2026-83022.
CVE-2026-83013
CVE-2026-83013 is a vulnerability in the Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware. The vulnerability is network-exploitable via HTTP by a low-privileged attacker and can lead to a full system compromise (takeover) of the product. The vulnerability has a CVSS 3.1 base score of 8.8.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83013
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83022.
CVE-2026-83014
CVE-2026-83014 is a vulnerability in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. A low-privileged attacker with network access via HTTP can exploit this flaw to perform unauthorized data modification or deletion, and trigger a denial-of-service condition affecting the availability of the product.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83014
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.
CVE-2026-83015
CVE-2026-83015 is a vulnerability in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The vulnerability allows a low-privileged attacker with local logon access to the underlying infrastructure to achieve a full takeover of the PeopleSoft Enterprise PeopleTools application. The exploit is characterized as difficult to perform but results in high impacts to confidentiality, integrity, and availability.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83015
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83016, CVE-2026-83017, CVE-2026-83019.
CVE-2026-83016
CVE-2026-83016 is a high-severity vulnerability within the SQR component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw requires a highly privileged local attacker to perform successful exploitation, necessitating human interaction from another user. Exploitation can lead to a complete system takeover and impact additional products via scope change, representing a significant risk to the integrity and confidentiality of the PeopleSoft environment.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83016
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83017, CVE-2026-83019.
CVE-2026-83017
CVE-2026-83017 is a vulnerability in the Report Distribution component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full compromise of the application, resulting in impacts to confidentiality, integrity, and availability.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83017
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83019.
CVE-2026-83018
A vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools (versions 8.61-8.63) allows a low-privileged authenticated attacker with local access to the execution infrastructure to achieve a full takeover of the application. The vulnerability is easily exploitable and carries a high impact on the confidentiality, integrity, and availability of the system.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83018
CVE-2026-83019
CVE-2026-83019 is a vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63. The vulnerability is network-exploitable via HTTP by a low-privileged attacker, potentially leading to unauthorized access to critical data and causing a Denial of Service (DoS) through repeatable crashes.
Affected products:
- PeopleSoft Enterprise PeopleTools (8.61-8.63)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83019
Related in this roundup: CVE-2026-73954, CVE-2026-73960, CVE-2026-82993, CVE-2026-83014, CVE-2026-83015, CVE-2026-83016, CVE-2026-83017.
CVE-2026-83022
Oracle WebCenter Enterprise Capture in Oracle Fusion Middleware contains a vulnerability in the Client Bundle component that allows an unauthenticated attacker with local network access to perform a full system takeover. The attack requires human interaction and is difficult to exploit, but it allows for scope change, potentially impacting additional products within the environment.
Affected products:
- WebCenter Enterprise Capture (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83022
Related in this roundup: CVE-2026-83006, CVE-2026-83339, CVE-2026-83004, CVE-2026-83005, CVE-2026-83007, CVE-2026-83008, CVE-2026-83009, CVE-2026-83010, CVE-2026-83012, CVE-2026-83013.
CVE-2026-83023
CVE-2026-83023 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated remote attacker over HTTP, allowing for unauthorized access to sensitive data and potential scope escalation, resulting in a CVSS base score of 8.6.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83023
Related in this roundup: CVE-2026-83027, CVE-2026-83025, CVE-2026-83028.
CVE-2026-83024
CVE-2026-83024 is a vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. A low-privileged attacker with local access to the infrastructure where the connector executes can exploit this flaw to gain unauthorized control over the component, resulting in a full takeover. The vulnerability carries a CVSS base score of 7.8, indicating significant impact on confidentiality, integrity, and availability.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83024
CVE-2026-83025
CVE-2026-83025 is a high-severity, unauthenticated network-accessible vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. An attacker can exploit this flaw to gain unauthorized access to or perform unauthorized modification/deletion of critical data, with a scope change that may impact other products.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83025
Related in this roundup: CVE-2026-83027, CVE-2026-83023, CVE-2026-83028.
CVE-2026-83026
CVE-2026-83026 is a critical vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. An unauthenticated attacker with access to the physical communication segment where the connector resides can exploit this vulnerability to achieve full takeover of the component. The vulnerability has a scope change (S:C) impact, potentially affecting other connected products, and carries a CVSS 3.1 base score of 8.3.
Affected products:
- Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83026
CVE-2026-83028
Oracle Identity Manager Connector within Oracle Fusion Middleware is vulnerable to an unauthenticated, physical adjacent network-based attack. An attacker with access to the physical communication segment can exploit this vulnerability to achieve full takeover of the component, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle Identity Manager Connector (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83028
Related in this roundup: CVE-2026-83027, CVE-2026-83023, CVE-2026-83025.
CVE-2026-83030
Oracle Managed File Transfer (MFT) within Oracle Fusion Middleware is vulnerable to a remote exploitation via T3 or IIOP protocols. A low-privileged attacker with network access can leverage this flaw to gain unauthorized read, write, or delete access to critical data, as well as trigger a denial-of-service (DoS) condition via a crash of the MFT Runtime Server.
Affected products:
- Managed File Transfer (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83030
Related in this roundup: CVE-2026-83029.
CVE-2026-83032
CVE-2026-83032 is a critical vulnerability in Oracle WebCenter Sites (part of Fusion Middleware) that allows a low-privileged, network-adjacent attacker to perform a full system takeover via HTTP. The vulnerability carries a CVSS 3.1 base score of 8.8 and impacts the confidentiality, integrity, and availability of the affected application.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83032
Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83033, CVE-2026-83034.
CVE-2026-83033
CVE-2026-83033 is a vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially leading to a full system takeover of the affected component.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83033
Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83034.
CVE-2026-83034
CVE-2026-83034 is a vulnerability in Oracle WebCenter Sites within Oracle Fusion Middleware, allowing an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data. The vulnerability is easily exploitable and carries a CVSS base score of 7.5, primarily affecting data confidentiality.
Affected products:
- WebCenter Sites (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83034
Related in this roundup: CVE-2026-83031, CVE-2026-83035, CVE-2026-83036, CVE-2026-83037, CVE-2026-83032, CVE-2026-83033.
CVE-2026-83041
CVE-2026-83041 is a vulnerability in the Portlet Services component of Oracle WebCenter Portal within Oracle Fusion Middleware. A low-privileged attacker with network access can exploit this vulnerability via HTTP to achieve unauthorized access to critical data. The vulnerability impacts the confidentiality of the system and involves a scope change, potentially affecting integrated products.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83041
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83044
CVE-2026-83044 is a vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by low-privileged attackers, potentially allowing unauthorized access to sensitive data and triggering a partial denial of service (DoS) condition.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83044
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83045
CVE-2026-83045 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is remotely exploitable over HTTP by a low-privileged attacker, allowing for unauthorized read, write, or deletion of sensitive data and potentially impacting other products through scope change.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83045
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83046
CVE-2026-83046 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal. A low-privileged attacker with network access can exploit this flaw via HTTP to gain unauthorized access to critical data or perform a partial denial of service (DoS) against the application.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83046
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83047
CVE-2026-83047 is an easily exploitable vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware. The vulnerability allows an unauthenticated, network-adjacent attacker to perform unauthorized read, update, insert, or delete operations on critical data via HTTP requests, resulting in significant impact to confidentiality and integrity.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83047
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83048
CVE-2026-83048 is a security vulnerability in Oracle WebCenter Portal's Runtime Tools component. It allows a low-privileged attacker with network access via HTTP to exploit the system, potentially leading to a scope change and unauthorized access to critical data. The vulnerability is rated with a CVSS 3.1 base score of 7.7.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83048
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83049
CVE-2026-83049 is an easily exploitable vulnerability in the Security Framework component of Oracle WebCenter Portal. The flaw allows a low-privileged network-based attacker to perform unauthorized read, update, insert, or delete operations on critical data. The vulnerability supports scope change and carries a CVSS 3.1 base score of 8.5, indicating significant impacts on confidentiality and integrity.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83049
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83050
A vulnerability in the Runtime Tools component of Oracle WebCenter Portal (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged network attacker to compromise the application via HTTP. Successful exploitation grants unauthorized access to critical data, including the ability to read, update, insert, or delete data within the portal, impacting both confidentiality and integrity.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83050
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83051, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83051
CVE-2026-83051 is a vulnerability in the Runtime Tools component of Oracle WebCenter Portal that allows an unauthenticated, network-adjacent attacker to gain unauthorized access to sensitive data via HTTP requests. The vulnerability is easily exploitable with low complexity, affecting versions 12.2.1.4.0 and 14.1.2.0.0, and carries a CVSS 3.1 base score of 7.5.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83051
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83052, CVE-2026-83053.
CVE-2026-83052
CVE-2026-83052 is an easily exploitable vulnerability in the Runtime Tools component of Oracle WebCenter Portal. The vulnerability allows a high-privileged attacker with network access via HTTP to perform unauthorized operations, including accessing, updating, inserting, or deleting critical data. Due to a scope change (S:C), the impact of a successful exploitation may extend to additional products integrated with the affected WebCenter Portal instance.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83052
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83053.
CVE-2026-83053
CVE-2026-83053 is a high-severity vulnerability in the Oracle WebCenter Portal component of Oracle Fusion Middleware. A low-privileged attacker with network access via HTTP can exploit this vulnerability to achieve a full takeover of the affected product, impacting confidentiality, integrity, and availability.
Affected products:
- WebCenter Portal (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83053
Related in this roundup: CVE-2026-73948, CVE-2026-73952, CVE-2026-73953, CVE-2026-73956, CVE-2026-83039, CVE-2026-73951, CVE-2026-83041, CVE-2026-83045, CVE-2026-83046, CVE-2026-83047, CVE-2026-83048, CVE-2026-83049, CVE-2026-83050, CVE-2026-83051, CVE-2026-83052.
CVE-2026-83063
A vulnerability exists in the Oracle Internet Directory component of Oracle Fusion Middleware, specifically within the LDAP server functionality. The flaw is remotely exploitable over the network by a high-privileged attacker, potentially leading to a full takeover of the Oracle Internet Directory service. The vulnerability impacts confidentiality, integrity, and availability.
Affected products:
- Oracle Internet Directory (12.2.1.4.0, 14.1.2.1.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83063
Related in this roundup: CVE-2026-83054, CVE-2026-83056, CVE-2026-83057, CVE-2026-83059, CVE-2026-83060, CVE-2026-83062, CVE-2026-83066.
CVE-2026-83065
Oracle WebCenter Portal version 14.1.2.0.0 is vulnerable to an unauthenticated takeover attack. Exploitation requires the attacker to have access to the physical communication segment of the hardware where the application is hosted. A successful exploit results in a total compromise of the Oracle WebCenter Portal instance, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle WebCenter Portal (14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83065
Related in this roundup: CVE-2026-73959.
CVE-2026-83067
A vulnerability in the ADF Shared Components of Oracle JDeveloper allows a low-privileged, network-adjacent attacker to compromise the integrity and availability of the application. The flaw can be exploited via HTTP to perform unauthorized data modification, deletion, or creation, and to trigger a denial-of-service condition through application crashing or hanging.
Affected products:
- JDeveloper (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83067
Related in this roundup: CVE-2026-73961.
CVE-2026-83068
CVE-2026-83068 is a vulnerability in the Core component of Oracle Enterprise Manager for Oracle Database version 24.1. The vulnerability allows a low-privileged, network-adjacent attacker to perform unauthorized access to critical data. Due to a scope change, exploitation can impact additional products beyond the vulnerable component. The vulnerability is highly exploitable via HTTP and specifically impacts confidentiality.
Affected products:
- Oracle Enterprise Manager for Oracle Database (24.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83068
CVE-2026-83069
CVE-2026-83069 is a critical vulnerability in the Framework component of Oracle Fusion Middleware Control that allows a low-privileged, network-adjacent attacker to achieve a complete takeover of the product via HTTP. The vulnerability carries a CVSS base score of 8.8, indicating high impact on confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware Control (12.2.1.4.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83069
CVE-2026-83070
CVE-2026-83070 is a vulnerability in Oracle PeopleSoft Enterprise PRTL Interaction Hub (component: Enterprise Portal) version 9.1 that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data. Due to a scope change, successful exploitation can result in complete access to all data within the affected application, resulting in a CVSS 3.1 base score of 7.7.
Affected products:
- PeopleSoft Enterprise PRTL Interaction Hub (9.1)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83070
CVE-2026-83071
CVE-2026-83071 is a vulnerability in the Machine Learning component of Oracle Business Intelligence Enterprise Edition. The flaw allows a locally authenticated, low-privileged attacker to achieve full takeover of the application. It is highly exploitable and impacts the confidentiality, integrity, and availability of the system.
Affected products:
- Oracle Business Intelligence Enterprise Edition (8.2.0.0.0, 26.01.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83071
Related in this roundup: CVE-2026-83282, CVE-2026-83283.
CVE-2026-83072
CVE-2026-83072 is a vulnerability within the Search Bean component of the Oracle Applications Framework in Oracle E-Business Suite. The flaw is remotely exploitable over HTTP by a low-privileged attacker, allowing for the unauthorized creation, modification, deletion, or access of critical data within the framework. The vulnerability carries a CVSS 3.1 base score of 8.1, indicating significant impact to both confidentiality and integrity.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83072
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83073
CVE-2026-83073 is an unauthenticated, easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability allows an attacker with access to the physical communication segment of the underlying hardware to bypass authentication and gain unauthorized access, modification, or deletion privileges over critical application data.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
- Siebel Cloud Manager (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83073
Related in this roundup: CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.
CVE-2026-83074
CVE-2026-83074 is a vulnerability in Oracle Siebel CRM Cloud Applications, specifically within the Siebel Cloud Manager component. An unauthenticated attacker with network access via SSH can exploit this flaw to gain unauthorized access to sensitive data, potentially impacting other products within the same scope. The vulnerability has a CVSS score of 8.6, reflecting its high impact on confidentiality.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83074
Related in this roundup: CVE-2026-83073, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.
CVE-2026-83075
CVE-2026-83075 is an easily exploitable vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability allows an unauthenticated attacker with network access via HTTP to perform unauthorized access to critical data. The vulnerability impacts confidentiality and does not require user interaction.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83075
Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.
CVE-2026-83078
CVE-2026-83078 is an easily exploitable, unauthenticated vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications (versions 22.3-26.7). The vulnerability is accessible via HTTP over the network, allowing an attacker to gain unauthorized access to critical data, including the ability to read, update, insert, or delete information within the application.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83078
Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83079, CVE-2026-83085, CVE-2026-83087.
CVE-2026-83079
CVE-2026-83079 is a vulnerability in Oracle Siebel CRM Cloud Applications (specifically the Siebel Cloud Manager component) affecting versions 22.3 through 26.7. The vulnerability allows a high-privileged attacker with local access to the infrastructure to achieve unauthorized access to, or modification of, critical data within the CRM application. The vulnerability has a scope change (S:C) and is characterized by significant confidentiality and integrity impacts.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83079
Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83085, CVE-2026-83087.
CVE-2026-83080
CVE-2026-83080 is a vulnerability in the Reports component of Oracle Banking Branch (versions 14.5.0.0.0 through 14.9.0.0.0) that allows a low-privileged, network-adjacent attacker to achieve full system takeover. The attack requires human interaction and is exploitable via HTTP. Given the reported impact on confidentiality, integrity, and availability, this represents a significant risk to the integrity of the banking application.
Affected products:
- Oracle Banking Branch (14.5.0.0.0-14.9.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83080
CVE-2026-83081
CVE-2026-83081 is a vulnerability in the Core component of Oracle Banking Corporate Lending versions 14.5.0.0.0 through 14.9.0.0.0. An unauthenticated attacker with physical access to the network segment of the hosting hardware can exploit this flaw to gain unauthorized access to or modify critical data. The vulnerability supports scope change and carries a CVSS 3.1 base score of 8.0.
Affected products:
- Oracle Banking Corporate Lending (14.5.0.0.0-14.9.0.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83081
CVE-2026-83082
CVE-2026-83082 is a critical vulnerability within the Audience component of Oracle Marketing, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP, potentially allowing for a full takeover of the Oracle Marketing product. It carries a CVSS 3.1 base score of 7.2, impacting confidentiality, integrity, and availability.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83082
Related in this roundup: CVE-2026-83452, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83083
Oracle Marketing, a component of Oracle E-Business Suite versions 12.2.3 through 12.2.15, is vulnerable to a network-based attack by low-privileged users. The vulnerability allows an attacker to gain unauthorized access to critical data and perform unauthorized modifications or deletions of data within the Audience component, with the potential for impact to additional products via scope change.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83083
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83084
CVE-2026-83084 is a critical vulnerability in the Audience component of Oracle Marketing within the Oracle E-Business Suite. The vulnerability allows a low-privileged, network-adjacent attacker to perform unauthorized access to critical data. The vulnerability has a scope change (S:C) and specifically impacts the confidentiality of the targeted system, carrying a CVSS 3.1 base score of 7.7.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83084
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83085
CVE-2026-83085 is a vulnerability in Oracle Siebel Cloud Manager within Siebel CRM Cloud Applications versions 22.3 through 26.7. An attacker with low-level privileges and access to the local physical communication segment can perform unauthorized data access, modification, deletion, and cause a partial denial of service. The vulnerability has a scope change (S:C) impact, potentially affecting other products within the environment.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83085
Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83087.
CVE-2026-83086
CVE-2026-83086 is a high-severity vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. A low-privileged attacker with network access can exploit this flaw via HTTP to achieve a full system takeover, impacting the confidentiality, integrity, and availability of the application. The vulnerability is considered easily exploitable and does not require user interaction.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83086
CVE-2026-83087
CVE-2026-83087 is a vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications, affecting versions 22.3 through 26.7. The vulnerability is exploitable over the network via HTTP by a low-privileged attacker. Successful exploitation allows for unauthorized modification, deletion, or access to critical data and carries a scope change, potentially impacting other integrated products.
Affected products:
- Siebel CRM Cloud Applications (22.3-26.7)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83087
Related in this roundup: CVE-2026-83073, CVE-2026-83074, CVE-2026-83075, CVE-2026-83078, CVE-2026-83079, CVE-2026-83085.
CVE-2026-83088
CVE-2026-83088 is a vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0 through 23.26.3. A low-privileged, authenticated attacker with network access via Oracle Net can exploit this flaw to cause a complete denial-of-service (DoS) resulting in a hang or repeatable crash of the RDBMS. The vulnerability impacts the broader scope of the system and is considered easily exploitable with high availability impacts.
Affected products:
- Database Server (23.4.0-23.26.3)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83088
CVE-2026-83089
CVE-2026-83089 is a vulnerability in the Oracle Alert component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an authenticated, low-privileged attacker with network access to perform unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to data within the Oracle Alert system. The vulnerability is classified as easily exploitable and carries a CVSS 3.1 base score of 8.1.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83089
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83090
CVE-2026-83090 is a critical vulnerability in the Oracle Spares Management component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by a low-privileged attacker, potentially leading to a full system takeover, impacting confidentiality, integrity, and availability.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83090
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83110, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83091
CVE-2026-83091 is a vulnerability in the Internal Operations component of Oracle Field Service (Oracle E-Business Suite) that allows a low-privileged, network-adjacent attacker to gain unauthorized access to data, modify or delete information, and trigger a partial denial-of-service condition via HTTP. The flaw is considered easily exploitable and carries a CVSS 3.1 base score of 7.6.
Affected products:
- Oracle Field Service (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83091
Related in this roundup: CVE-2026-83092.
CVE-2026-83092
CVE-2026-83092 is a vulnerability in the Internal Operations component of Oracle Field Service (within Oracle E-Business Suite) that allows a low-privileged attacker with network access via HTTP to perform unauthorized data modification, deletion, or access, as well as cause a partial denial of service. The vulnerability is difficult to exploit but carries a CVSS 3.1 base score of 7.1.
Affected products:
- Oracle Field Service (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83092
Related in this roundup: CVE-2026-83091.
CVE-2026-83093
An unauthenticated, network-accessible vulnerability exists in the Forms Services component of Oracle Fusion Middleware. The flaw allows remote attackers to compromise the Oracle Forms environment via HTTP, potentially leading to unauthorized access to critical data. The vulnerability is characterized by a scope change, allowing the impact to extend beyond the affected component, and is rated with a CVSS 3.1 base score of 8.6 due to its ease of exploitation and high confidentiality impact.
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83093
CVE-2026-83096
Oracle Fusion Middleware Forms Services contains a vulnerability that allows an authenticated, low-privileged attacker with network access to perform unauthorized data manipulation, access sensitive information, or cause a partial denial of service. The attack requires user interaction and is characterized by a scope change, potentially impacting other integrated products.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83096
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83101, CVE-2026-83106.
CVE-2026-83101
Oracle Fusion Middleware Oracle Forms component (Forms Services) contains a vulnerability that allows an unauthenticated, network-adjacent attacker to achieve full takeover of the Oracle Forms application via HTTP requests. The vulnerability is difficult to exploit but results in high impact to confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83101
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83106.
CVE-2026-83102
CVE-2026-83102 is a vulnerability in the Forms Services component of Oracle Fusion Middleware's Oracle Forms. The vulnerability allows an unauthenticated, remote attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical data. Exploitation requires high complexity and impacts the confidentiality and integrity of the affected Oracle Forms environment.
Affected products:
- Oracle Forms (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83102
Related in this roundup: CVE-2026-83094.
CVE-2026-83106
CVE-2026-83106 is a critical vulnerability in the Oracle Forms component of Oracle Fusion Middleware (specifically Forms Services, C/S, Charmode). A low-privileged attacker with network access via HTTP can exploit this flaw to achieve a full takeover of the Oracle Forms application. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant impacts on confidentiality, integrity, and availability.
Affected products:
- Oracle Fusion Middleware (12.2.1.19.0, 14.1.2.0.0)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83106
Related in this roundup: CVE-2026-83099, CVE-2026-83100, CVE-2026-83104, CVE-2026-83107, CVE-2026-83108, CVE-2026-83096, CVE-2026-83101.
CVE-2026-83110
CVE-2026-83110 is a critical vulnerability in the Audience component of Oracle Marketing within Oracle E-Business Suite. The vulnerability allows an unauthenticated, network-adjacent attacker to gain unauthorized access to critical data through HTTP requests. It is rated with a CVSS score of 7.5, focusing on information disclosure (confidentiality impact) without requiring authentication or user interaction.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83110
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83115, CVE-2026-83117.
CVE-2026-83111
CVE-2026-83111 is a vulnerability in the Oracle Partner Management component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the component. Successful exploitation can lead to unauthorized access, modification, or deletion of critical data, and features a scope change impacting additional products within the suite.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83111
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83112
CVE-2026-83112 is a vulnerability within the Oracle Lease and Finance Management component of the Oracle E-Business Suite. The flaw is remotely exploitable over HTTP by a high-privileged attacker, potentially leading to a full system takeover. The vulnerability carries a CVSS 3.1 base score of 7.2.
Affected products:
- Oracle E-Business Suite (12.2.7-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83112
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83113, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83113
CVE-2026-83113 is a vulnerability in the Oracle Quality component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is network-exploitable via HTTP by low-privileged attackers. Successful exploitation allows unauthorized access, modification, or deletion of critical data within the Oracle Quality module.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83113
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83114, CVE-2026-83116.
CVE-2026-83114
Oracle Quality, a component of Oracle E-Business Suite versions 12.2.3 through 12.2.15, contains a vulnerability that allows a low-privileged, network-adjacent attacker to achieve full takeover of the application via HTTP. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating significant impact on confidentiality, integrity, and availability.
Affected products:
- Oracle E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83114
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83116.
CVE-2026-83115
CVE-2026-83115 is an unauthenticated, network-exploitable vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (RapidClone). The vulnerability allows a remote attacker to gain unauthorized access to critical data or complete access to all data managed by the Oracle Applications Manager, posing a significant confidentiality risk.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83115
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83117.
CVE-2026-83116
CVE-2026-83116 is a vulnerability in the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite. The vulnerability is network-exploitable via HTTP by low-privileged attackers. It exhibits a scope change and allows for unauthorized access to critical data, resulting in a CVSS 3.1 base score of 7.7. The vulnerability impacts confidentiality but does not affect integrity or availability.
Affected products:
- Oracle E-Business Suite (12.2.5-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83116
Related in this roundup: CVE-2026-83452, CVE-2026-83082, CVE-2026-83089, CVE-2026-83111, CVE-2026-83112, CVE-2026-83113, CVE-2026-83114.
CVE-2026-83117
CVE-2026-83117 is a vulnerability in the AD Utilities component of Oracle E-Business Suite Applications DBA, rated with a CVSS score of 7.2. The vulnerability is easily exploitable over the network via HTTP by a high-privileged attacker, potentially leading to a full takeover of the Applications DBA component.
Affected products:
- E-Business Suite (12.2.3-12.2.15)
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83117
Related in this roundup: CVE-2026-83327, CVE-2026-83462, CVE-2026-83044, CVE-2026-83072, CVE-2026-83083, CVE-2026-83084, CVE-2026-83090, CVE-2026-83110, CVE-2026-83115.