A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.
Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.
This Critical Security Patch Update contains 673 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at September 2026 Critical Security Patch Update: Executive Summary and Analysis.
Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.
Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.
Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.
Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.
Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).
Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.
Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.
The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible. Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.
Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Security Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.
Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.
Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.
The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:
Security patches are released on the third Tuesday of each month. The next four dates are:
| Date | Note |
|---|---|
| 2026-September-15 | Rev 1. Initial Release. |
This Critical Security Patch Update contains 13 new security patches for Oracle Database Products divided as follows:
This Critical Security Patch Update contains 11 new security patches for Oracle Database Products. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. 2 of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.
| CVE ID | Component | Package and/or Privilege Required | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83348 | RDBMS | Create DB Link | Oracle Net | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83160 | RDBMS | Create Table | Oracle Net | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 23.4.0-23.26.3 | |
| CVE-2026-83271 | RDBMS | Execute on DBMS_REDEFINITION | Oracle Net | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83272 | Oracle Text | Create Index | Oracle Net | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83351 | RDBMS | None | Oracle Net | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 23.4.0-23.26.3 | |
| CVE-2026-83088 | RDBMS | Authenticated User | Oracle Net | No | 7.7 | Network | Low | Low | None | Changed | None | None | High | 23.4.0-23.26.3 | |
| CVE-2026-83349 | Oracle Net Services | Connection Manager | Oracle Net | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83350 | Oracle Net Services | Connection Manager | Oracle Net | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83333 | Oracle Net Services | Listener | Oracle Net | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 23.4.0-23.26.3 | |
| CVE-2026-83156 | Oracle XML Developers Kit | XDKC | Oracle Net | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-83347 | Oracle Net Services | Listener | TCPS | Yes | 6.5 | Network | Low | None | Required | Un- changed |
None | None | High | 23.4.0-23.26.3 | |
This Critical Security Patch Update contains 2 new security patches, plus additional third party patches noted below, for Oracle Autonomous Health Framework. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-14456 | Oracle Autonomous Health Framework | AHFCOMMON (OpenSSL) | HTTPS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 26.2, 26.3.1, 26.5.3, 26.8 | |
| CVE-2026-75838 | Oracle Autonomous Health Framework | AHFCOMMON (DOMPurify) | HTTP | No | 4.6 | Network | Low | Low | Required | Un- changed |
Low | Low | None | 26.8 | |
This Critical Security Patch Update contains 3 new security patches for Oracle Application Testing Suite. None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Component | Package and/or Privilege Required | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83149 | Oracle Application Testing Suite | Test Manager for Web Apps | HTTP | No | 9.1 | Network | Low | Low | None | Changed | High | Low | Low | 13.3.0.1 | |
| CVE-2026-83148 | Oracle Application Testing Suite | Test Manager for Web Apps | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 13.3.0.1 | |
| CVE-2026-83150 | Oracle Application Testing Suite | OpenScript | None | No | 7.0 | Local | High | None | Required | Un- changed |
High | High | High | 13.3.0.1 | |
This Critical Security Patch Update contains 27 new security patches for Oracle Commerce. 16 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83234 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.4.0 | |
| CVE-2026-83236 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-83248 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
Low | None | High | 11.4.0 | |
| CVE-2026-83245 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83246 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83258 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83254 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | TCP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83255 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | TCP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83256 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | TCP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83253 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83247 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83249 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | None | No | 7.8 | Local | High | Low | None | Changed | High | High | High | 11.4.0 | |
| CVE-2026-83233 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-83243 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-83235 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-83241 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 7.5 | Network | High | None | Required | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83257 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83242 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 11.4.0 | |
| CVE-2026-83237 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-83238 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-83259 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-83240 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | None | No | 7.1 | Local | Low | Low | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-83244 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | TCP/IP | Yes | 7.1 | Adjacent Network |
High | None | None | Un- changed |
High | Low | High | 11.4.0 | |
| CVE-2026-83252 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 7.0 | Network | High | None | None | Un- changed |
High | Low | Low | 11.4.0 | |
| CVE-2026-83239 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-83250 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 6.5 | Network | High | None | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-83251 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | TLS | Yes | 6.5 | Network | High | None | None | Un- changed |
Low | None | High | 11.4.0 | |
This Critical Security Patch Update contains 31 new security patches for Oracle Communications. 23 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-44024 | Oracle Communications Unified Assurance | Core (Fluentd) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-17544 | Oracle Communications Unified Assurance | Core (PHP) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 7.0.0 | |
| CVE-2026-71290 | Oracle Communications Unified Assurance | Core (Apache HttpClient) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
| CVE-2026-73194 | Oracle Communications Unified Assurance | Core (DBI) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 6.1.1-7.0.0 | |
| CVE-2026-83418 | Oracle Communications Cloud Native Core Security Edge Protection Proxy | SEPP | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 26.1.200, 25.2.201 | |
| CVE-2026-67355 | Oracle Communications Unified Assurance | Core (Guzzle) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-64849 | Oracle Communications Unified Assurance | Core (MLflow) | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
| CVE-2026-54518 | Oracle Communications Unified Assurance | Core (jackson-databind) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-39822 | Oracle Communications Unified Assurance | Core (Golang Go) | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-34477 | Oracle Communications MetaSolv Solution Module - ASR | Access Service Request (Apache Log4j) | Multiple | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 70.0.0 | |
| CVE-2026-9563 | Oracle Communications Service Catalog and Design | Third Party Patch (Eclipse Parsson) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 8.0-8.3 | |
| CVE-2026-73508 | Oracle Communications Service Catalog and Design | Third Party Patch (Netty) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 8.0-8.1 | |
| CVE-2026-66299 | Oracle Communications Unified Assurance | Core (Apache Tomcat) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 6.1.1-7.0.0 | |
| CVE-2026-55952 | Oracle Communications Unified Assurance | Core (Erlang/OTP) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.0.0 | |
| CVE-2026-50734 | Oracle Communications Unified Assurance | Message Bus (Apache ActiveMQ) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 6.1.1-7.0.0 | |
| CVE-2026-57220 | Oracle Communications Unified Assurance | Message Bus (Pivotal RabbitMQ) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.0.0 | |
| CVE-2026-83417 | Oracle Communications Cloud Native Core Security Edge Protection Proxy | SEPP | HTTP/2 | Yes | 7.1 | Adjacent Network |
Low | None | None | Un- changed |
High | Low | None | 26.1.200, 25.2.201 | |
| CVE-2026-49284 | Oracle Communications Unified Assurance | Core (SimpleSAMLphp) | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 6.1.1-7.0.0 | |
| CVE-2026-41239 | Oracle Communications Operations Monitor | Mediation Engine (DOMPurify) | HTTP | Yes | 6.8 | Network | High | None | Required | Un- changed |
High | High | None | 6.1 | |
| CVE-2026-41989 | Oracle Communications Unified Assurance | Core (libgcrypt) | None | No | 6.7 | Local | High | None | None | Un- changed |
None | High | High | 6.1.1-7.0.0 | |
| CVE-2026-59943 | Oracle Communications Unified Assurance | Core (Dompdf) | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
None | Low | Low | 6.1.1-7.0.0 | |
| CVE-2026-19880 | Oracle Communications Unified Assurance | Core (logback) | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 6.1.1-7.0.0 | |
| CVE-2026-61109 | Oracle Communications Unified Assurance | Core (MySQL Server) | MySQL Protocol | No | 6.5 | Network | Low | Low | None | Un- changed |
None | None | High | 6.1.1-7.0.0 | |
| CVE-2026-58520 | Oracle Communications Unified Assurance | Core (MediaWiki) | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 6.1.1-7.0.0 | |
| CVE-2026-13006 | Oracle Communications Unified Assurance | Core (logback) | None | No | 6.0 | Local | Low | High | None | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
| CVE-2026-49844 | Oracle Communications Unified Assurance | Core (Apache Log4j) | HTTP | Yes | 5.9 | Network | High | None | None | Un- changed |
None | High | None | 6.1.1-7.0.0 | |
| CVE-2026-83419 | Oracle Communications Cloud Native Core Security Edge Protection Proxy | SEPP | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 26.1.200, 25.2.201 | |
| CVE-2026-48998 | Oracle Communications Unified Assurance | Core (Guzzle PSR-7) | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 6.1.1-7.0.0 | |
| CVE-2026-63308 | Oracle Communications Unified Assurance | Core (Helm) | HTTP | Yes | 4.3 | Network | Low | None | Required | Un- changed |
None | None | Low | 7.0.0 | |
| CVE-2026-13758 | Oracle Communications Unified Assurance | Core (CryptX) | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
None | None | Low | 6.1.1-7.0.0 | |
| CVE-2026-12590 | Oracle Communications Unified Assurance | Core (Node.js) | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
None | None | Low | 6.1.1-7.0.0 | |
This Critical Security Patch Update contains 159 new security patches for Oracle E-Business Suite. 19 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (September 2026), My Oracle Support Note KA923.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83327 | Oracle Applications Framework | Personalization | SOAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83452 | Oracle Document Management and Collaboration | Internal Operations | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83462 | Oracle Mobile Application Server | MWA Terminal Server | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83120 | Oracle Alert | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83163 | Oracle Application Object Library | Attachments / File Upload | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83205 | Oracle Applications Framework | Personalization | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83329 | Oracle Applications Framework | Personalization | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.9-12.2.15 | |
| CVE-2026-83331 | Oracle Applications Framework | Personalization | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.9-12.2.15 | |
| CVE-2026-83338 | Oracle Applications Manager | Oracle Diagnostics Interfaces | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83168 | Oracle Applications Manager | Oracle Diagnostics Interfaces | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-87150 | Oracle Bills of Material | Setup Workbench | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83445 | Oracle Complex Maintenance, Repair and Overhaul | Internal Operations | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-87162 | Oracle Contract Lifecycle Management for Public Sector | Award/PO | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.13-12.2.15 | |
| CVE-2026-87165 | Oracle Contract Lifecycle Management for Public Sector | ECC For Award and IDV | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | V16 | |
| CVE-2026-83479 | Oracle Contracts | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.14-12.2.15 | |
| CVE-2026-83164 | Oracle Customer Interaction History | Outcome-Result | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83165 | Oracle Customer Interaction History | User Interface | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83456 | Oracle Demand Signal Repository | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83194 | Oracle Depot Repair | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.10-12.2.15 | |
| CVE-2026-83454 | Oracle Document Management and Collaboration | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83121 | Oracle Marketing | Audience | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83444 | Oracle Product Hub | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-87155 | Oracle Product Hub | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-87163 | Oracle Purchasing | Other issue | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83125 | Oracle Report Manager | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83122 | Oracle Report Manager | Internal Operations | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83124 | Oracle Sales Online | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83090 | Oracle Spares Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83136 | Oracle Spares Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83137 | Oracle Spares Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83119 | Oracle User Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.6-12.2.15 | |
| CVE-2026-83189 | Oracle User Management | Proxy User Delegation | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83135 | Oracle iStore | Shopping Cart | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83449 | Oracle Bills of Material | Internal Operations | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83425 | Oracle Complex Maintenance, Repair and Overhaul | Internal Operations | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | None | Low | 12.2.12-12.2.15 | |
| CVE-2026-87161 | Oracle HRMS (India) | Internal Operations | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83490 | Oracle iRecruitment | Internal Operations | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83083 | Oracle Marketing | Audience | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83451 | Oracle Product Workbench | Internal Operations | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83172 | Oracle Sales Online | OSO Other | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-87125 | Oracle Financials for Asia/Pacific | Internal Operations | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 12.2.8-12.2.15 | |
| CVE-2026-83435 | Oracle Bills of Material | Internal Operations | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 12.2.13-12.2.15 | |
| CVE-2026-83438 | Oracle Engineering | Internal Operations | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83465 | Oracle Mobile Application Server | MWA Terminal Server | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | None | Low | High | 12.2.3-12.2.15 | |
| CVE-2026-83461 | Oracle Mobile Application Server | MWA Terminal Server | TCP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83089 | Oracle Alert | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83072 | Oracle Applications Framework | Search Bean [Incl. Advanced] | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83447 | Oracle Bills of Material | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83448 | Oracle Bills of Material | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83174 | Oracle CRM Technical Foundation | Application Framework | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83428 | Oracle Demand Signal Repository | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83429 | Oracle Demand Signal Repository | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83455 | Oracle Demand Signal Repository | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83457 | Oracle Demand Signal Repository | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83432 | Oracle Depot Repair | Estimate and Actual Charges | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83446 | Oracle Financials Common Modules | Common Components | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87159 | Oracle HRMS (India) | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87152 | Oracle Installed Base | Create Item Instance | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83132 | Oracle iStore | Shopping Cart | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83464 | Oracle Mobile Application Server | MWA Terminal Server | TCP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83177 | Oracle One-to-One Fulfillment | Documents | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83169 | Oracle One-to-One Fulfillment | Java Server Issues | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-87157 | Oracle Order Management | Product Diagnostic Tools | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.4-12.2.15 | |
| CVE-2026-87153 | Oracle Product Hub | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87154 | Oracle Product Hub | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83430 | Oracle Product Workbench | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83434 | Oracle Product Workbench | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83152 | Oracle Project Intelligence | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87167 | Oracle Purchasing | G-Invoicing | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.11-12.2.15 | |
| CVE-2026-87168 | Oracle Purchasing | G-Invoicing | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.10-12.2.15 | |
| CVE-2026-87166 | Oracle Purchasing | Other issue | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87265 | Oracle Purchasing | Other issue | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83477 | Oracle Work in Process | Workbenches | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83483 | Oracle Advanced Benefits | Self-serv What-if Analysis | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83178 | Oracle Application Object Library | Core | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83157 | Oracle Applications Manager | Command Line - RapidClone | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83450 | Oracle Bills of Material | Setup Workbench | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83170 | Oracle One-to-One Fulfillment | Documents | UDP | No | 8.0 | Adjacent Network |
Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83138 | Oracle Spares Management | Internal Operations | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83118 | Applications DBA | AD Utilities | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83159 | Applications DBA | ADPatch | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83356 | Enterprise Command Center Framework | Security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | V16 | |
| CVE-2026-87151 | Oracle Bills of Material | Setup Workbench | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83166 | Oracle Customer Interaction History | Outcome-Result | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83437 | Oracle Engineering | Change Management | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83141 | Oracle Field Service | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-87124 | Oracle iRecruitment | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83134 | Oracle iStore | Shopping Cart | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83084 | Oracle Marketing | Audience | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83116 | Oracle Order Management | Product Diagnostic Tools | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.5-12.2.15 | |
| CVE-2026-83485 | Oracle Product Hub | Item Catalog | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83486 | Oracle Product Hub | Item Catalog | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83487 | Oracle Product Hub | Item Catalog | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83142 | Oracle Proposals | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-87127 | Oracle Purchasing | G-Invoicing | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.10-12.2.15 | |
| CVE-2026-83129 | Oracle Sales | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83127 | Oracle Sales Offline | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83131 | Oracle Web Applications Desktop Integrator | File download | HTTPS | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83091 | Oracle Field Service | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
High | Low | Low | 12.2.3-12.2.15 | |
| CVE-2026-83126 | Oracle Sales Online | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83167 | Oracle Application Object Library | Core | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83115 | Oracle Applications Manager | Command Line - RapidClone | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83341 | Oracle Applications Manager | Command Line - RapidClone | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83133 | Oracle iStore | Shopping Cart | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83110 | Oracle Marketing | Audience | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83463 | Oracle Mobile Application Server | MWA Terminal Server | TCP | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83114 | Oracle Quality | Internal Operations | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83128 | Oracle Sales Offline | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83204 | Oracle Sourcing | Internal Operations | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83184 | Oracle Application Object Library | Core | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83162 | Oracle Application Object Library | Core | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83185 | Oracle Common Applications | CRM User Management Framework | HTTP | No | 7.3 | Network | Low | Low | Required | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83117 | Applications DBA | AD Utilities | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83328 | Oracle Applications Framework | Personalization | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83176 | Oracle Common Applications | CRM User Management Framework | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83481 | Oracle Contracts | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.14-12.2.15 | |
| CVE-2026-83482 | Oracle Contracts | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.14-12.2.15 | |
| CVE-2026-83188 | Oracle Depot Repair | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83453 | Oracle Document Management and Collaboration | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83112 | Oracle Lease and Finance Management | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.7-12.2.15 | |
| CVE-2026-83082 | Oracle Marketing | Audience | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83440 | Oracle Product Hub | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83442 | Oracle Product Hub | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83332 | Oracle Applications Framework | Personalization | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.9-12.2.15 | |
| CVE-2026-83158 | Oracle Applications Manager | Command Line - RapidClone | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83179 | Oracle Common Applications Calendar | Applications Calendar | HTTP | No | 7.1 | Network | High | Low | None | Un- changed |
High | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-83186 | Oracle Common Applications Calendar | Applications Calendar | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
None | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-83187 | Oracle Common Applications Calendar | Applications Calendar | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-87149 | Oracle Contract Lifecycle Management for Public Sector | Award/PO | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.8-12.2.15 | |
| CVE-2026-83436 | Oracle Depot Repair | Recall Management | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83092 | Oracle Field Service | Internal Operations | HTTP | No | 7.1 | Network | High | Low | None | Un- changed |
High | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-87160 | Oracle HRMS (India) | Internal Operations | HTTPS | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83171 | Oracle One-to-One Fulfillment | Documents | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83173 | Oracle One-to-One Fulfillment | Documents | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-87158 | Oracle Order Management | Enterprise Command Center | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | V16 | |
| CVE-2026-83111 | Oracle Partner Management | Internal Operations | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-87156 | Oracle Product Hub | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83161 | Oracle Project Intelligence | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83113 | Oracle Quality | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-87126 | Oracle Report Manager | Reports Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83123 | Oracle Report Manager | Internal Operations | HTTPS | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83130 | Oracle Site Hub | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83484 | Oracle US Federal Human Resources | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83044 | Oracle XML Gateway | Install | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83300 | Oracle XML Gateway | Install | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83345 | Oracle XML Gateway | Install | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83352 | Oracle XML Gateway | Install | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-83076 | Oracle HR Intelligence | Internal Operations | HTTP | No | 6.8 | Network | High | Low | None | Un- changed |
None | High | High | 12.2.3-12.2.15 | |
| CVE-2026-83491 | Oracle iRecruitment | Internal Operations | TCP | Yes | 6.8 | Adjacent Network |
High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83441 | Oracle Product Hub | Internal Operations | HTTP | No | 6.8 | Network | High | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83175 | Oracle Application Object Library | Core | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83443 | Oracle Assets | Internal Operations | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83433 | Oracle Depot Repair | Depot Repair Diagnostics | HTTP | No | 6.5 | Network | Low | High | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-83140 | Oracle Field Service | Internal Operations | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-83200 | Oracle Process Manufacturing Intelligence | Internal Operations | Oracle Net | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70755 | Oracle Web Applications Desktop Integrator | File download | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-87169 | Oracle Contract Lifecycle Management for Public Sector | Wage Determination Online | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83198 | Oracle Field Service | Internal Operations | HTTP | No | 5.4 | Network | Low | Low | Required | Changed | Low | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-83431 | Oracle Product Workbench | WebUI | HTTP | No | 5.4 | Network | Low | Low | Required | Changed | Low | Low | None | 12.2.3-12.2.15 | |
This Critical Security Patch Update contains 7 new security patches for Oracle Enterprise Manager. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.
Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update September 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU350.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-41635 | Oracle Enterprise Manager Base Platform | Agent Next Gen (Apache Mina) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-83355 | Oracle Enterprise Manager for Fusion Middleware | Metrics | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-2332 | Oracle Enterprise Manager Base Platform | OMS (Eclipse Jetty) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 24.1 | |
| CVE-2026-83068 | Oracle Enterprise Manager for Oracle Database | Core | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 24.1 | |
| CVE-2026-62597 | Oracle Enterprise Manager Base Platform | Event Management | SOAP | No | 6.5 | Network | Low | Low | None | Un- changed |
None | High | None | 13.5, 24.1 | |
| CVE-2026-49844 | Oracle Enterprise Manager Base Platform | OMS (Apache Log4j) | HTTP | Yes | 5.9 | Network | High | None | None | Un- changed |
None | High | None | 13.5, 24.1 | |
| CVE-2025-68161 | Oracle Enterprise Manager Base Platform | Diagnostic Kit (Apache Log4j) | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 13.5, 24.1 | |
This Critical Security Patch Update contains 6 new security patches for Oracle Financial Services Applications. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-87164 | Oracle Banking Branch | Reports | HTTP | No | 8.0 | Network | High | Low | Required | Changed | High | High | High | 14.5.0.0.0-14.9.0.0.0 | |
| CVE-2026-83081 | Oracle Banking Corporate Lending | Core | HTTPS | Yes | 8.0 | Adjacent Network |
High | None | None | Changed | High | High | None | 14.5.0.0.0-14.9.0.0.0 | |
| CVE-2026-83489 | Oracle Banking Origination | Onboarding Batch Processes | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 14.5.0.0.0-14.9.0.0.0 | |
| CVE-2026-34480 | Oracle Banking Treasury Management | Infrastructure (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 14.5.0.0.0-14.9.0.0.0 | |
| CVE-2026-83080 | Oracle Banking Branch | Reports | HTTP | No | 7.1 | Network | High | Low | Required | Un- changed |
High | High | High | 14.5.0.0.0-14.9.0.0.0 | |
| CVE-2026-83206 | Oracle Banking Corporate Lending Process Management | Base | HTTP | No | 7.1 | Network | High | Low | Required | Un- changed |
High | High | High | 14.5.0.0.0-14.9.0.0.0 | |
This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware. 78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71133 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83099 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83059 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83020 | Oracle Platform Security for Java | Centralized Thirdparty Jars | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83021 | Oracle WebLogic Server | Web Container | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 | |
| CVE-2026-71163 | Oracle Access Manager | Authentication Engine | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | Low | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73945 | Oracle Access Manager | Authentication Engine | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83055 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83056 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83057 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83058 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73948 | Oracle WebCenter Portal | Composer | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83039 | Oracle WebCenter Portal | Composer | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83031 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83038 | Oracle WebLogic Server | TopLink Integration | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-82999 | Service Delivery Platform | Messaging Enabler | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-82997 | Service Delivery Platform | Messaging Enabler | T3, IIOP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-82998 | Service Delivery Platform | Messaging Enabler | T3, IIOP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73950 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73947 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73940 | Oracle Access Manager | Authentication Engine | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-47065 | Oracle Access Manager | Third Party (Apache Mina) | TCP/IP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83232 | Oracle Data Integrator | Console / Repository Explorer | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83094 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83095 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83098 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83100 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83108 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-70913 | Oracle Identity Manager | Core | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83042 | Oracle Identity Manager | OIM Legacy UI | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83054 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83060 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83061 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83062 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83066 | Oracle Internet Directory | OID LDAP Server | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73961 | Oracle JDeveloper | ADF Faces | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-82994 | Oracle Platform Security for Java | Centralized Thirdparty Jars | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-82995 | Oracle Platform Security for Java | Centralized Thirdparty Jars | SOAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83339 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73956 | Oracle WebCenter Portal | Composer | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73953 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73963 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83035 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83036 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83037 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-70756 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-70757 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-70748 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83000 | Service Delivery Platform | Messaging Enabler | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83151 | Service Delivery Platform | Messaging Enabler | SOAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73962 | Oracle Access Manager | Authentication Engine | HTTPS | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83029 | Oracle Managed File Transfer | MFT Runtime Server | HTTP | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83043 | Oracle WebCenter Portal | Composer | HTTP | Yes | 9.6 | Network | Low | None | Required | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83040 | Oracle WebCenter Portal | Portlet Services | SOAP | Yes | 9.6 | Network | Low | None | Required | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83027 | Oracle Identity Manager Connector | Core | TLS | Yes | 9.3 | Adjacent Network |
Low | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73957 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 9.3 | Network | Low | None | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73944 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73946 | Oracle Access Manager | Authentication Engine | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83001 | Oracle Access Manager | Authentication Engine | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83103 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83107 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83104 | Oracle Forms | Forms Services, C/S, Charmode | TCP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83006 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73952 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83064 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83105 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 9.0 | Network | High | None | None | Changed | High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83411 | Oracle Coherence | Core | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83410 | Oracle Coherence | Core | Multiple | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83069 | Oracle Fusion Middleware Control | Framework | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-71047 | Oracle Identity Manager | Core | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73942 | Oracle Identity Manager | OIM Legacy UI | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83340 | Oracle Identity Manager | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-70915 | Oracle Identity Manager | Core | T3, IIOP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83306 | Oracle JDeveloper | Resource Catalog Services | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83423 | Oracle JDeveloper | Security Framework | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83005 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83009 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83013 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83008 | Oracle WebCenter Enterprise Capture | Client Bundle | T3, IIOP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73959 | Oracle WebCenter Portal | Composer | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73949 | Oracle WebCenter Portal | Portlet Services | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83053 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83032 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83033 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73926 | Oracle Access Manager | Authentication Engine | HTTP | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83025 | Oracle Identity Manager Connector | Core | TCP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73941 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83093 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83023 | Oracle Identity Manager Connector | Core | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83002 | Oracle Access Manager | Authentication Engine | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83007 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83003 | Oracle WebCenter Enterprise Capture | Client Bundle | SOAP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83045 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83049 | Oracle WebCenter Portal | Security Framework | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83026 | Oracle Identity Manager Connector | Core | TLS | Yes | 8.3 | Adjacent Network |
High | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83030 | Oracle Managed File Transfer | MFT Runtime Server | T3, IIOP | No | 8.3 | Network | Low | Low | None | Un- changed |
Low | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83266 | Oracle JDeveloper | Resource Catalog Services | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83265 | Oracle Web Services Manager | Web Services Agent | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83047 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83439 | Helidon | helidon-security-providers-idcs-mapper | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 3.0.0-3.2.20,4.0.0-4.5.4 | |
| CVE-2026-73958 | Oracle Access Manager | Authentication Engine | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83412 | Oracle Coherence | Core | TCP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83101 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83422 | Oracle Identity Manager | OIM Legacy UI | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83067 | Oracle JDeveloper | ADF Shared Components | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83011 | Oracle Platform Security for Java | Centralized Thirdparty Jars | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83010 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 8.1 | Network | Low | High | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73951 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83096 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | No | 7.9 | Network | High | Low | Required | Changed | High | High | Low | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83022 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | Yes | 7.9 | Adjacent Network |
High | None | Required | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83024 | Oracle Identity Manager Connector | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83337 | Oracle Middleware Common Libraries and Tools | Remote Diagnostic Agent | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-82996 | Oracle Platform Security for Java | Centralized Thirdparty Jars | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83353 | Oracle WebCenter Content | Content Server | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83012 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83041 | Oracle WebCenter Portal | Portlet Services | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83048 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73943 | Oracle Identity Manager | OIM Legacy UI | HTTP | No | 7.6 | Network | Low | High | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83052 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.6 | Network | Low | High | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83330 | Helidon | WebSocket | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.0.0-4.5.4 | |
| CVE-2026-87289 | Helidon | helidon-webserver-static-content | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.0.0-4.5.4 | |
| CVE-2026-83276 | Helidon | helidon-webclient-http2 | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.0.0-4.5.4 | |
| CVE-2026-83280 | Helidon | helidon-webserver-http2 | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.0.0-4.5.4 | |
| CVE-2026-83281 | Helidon | helidon-webserver | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.0.0-4.5.4 | |
| CVE-2026-83415 | Oracle Coherence | Core | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83106 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83028 | Oracle Identity Manager Connector | Core | TLS | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83424 | Oracle JDeveloper | Oracle JDeveloper | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83051 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83065 | Oracle WebCenter Portal | Runtime Tools | HTTPS | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-83034 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83102 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83334 | Oracle Web Services Manager | Web Services Security | SOAP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | None | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83344 | Oracle Identity Manager Connector | Database Application Table | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83063 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83004 | Oracle WebCenter Enterprise Capture | Client Bundle | None | No | 7.2 | Local | High | Low | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83046 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83050 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83231 | Helidon | helidon-dbclient-mongodb | HTTP | Yes | 7.0 | Network | High | None | None | Un- changed |
High | Low | Low | 3.0.0-3.2.20,4.0.0-4.5.4 | |
| CVE-2026-83278 | Helidon | helidon-integrations-neo4j | HTTPS | Yes | 6.8 | Adjacent Network |
High | None | None | Un- changed |
High | High | None | 3.0.0-3.2.20,4.0.0-4.5.4 | |
| CVE-2026-83460 | Helidon | LRA | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.0.0-4.5.4 | |
| CVE-2026-83097 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | No | 6.5 | Network | Low | High | None | Un- changed |
None | High | High | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83354 | Oracle Coherence | Core | HTTP | No | 6.3 | Network | High | Low | None | Changed | High | None | None | 15.1.1.0.0 | |
| CVE-2026-83488 | Helidon | helidon-microprofile-security | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 4.0.0-4.5.4 | |
| CVE-2026-83346 | Oracle Fusion Middleware Control | Framework | HTTP | No | 5.4 | Network | Low | Low | Required | Changed | Low | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-83458 | Helidon | JSON | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 4.0.0-4.5.4 | |
| CVE-2026-83480 | Helidon | WebSocket | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 4.0.0-4.5.4 | |
| CVE-2026-83459 | Helidon | helidon-media-multipart | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 3.0.0-3.2.20 | |
| CVE-2026-83109 | Oracle Forms | Forms Services, C/S, Charmode | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 12.2.1.19.0, 14.1.2.0.0 | |
| CVE-2026-83416 | Oracle Coherence | Core | HTTP | No | 4.3 | Network | Low | Low | None | Un- changed |
None | None | Low | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-83369 | Oracle Access Manager | Access SDK | HTTP | No | 3.1 | Network | High | Low | None | Un- changed |
None | None | Low | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-83414 | Oracle Coherence | Core | None | No | 2.5 | Local | High | Low | None | Un- changed |
Low | None | None | 15.1.1.0.0 | |
| CVE-2026-83413 | Oracle Coherence | Core | None | No | 1.9 | Local | High | High | None | Un- changed |
None | Low | None | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
This Critical Security Patch Update contains 50 new security patches for Oracle Analytics. 8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83282 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0 | |
| CVE-2026-83269 | Oracle BI Publisher | BI Platform Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83283 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-83268 | Oracle BI Publisher | BI Platform Security | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83304 | Oracle Business Intelligence Enterprise Edition | Analytics Web General | HTTP | Yes | 8.9 | Network | High | None | None | Changed | High | High | Low | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83315 | Oracle BI Publisher | BI Platform Security | SOAP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83335 | Oracle Business Intelligence Enterprise Edition | Analytics Server | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83301 | Oracle Business Intelligence Enterprise Edition | Service Administration UI | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-83310 | Oracle BI Publisher | BI Platform Security | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83305 | Oracle BI Publisher | BI Platform Security | HTTP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83284 | Oracle BI Publisher | BI Platform Security | SOAP | Yes | 8.6 | Network | Low | None | None | Un- changed |
Low | Low | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83267 | Oracle BI Publisher | BI Publisher Security | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83302 | Oracle BI Publisher | BI Publisher Security | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | None | Low | 12.2.1.4.0 | |
| CVE-2026-83309 | Oracle BI Publisher | Web Server | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83303 | Oracle BI Publisher | BI Platform Security | SOAP | No | 8.5 | Network | Low | Low | None | Changed | Low | High | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83311 | Oracle BI Publisher | BI Platform Security | SOAP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83321 | Oracle Business Intelligence Enterprise Edition | Analytics Actions | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83307 | Oracle BI Publisher | BI Platform Security | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83285 | Oracle Business Intelligence Enterprise Edition | BI Search | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 12.2.1.4.0 | |
| CVE-2026-83297 | Oracle BI Publisher | BI Platform Security | LDAP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83308 | Oracle BI Publisher | BI Platform Security | SOAP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83314 | Oracle BI Publisher | Web Service API | SOAP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83299 | Oracle Business Intelligence Enterprise Edition | Analytics Web General | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-83286 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83336 | Oracle Business Intelligence Enterprise Edition | Analytics Server | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83288 | Oracle Business Intelligence Enterprise Edition | BI Search | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83293 | Oracle Business Intelligence Enterprise Edition | FNDN | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-83317 | Oracle Business Intelligence Enterprise Edition | Installation | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83071 | Oracle Business Intelligence Enterprise Edition | Machine Learning | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83290 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83291 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83294 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83313 | Oracle BI Publisher | BI Platform Security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83312 | Oracle BI Publisher | E-Business Suite - XDO | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83319 | Oracle BI Publisher | Web Service API | SOAP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.1.4.0 | |
| CVE-2026-83287 | Oracle Business Intelligence Enterprise Edition | Presentation Services | SOAP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83320 | Oracle BI Publisher | Administration | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83318 | Oracle BI Publisher | Administration | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83270 | Oracle Business Intelligence Enterprise Edition | BI Platform Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83296 | Oracle Business Intelligence Enterprise Edition | BI Search | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83292 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83323 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.5 | Local | High | Low | Required | Changed | High | High | High | 26.01.0.0.0 | |
| CVE-2026-83289 | Oracle Business Intelligence Enterprise Edition | Analytics Web General | SOAP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83295 | Oracle Business Intelligence Enterprise Edition | Presentation Services | SOAP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-83298 | Oracle BI Publisher | BI Platform Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-83273 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 26.01.0.0.0 | |
| CVE-2026-83322 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83325 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83324 | Oracle Business Intelligence Enterprise Edition | BI Platform Security | HTTP | No | 7.1 | Network | High | Low | None | Changed | Low | High | None | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-83316 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 26.01.0.0.0 | |
This Critical Security Patch Update contains 102 new security patches for Oracle Hyperion. 50 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-87230 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87172 | Oracle Hyperion Financial Management | Security | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87188 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87184 | Oracle Hyperion Financial Management | Security | SQL | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87186 | Oracle Hyperion Financial Management | Security | TCP | Yes | 9.6 | Adjacent Network |
Low | None | None | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87128 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87129 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87170 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87214 | Oracle Hyperion Financial Management | Security | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87217 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87223 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.2.26.0.000 | |
| CVE-2026-87189 | Oracle Hyperion Financial Management | Security | Oracle Net | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87173 | Oracle Hyperion Financial Management | Security | TCP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87175 | Oracle Hyperion Financial Management | Security | TCP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87176 | Oracle Hyperion Financial Management | Security | TCP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87179 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87180 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87181 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87185 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87201 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87204 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87224 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87226 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87227 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87182 | Oracle Hyperion Financial Management | Security | None | No | 8.8 | Local | Low | Low | None | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87202 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87238 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87187 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.8 | Adjacent Network |
Low | None | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87171 | Oracle Hyperion Financial Management | Security | HTTPS | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87178 | Oracle Hyperion Financial Management | Security | SQL | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87177 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87219 | Oracle Hyperion Financial Management | Security | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87210 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.3 | Adjacent Network |
Low | None | None | Un- changed |
High | High | Low | 11.2.26.0.000 | |
| CVE-2026-87196 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87197 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87200 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | High | Low | 11.2.26.0.000 | |
| CVE-2026-87228 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87229 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
Low | High | None | 11.2.26.0.000 | |
| CVE-2026-87174 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87231 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87234 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87218 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
None | High | High | 11.2.26.0.000 | |
| CVE-2026-87232 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87241 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87245 | Oracle Hyperion Financial Management | Security | TCP/IP | No | 8.0 | Adjacent Network |
Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87243 | Oracle Hyperion Financial Management | Security | TLS | Yes | 8.0 | Adjacent Network |
High | None | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87216 | Oracle Hyperion Financial Management | Security | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87141 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.26.0.000 | |
| CVE-2026-87147 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.7 | Network | High | High | None | Changed | High | High | None | 11.2.26.0.000 | |
| CVE-2026-87134 | Oracle Hyperion Data Relationship Management | Access and security | TCP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.26.0.000 | |
| CVE-2026-87183 | Oracle Hyperion Financial Management | Security | None | No | 7.7 | Local | Low | High | Required | Changed | High | High | High | 11.2.26.0.000 | |
| CVE-2026-87131 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87132 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87133 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.6 | Network | Low | High | None | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87137 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87144 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87233 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.6 | Network | Low | High | None | Changed | High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87250 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87136 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87139 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87140 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87148 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.2.26.0.000 | |
| CVE-2026-87138 | Oracle Hyperion Data Relationship Management | Access and security | SOAP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.2.26.0.000 | |
| CVE-2026-87190 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87193 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87194 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87199 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.2.26.0.000 | |
| CVE-2026-87203 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87205 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87211 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87221 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.26.0.000 | |
| CVE-2026-87222 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.2.26.0.000 | |
| CVE-2026-87237 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87247 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87215 | Oracle Hyperion Financial Management | Security | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.2.26.0.000 | |
| CVE-2026-87130 | Oracle Hyperion Data Relationship Management | Access and security | SMTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87143 | Oracle Hyperion Data Relationship Management | Access and security | TCP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87198 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87206 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87213 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87212 | Oracle Hyperion Financial Management | Security | SQL | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87235 | Oracle Hyperion Financial Management | Security | SSH | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87195 | Oracle Hyperion Financial Management | Security | TLS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87242 | Oracle Hyperion Financial Management | Security | TLS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.26.0.000 | |
| CVE-2026-87145 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 11.2.26.0.000 | |
| CVE-2026-87239 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87244 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87246 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87207 | Oracle Hyperion Financial Management | Security | SQL | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87135 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87146 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87142 | Oracle Hyperion Data Relationship Management | Access and security | HTTPS | Yes | 7.1 | Network | Low | None | Required | Un- changed |
None | High | Low | 11.2.26.0.000 | |
| CVE-2026-87191 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87192 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87208 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 11.2.26.0.000 | |
| CVE-2026-87209 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87225 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87236 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.26.0.000 | |
| CVE-2026-87249 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.1 | Network | Low | None | Required | Un- changed |
None | High | Low | 11.2.26.0.000 | |
| CVE-2026-87220 | Oracle Hyperion Financial Management | Security | TCP | Yes | 7.1 | Adjacent Network |
Low | None | None | Un- changed |
None | Low | High | 11.2.26.0.000 | |
| CVE-2026-87240 | Oracle Hyperion Financial Management | Security | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
| CVE-2026-87248 | Oracle Hyperion Financial Management | Security | None | No | 6.7 | Local | Low | High | None | Un- changed |
High | High | High | 11.2.26.0.000 | |
This Critical Security Patch Update contains 3 new security patches for Oracle Java SE. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83357 | Oracle GraalVM for JDK | Compiler | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1 | |
| CVE-2026-83408 | Oracle GraalVM for JDK | Compiler | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1 | |
| CVE-2026-83368 | Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Compiler | HTTP | Yes | 7.0 | Network | High | None | None | Un- changed |
High | Low | Low | Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1 | |
This Critical Security Patch Update contains 16 new security patches for Oracle PeopleSoft. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83017 | PeopleSoft Enterprise PeopleTools | Report Distribution | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-82993 | PeopleSoft Enterprise PeopleTools | Business Interlink | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 8.61-8.63 | |
| CVE-2026-73954 | PeopleSoft Enterprise PeopleTools | Business Interlink | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-83014 | PeopleSoft Enterprise PeopleTools | Cube Manager | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 8.61-8.63 | |
| CVE-2026-83019 | PeopleSoft Enterprise PeopleTools | SQR | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | None | High | 8.61-8.63 | |
| CVE-2026-83420 | PeopleSoft Enterprise FIN Engineering Brazil | Engineering | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 9.1 | |
| CVE-2026-83147 | PeopleSoft Enterprise FIN Inventory Brazil | Inventory | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 9.1 | |
| CVE-2026-83018 | PeopleSoft Enterprise PeopleTools | SQR | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-87264 | PeopleSoft Enterprise PeopleTools | Integration Broker | HTTP | No | 7.7 | Network | Low | Low | None | Changed | None | High | None | 8.61-8.63 | |
| CVE-2026-83070 | PeopleSoft Enterprise PRTL Interaction Hub | Enterprise Portal | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 9.1 | |
| CVE-2026-25639 | PeopleSoft Enterprise CC Common Application Objects | Chatbot Framework (Axios) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 9.2 | |
| CVE-2026-73960 | PeopleSoft Enterprise PeopleTools | Ren Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 8.61-8.63 | |
| CVE-2026-73955 | PeopleSoft Enterprise PeopleTools | Charting | HTTP | No | 7.3 | Network | Low | Low | Required | Un- changed |
High | High | None | 8.61-8.63 | |
| CVE-2026-7598 | PeopleSoft Enterprise PeopleTools | File Processing (libssh2) | SSH | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 8.61-8.63 | |
| CVE-2026-83016 | PeopleSoft Enterprise PeopleTools | SQR | None | No | 7.2 | Local | High | High | Required | Changed | High | High | High | 8.61-8.63 | |
| CVE-2026-83015 | PeopleSoft Enterprise PeopleTools | Cube Manager | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 8.61-8.63 | |
This Critical Security Patch Update contains 63 new security patches for Oracle Siebel CRM. 26 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83197 | Siebel Apps - Financial Services | Financial Accounts | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 17.0-26.7 | |
| CVE-2026-83196 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 17.0-26.7 | |
| CVE-2026-83201 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83202 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83229 | Siebel CRM Deployment | Siebel Management Console | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 17.0-26.7 | |
| CVE-2026-83154 | Siebel CRM End User | Open UI | SOAP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83212 | Siebel Apps - Self Service | Helpdesk/Training | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83086 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 22.3-26.7 | |
| CVE-2026-83180 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83199 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83153 | Siebel CRM Deployment | Server Infrastructure | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83208 | Siebel CRM Deployment | Migration | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83210 | Siebel CRM Deployment | Server Infrastructure | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83209 | Siebel CRM Development | Workflow | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83144 | Siebel Apps - Customer Order Management | Order Management | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 17.0-26.7 | |
| CVE-2026-83145 | Siebel Apps - Customer Order Management | Order Management | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 17.0-26.7 | |
| CVE-2026-83074 | Siebel CRM Cloud Applications | Siebel Cloud Manager | SSH | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 22.3-26.7 | |
| CVE-2026-83203 | Siebel CRM End User | Open UI | HTTP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 17.0-26.7 | |
| CVE-2026-83078 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 22.3-26.7 | |
| CVE-2026-83087 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 22.3-26.7 | |
| CVE-2026-83085 | Siebel CRM Cloud Applications | Siebel Cloud Manager | TCP | No | 8.2 | Adjacent Network |
Low | Low | None | Changed | High | Low | Low | 22.3-26.7 | |
| CVE-2026-83215 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 17.0-26.7 | |
| CVE-2026-83181 | Siebel CRM Development | Workspaces | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 17.0-26.7 | |
| CVE-2026-83143 | Siebel Apps - Life Sciences | eDetailing | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83073 | Siebel CRM Cloud Applications | Siebel Cloud Manager | TLS | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 22.3-26.7 | |
| CVE-2026-83191 | Siebel CRM Deployment | Server Infrastructure | TCP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83192 | Siebel CRM End User | Open UI | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-54513 | Siebel CRM Integration | Open Integration (jackson-databind) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 25.12-26.7 | |
| CVE-2026-83220 | Siebel CRM Integration | Event Publish and Subscribe | TLS | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 23.6-26.7 | |
| CVE-2026-83079 | Siebel CRM Cloud Applications | Siebel Cloud Manager | None | No | 7.9 | Local | Low | High | None | Changed | High | High | None | 22.3-26.7 | |
| CVE-2026-82992 | Siebel CRM Deployment | Installation | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83211 | Siebel CRM Deployment | Server Infrastructure | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83214 | Siebel CRM Deployment | Server Infrastructure | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83216 | Siebel CRM Deployment | Server Infrastructure | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83146 | Siebel CRM End User | Open UI | HTTP | No | 7.7 | Network | High | Low | Required | Changed | High | High | None | 17.0-26.7 | |
| CVE-2026-83207 | Siebel CRM Development | Integration - Scripting | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
Low | Low | High | 17.0-26.7 | |
| CVE-2026-83075 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 22.3-26.7 | |
| CVE-2026-83183 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 17.0-26.7 | |
| CVE-2026-83226 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83223 | Siebel CRM Deployment | Siebel Remote | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83222 | Siebel CRM Deployment | Server Infrastructure | Multiple | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 17.0-26.7 | |
| CVE-2026-83225 | Siebel CRM Deployment | Server Infrastructure | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 17.0-26.7 | |
| CVE-2026-83228 | Siebel CRM Deployment | Server Infrastructure | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 17.0-26.7 | |
| CVE-2026-83182 | Siebel CRM Development | Configuration Tools | SQL | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83213 | Siebel CRM End User | Reports | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 17.0-26.7 | |
| CVE-2026-83227 | Siebel CRM Integration | EAI | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83326 | Siebel CRM Integration | Open Integration | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 25.12-26.7 | |
| CVE-2026-50010 | Siebel CRM Integration | Open Integration (Netty) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 25.12-26.7 | |
| CVE-2026-83218 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83193 | Siebel Apps - Life Sciences | Life Sciences | None | No | 7.3 | Local | Low | Low | Required | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83190 | Siebel CRM Deployment | Server Infrastructure | None | No | 7.3 | Local | Low | Low | Required | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83155 | Siebel CRM Deployment | Server Infrastructure | TCP | No | 7.3 | Adjacent Network |
Low | Low | None | Un- changed |
High | None | High | 17.0-26.7 | |
| CVE-2026-73966 | Siebel Apps - Marketing | Marketing | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83195 | Siebel CRM Deployment | Server Infrastructure | TCP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 17.0-26.7 | |
| CVE-2026-83224 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 17.0-26.7 | |
| CVE-2026-83230 | Siebel CRM Deployment | Siebel Management Console | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 17.0-26.7 | |
| CVE-2026-83219 | Siebel CRM Deployment | Server Infrastructure | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-83217 | Siebel CRM End User | Open UI | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 17.0-26.7 | |
| CVE-2026-83221 | Siebel CRM Integration | EAI | SOAP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 17.0-26.7 | |
| CVE-2026-73965 | Siebel CRM Deployment | Cloud Gateway | HTTP | No | 6.8 | Network | High | Low | None | Un- changed |
High | High | None | 17.0-26.7 | |
| CVE-2026-55956 | Siebel CRM Integration | EAI (Apache Tomcat) | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 17.0-26.7 | |
| CVE-2026-83077 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 6.4 | Network | Low | Low | None | Changed | Low | Low | None | 22.3-26.7 | |
| CVE-2026-54515 | Siebel CRM Deployment | Database Upgrade (jackson-databind) | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | Low | None | 25.12-26.7 | |
This Critical Security Patch Update contains 19 new security patches for Oracle Supply Chain. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83261 | Oracle Product Lifecycle Analytics | Core | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 3.6.1 | |
| CVE-2026-83260 | Oracle Agile PLM | Event Java PX | T3, IIOP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 9.3.6 | |
| CVE-2026-87259 | Oracle Agile Engineering Data Management | Engineering Communication Interface | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 6.2.1 | |
| CVE-2026-83264 | Oracle Product Lifecycle Analytics | Installation Issues | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 3.6.1 | |
| CVE-2026-87266 | Oracle Agile PLM | Application Server | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 9.3.6 | |
| CVE-2026-87256 | Oracle Agile PLM | Application Server | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 9.3.6 | |
| CVE-2026-87257 | Oracle Agile PLM | SDK | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 9.3.6 | |
| CVE-2026-87258 | Oracle Agile PLM | Folders, Files & Attachments | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 9.3.6 | |
| CVE-2026-87254 | Oracle Agile PLM | Folders, Files & Attachments | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2026-83262 | Oracle Product Lifecycle Analytics | Installation Issues | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 3.6.1 | |
| CVE-2026-83263 | Oracle Product Lifecycle Analytics | Installation Issues | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 3.6.1 | |
| CVE-2026-87261 | Oracle Agile Engineering Data Management | Engineering Communication Interface | None | No | 7.3 | Local | Low | Low | None | Changed | High | Low | None | 6.2.1 | |
| CVE-2026-87260 | Oracle Agile Engineering Data Management | Engineering Communication Interface | TCP | No | 7.3 | Adjacent Network |
Low | Low | None | Un- changed |
High | High | None | 6.2.1 | |
| CVE-2026-83277 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 7.3 | Local | Low | Low | None | Changed | Low | High | None | 3.6 | |
| CVE-2026-87262 | Oracle Agile Engineering Data Management | Engineering Communication Interface | TCP | Yes | 7.1 | Adjacent Network |
Low | None | None | Un- changed |
High | Low | None | 6.2.1 | |
| CVE-2026-87252 | Oracle Agile PLM | Application Server | HTTPS | Yes | 6.8 | Adjacent Network |
High | None | None | Un- changed |
High | High | None | 9.3.6 | |
| CVE-2026-87253 | Oracle Agile PLM | Web Client | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 9.3.6 | |
| CVE-2026-83274 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 3.6 | |
| CVE-2026-83279 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 3.6 | |
This Critical Security Patch Update contains 2 new security patches for Oracle Utilities Applications. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-83343 | Oracle Utilities Network Management System | System Wide | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3 | |
| CVE-2026-83342 | Oracle Utilities Network Management System | System Wide | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3 | |
This Critical Security Patch Update contains 19 new security patches for Oracle Virtualization. 1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-87273 | Oracle VM VirtualBox | Core | None | No | 8.6 | Local | Low | None | Required | Changed | High | High | High | 7.2.16 | |
| CVE-2026-87268 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 7.2.16 | See Note 1 |
| CVE-2026-87269 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 7.2.16 | See Note 1 |
| CVE-2026-87270 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 7.2.16 | See Note 1 |
| CVE-2026-87271 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 7.2.16 | See Note 1 |
| CVE-2026-87272 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 7.2.16 | |
| CVE-2026-87276 | Oracle VM VirtualBox | Core | None | No | 7.5 | Local | High | Low | Required | Changed | High | High | High | 7.2.16 | |
| CVE-2026-87277 | Oracle VM VirtualBox | Core | RDP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.2.16 | |
| CVE-2026-87278 | Oracle VM VirtualBox | Core | None | No | 6.1 | Local | Low | None | Required | Un- changed |
None | Low | High | 7.2.16 | |
| CVE-2026-87279 | Oracle VM VirtualBox | Core | None | No | 6.1 | Local | Low | Low | None | Un- changed |
None | Low | High | 7.2.16 | |
| CVE-2026-87282 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.16 | |
| CVE-2026-87283 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.16 | |
| CVE-2026-87285 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.16 | |
| CVE-2026-87267 | Oracle VM VirtualBox | Core | RDP | No | 5.3 | Network | High | Low | None | Un- changed |
None | None | High | 7.2.16 | |
| CVE-2026-87275 | Oracle VM VirtualBox | Core | None | No | 4.6 | Local | Low | High | None | Changed | Low | None | Low | 7.2.16 | |
| CVE-2026-87274 | Oracle VM VirtualBox | Core | None | No | 4.4 | Local | High | Low | Required | Un- changed |
None | None | High | 7.2.16 | |
| CVE-2026-87280 | Oracle VM VirtualBox | Core | None | No | 4.2 | Local | Low | High | Required | Un- changed |
None | None | High | 7.2.16 | |
| CVE-2026-87281 | Oracle VM VirtualBox | Core | None | No | 3.2 | Local | Low | High | None | Changed | Low | None | None | 7.2.16 | |
| CVE-2026-87284 | Oracle VM VirtualBox | Core | None | No | 3.2 | Local | Low | High | None | Changed | None | None | Low | 7.2.16 | |