Oracle Critical Security Patch Update Advisory - September 2026

Description

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.

This Critical Security Patch Update contains 673 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at September 2026 Critical Security Patch Update: Executive Summary and Analysis.

Affected Products and Patch Information

Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.

Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.

Affected Products and Versions Patch Availability Document
Helidon, versions 3.0.0-3.2.20, 4.0.0-4.5.4 Helidon
Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.0.0, 14.1.2.1.0 Fusion Middleware
Oracle Agile Engineering Data Management, version 6.2.1 Oracle Supply Chain Products
Oracle Agile PLM, version 9.3.6 Oracle Supply Chain Products
Oracle Agile PLM MCAD Connector, version 3.6 Oracle Supply Chain Products
Oracle Application Testing Suite, version 13.3.0.1 Oracle Application Testing Suite
Oracle Autonomous Health Framework, versions 26.2, 26.3.1, 26.5.3, 26.8 Oracle Autonomous Health Framework
Oracle Banking Branch, versions 14.5.0.0.0-14.9.0.0.0 Contact Support
Oracle Banking Corporate Lending, versions 14.5.0.0.0-14.9.0.0.0 Contact Support
Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0-14.9.0.0.0 Contact Support
Oracle Banking Origination, versions 14.5.0.0.0-14.9.0.0.0 Contact Support
Oracle Banking Treasury Management, versions 14.5.0.0.0-14.9.0.0.0 Contact Support
Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 Oracle Analytics
Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 Oracle Analytics
Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 Oracle Commerce
Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 25.2.201, 26.1.200 Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications MetaSolv Solution Module - ASR, version 70.0.0 Oracle Communications MetaSolv Solution Module - ASR
Oracle Communications Operations Monitor, version 6.1 Oracle Communications Operations Monitor
Oracle Communications Service Catalog and Design, versions 8.0-8.3 Oracle Communications Service Catalog and Design
Oracle Communications Unified Assurance, versions 6.1.1-7.0.0 Oracle Communications Unified Assurance
Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Database Server, versions 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 Database
Oracle E-Business Suite, versions 12.2.3-12.2.15, V16 Oracle E-Business Suite
Oracle Enterprise Manager Base Platform, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Enterprise Manager for Fusion Middleware, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Enterprise Manager for Oracle Database, version 24.1 Oracle Enterprise Manager
Oracle Forms, versions 12.2.1.19.0, 14.1.2.0.0 Fusion Middleware
Oracle Fusion Middleware Control, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle GraalVM Enterprise Edition, version 21.3.19.1 Java SE
Oracle GraalVM for JDK 17, version 23.0.13.1 Java SE
Oracle GraalVM for JDK 21, version 23.1.12.1 Java SE
Oracle Hyperion Data Relationship Management, version 11.2.26.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Financial Management, version 11.2.26.0.0 Oracle Enterprise Performance Management
Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Internet Directory, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle JDeveloper, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Middleware Common Libraries and Tools, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
Oracle Platform Security for Java, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Product Lifecycle Analytics, version 3.6.1 Oracle Supply Chain Products
Oracle Utilities Network Management System, versions 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 25.12.0.0.0-25.12.0.0.3 Oracle Utilities Applications
Oracle VM VirtualBox, version 7.2.16 Virtualization
Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
PeopleSoft Enterprise CC Common Application Objects, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Engineering Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Inventory Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise PeopleTools, versions 8.61-8.63 PeopleSoft
PeopleSoft Enterprise PRTL Interaction Hub, version 9.1 PeopleSoft
Service Delivery Platform, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Siebel Applications, versions 17.0-26.7 Siebel

Risk Matrix Content

Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.

Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.

Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).

Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.

Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.

The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.

Workarounds

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible. Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.

Skipped Security Patch Updates

Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Security Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.

Critical Security Patch Update Supported Products and Versions

Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.

Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.

Credit Statement

The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:

  • Diego Palacios: CVE-2026-87273
  • James Forshaw: CVE-2026-87268, CVE-2026-87269, CVE-2026-87270, CVE-2026-87271, CVE-2026-87272
  • Khalilov M (3ntr0py1337): CVE-2026-87275
  • Kirishiki Yudai: CVE-2026-87279
  • Myeonghun Pak and Seongmin Kim of Team SaturnX: CVE-2026-87267
  • Nathan Tsai: CVE-2026-87274
  • Nebula Security: CVE-2026-87280, CVE-2026-87281, CVE-2026-87282, CVE-2026-87283, CVE-2026-87284, CVE-2026-87285
  • Nhat Anh Vu: CVE-2026-87289
  • Polina Demura: CVE-2026-70755
  • Samet Akilli: CVE-2026-83354
  • Tristan Madani of Talence Security: CVE-2026-87276
  • Wei Ming Tan: CVE-2026-87277, CVE-2026-87278

Upcoming Security Release Dates

Security patches are released on the third Tuesday of each month. The next four dates are:

  • 20 October 2026 (CPU)
  • 17 November 2026 (CSPU)
  • 15 December 2026 (CSPU)
  • 19 January 2027 (CPU)

References

 

Modification History

Date Note
2026-September-15 Rev 1. Initial Release.

 

Oracle Database Products Risk Matrices

This Critical Security Patch Update contains 13 new security patches for Oracle Database Products divided as follows:

  • 11 new security patches for Oracle Database Products
  • 2 new security patches for Oracle Autonomous Health Framework

 

Oracle Database Server Risk Matrix

This Critical Security Patch Update contains 11 new security patches for Oracle Database Products.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  2 of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83348 RDBMS Create DB Link Oracle Net No 8.8 Network Low Low None Un-
changed
High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83160 RDBMS Create Table Oracle Net No 8.8 Network Low Low None Un-
changed
High High High 23.4.0-23.26.3  
CVE-2026-83271 RDBMS Execute on DBMS_REDEFINITION Oracle Net No 8.8 Network Low Low None Un-
changed
High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83272 Oracle Text Create Index Oracle Net No 8.5 Network High Low None Changed High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83351 RDBMS None Oracle Net Yes 8.1 Network High None None Un-
changed
High High High 23.4.0-23.26.3  
CVE-2026-83088 RDBMS Authenticated User Oracle Net No 7.7 Network Low Low None Changed None None High 23.4.0-23.26.3  
CVE-2026-83349 Oracle Net Services Connection Manager Oracle Net Yes 7.5 Network Low None None Un-
changed
None None High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83350 Oracle Net Services Connection Manager Oracle Net Yes 7.5 Network Low None None Un-
changed
None None High 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83333 Oracle Net Services Listener Oracle Net Yes 7.5 Network Low None None Un-
changed
None None High 23.4.0-23.26.3  
CVE-2026-83156 Oracle XML Developers Kit XDKC Oracle Net No 7.5 Network High Low None Un-
changed
High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-83347 Oracle Net Services Listener TCPS Yes 6.5 Network Low None Required Un-
changed
None None High 23.4.0-23.26.3  

Oracle Database Server Client-Only Installations

  • The following Oracle Database Server vulnerabilities included in this Critical Security Patch Update affect client-only installations: CVE-2026-83348 and CVE-2026-83156.

 

Oracle Autonomous Health Framework Risk Matrix

This Critical Security Patch Update contains 2 new security patches, plus additional third party patches noted below, for Oracle Autonomous Health Framework.  1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-14456 Oracle Autonomous Health Framework AHFCOMMON (OpenSSL) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 26.2, 26.3.1, 26.5.3, 26.8  
CVE-2026-75838 Oracle Autonomous Health Framework AHFCOMMON (DOMPurify) HTTP No 4.6 Network Low Low Required Un-
changed
Low Low None 26.8  

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Autonomous Health Framework
    • AHFCOMMON: CVE-2026-61308 [VEX Justification: vulnerable_code_not_in_execute_path].
    • CLISDK (pip): CVE-2026-13346 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].

 

Oracle Application Testing Suite Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Application Testing Suite.  None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83149 Oracle Application Testing Suite Test Manager for Web Apps HTTP No 9.1 Network Low Low None Changed High Low Low 13.3.0.1  
CVE-2026-83148 Oracle Application Testing Suite Test Manager for Web Apps HTTP No 8.8 Network Low Low None Un-
changed
High High High 13.3.0.1  
CVE-2026-83150 Oracle Application Testing Suite OpenScript None No 7.0 Local High None Required Un-
changed
High High High 13.3.0.1  

 

Oracle Commerce Risk Matrix

This Critical Security Patch Update contains 27 new security patches for Oracle Commerce.  16 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83234 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 11.4.0  
CVE-2026-83236 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 8.2 Network Low None Required Changed High Low None 11.4.0  
CVE-2026-83248 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.2 Network Low None None Un-
changed
Low None High 11.4.0  
CVE-2026-83245 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83246 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83258 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83254 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge TCP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83255 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge TCP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83256 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge TCP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-83253 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller None No 7.8 Local Low None Required Un-
changed
High High High 11.4.0  
CVE-2026-83247 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge None No 7.8 Local Low None Required Un-
changed
High High High 11.4.0  
CVE-2026-83249 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge None No 7.8 Local High Low None Changed High High High 11.4.0  
CVE-2026-83233 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 7.7 Network Low Low None Changed High None None 11.4.0  
CVE-2026-83243 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 7.7 Network Low Low None Changed High None None 11.4.0  
CVE-2026-83235 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-83241 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 7.5 Network High None Required Un-
changed
High High High 11.4.0  
CVE-2026-83257 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP No 7.5 Network High Low None Un-
changed
High High High 11.4.0  
CVE-2026-83242 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 11.4.0  
CVE-2026-83237 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.4.0  
CVE-2026-83238 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.4.0  
CVE-2026-83259 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.4.0  
CVE-2026-83240 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge None No 7.1 Local Low Low None Un-
changed
None High High 11.4.0  
CVE-2026-83244 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge TCP/IP Yes 7.1 Adjacent
Network
High None None Un-
changed
High Low High 11.4.0  
CVE-2026-83252 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 7.0 Network High None None Un-
changed
High Low Low 11.4.0  
CVE-2026-83239 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller None No 7.0 Local High Low None Un-
changed
High High High 11.4.0  
CVE-2026-83250 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 6.5 Network High None None Un-
changed
High None Low 11.4.0  
CVE-2026-83251 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge TLS Yes 6.5 Network High None None Un-
changed
Low None High 11.4.0  

 

Oracle Communications Risk Matrix

This Critical Security Patch Update contains 31 new security patches for Oracle Communications.  23 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-44024 Oracle Communications Unified Assurance Core (Fluentd) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-17544 Oracle Communications Unified Assurance Core (PHP) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 7.0.0  
CVE-2026-71290 Oracle Communications Unified Assurance Core (Apache HttpClient) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-73194 Oracle Communications Unified Assurance Core (DBI) HTTP Yes 9.1 Network Low None None Un-
changed
High None High 6.1.1-7.0.0  
CVE-2026-83418 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP HTTP No 8.2 Network High Low None Changed High High None 26.1.200, 25.2.201  
CVE-2026-67355 Oracle Communications Unified Assurance Core (Guzzle) HTTP Yes 8.1 Network High None None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-64849 Oracle Communications Unified Assurance Core (MLflow) HTTP No 8.1 Network Low Low None Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-54518 Oracle Communications Unified Assurance Core (jackson-databind) HTTP Yes 8.1 Network High None None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-39822 Oracle Communications Unified Assurance Core (Golang Go) None No 7.8 Local Low Low None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-34477 Oracle Communications MetaSolv Solution Module - ASR Access Service Request (Apache Log4j) Multiple Yes 7.5 Network Low None None Un-
changed
None High None 70.0.0  
CVE-2026-9563 Oracle Communications Service Catalog and Design Third Party Patch (Eclipse Parsson) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.0-8.3  
CVE-2026-73508 Oracle Communications Service Catalog and Design Third Party Patch (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.0-8.1  
CVE-2026-66299 Oracle Communications Unified Assurance Core (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-55952 Oracle Communications Unified Assurance Core (Erlang/OTP) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 7.0.0  
CVE-2026-50734 Oracle Communications Unified Assurance Message Bus (Apache ActiveMQ) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-57220 Oracle Communications Unified Assurance Message Bus (Pivotal RabbitMQ) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 7.0.0  
CVE-2026-83417 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP HTTP/2 Yes 7.1 Adjacent
Network
Low None None Un-
changed
High Low None 26.1.200, 25.2.201  
CVE-2026-49284 Oracle Communications Unified Assurance Core (SimpleSAMLphp) HTTP No 7.1 Network Low Low None Un-
changed
Low High None 6.1.1-7.0.0  
CVE-2026-41239 Oracle Communications Operations Monitor Mediation Engine (DOMPurify) HTTP Yes 6.8 Network High None Required Un-
changed
High High None 6.1  
CVE-2026-41989 Oracle Communications Unified Assurance Core (libgcrypt) None No 6.7 Local High None None Un-
changed
None High High 6.1.1-7.0.0  
CVE-2026-59943 Oracle Communications Unified Assurance Core (Dompdf) HTTP Yes 6.5 Network Low None None Un-
changed
None Low Low 6.1.1-7.0.0  
CVE-2026-19880 Oracle Communications Unified Assurance Core (logback) HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 6.1.1-7.0.0  
CVE-2026-61109 Oracle Communications Unified Assurance Core (MySQL Server) MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-58520 Oracle Communications Unified Assurance Core (MediaWiki) HTTP Yes 6.1 Network Low None Required Changed Low Low None 6.1.1-7.0.0  
CVE-2026-13006 Oracle Communications Unified Assurance Core (logback) None No 6.0 Local Low High None Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-49844 Oracle Communications Unified Assurance Core (Apache Log4j) HTTP Yes 5.9 Network High None None Un-
changed
None High None 6.1.1-7.0.0  
CVE-2026-83419 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 26.1.200, 25.2.201  
CVE-2026-48998 Oracle Communications Unified Assurance Core (Guzzle PSR-7) HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 6.1.1-7.0.0  
CVE-2026-63308 Oracle Communications Unified Assurance Core (Helm) HTTP Yes 4.3 Network Low None Required Un-
changed
None None Low 7.0.0  
CVE-2026-13758 Oracle Communications Unified Assurance Core (CryptX) HTTP Yes 3.7 Network High None None Un-
changed
None None Low 6.1.1-7.0.0  
CVE-2026-12590 Oracle Communications Unified Assurance Core (Node.js) HTTP Yes 3.7 Network High None None Un-
changed
None None Low 6.1.1-7.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-34477 also addresses CVE-2026-34478 and CVE-2026-34480.
  • The patch for CVE-2026-48998 also addresses CVE-2026-49214, CVE-2026-55766, and CVE-2026-59882.
  • The patch for CVE-2026-61109 also addresses CVE-2026-46936, CVE-2026-47012, CVE-2026-47023, CVE-2026-47052, CVE-2026-47064, CVE-2026-60145, CVE-2026-60163, CVE-2026-60177, CVE-2026-60178, CVE-2026-60182, CVE-2026-60183, CVE-2026-60184, CVE-2026-60185, CVE-2026-60186, CVE-2026-60187, CVE-2026-60188, CVE-2026-60189, CVE-2026-60190, CVE-2026-60191, CVE-2026-60315, CVE-2026-60316, CVE-2026-60331, CVE-2026-60332, CVE-2026-60585, CVE-2026-60747, CVE-2026-61081, CVE-2026-61094, and CVE-2026-61096.
  • The patch for CVE-2026-41239 also addresses CVE-2026-0540, CVE-2026-41238, and CVE-2026-41240.
  • The patch for CVE-2026-55952 also addresses CVE-2026-48855, CVE-2026-48856, CVE-2026-48858, CVE-2026-48860, CVE-2026-49759, CVE-2026-49760, CVE-2026-53422, CVE-2026-54886, CVE-2026-54887, and CVE-2026-55950.
  • The patch for CVE-2026-73194 also addresses CVE-2026-10879, CVE-2026-14380, CVE-2026-14739, CVE-2026-14740, CVE-2026-73193, and CVE-2026-9698.
  • The patch for CVE-2026-64849 also addresses CVE-2026-10803, CVE-2026-13484, CVE-2026-3198, CVE-2026-4035, CVE-2026-69146, CVE-2026-69148, and CVE-2026-8147.
  • The patch for CVE-2026-73508 also addresses CVE-2026-44249, CVE-2026-45416, CVE-2026-45673, CVE-2026-45674, CVE-2026-47691, CVE-2026-50010, CVE-2026-50020, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-59898, CVE-2026-59899, CVE-2026-59901, and CVE-2026-59921.
  • The patch for CVE-2026-59943 also addresses CVE-2026-55554, CVE-2026-55555, CVE-2026-56722, CVE-2026-59941, and CVE-2026-59942.
  • The patch for CVE-2026-67355 also addresses CVE-2026-55568, CVE-2026-55767, CVE-2026-59883, CVE-2026-67339, CVE-2026-67353, and CVE-2026-67354.
  • The patch for CVE-2026-41989 also addresses CVE-2026-41990.
  • The patch for CVE-2026-57220 also addresses CVE-2026-57211, CVE-2026-57212, CVE-2026-57213, CVE-2026-57214, CVE-2026-57215, CVE-2026-57216, CVE-2026-57217, CVE-2026-57218, CVE-2026-57219, and CVE-2026-57221.
  • The patch for CVE-2026-58520 also addresses CVE-2026-13706, CVE-2026-13707, CVE-2026-14358, CVE-2026-14363, CVE-2026-58024, CVE-2026-58025, CVE-2026-58026, CVE-2026-58027, CVE-2026-58028, CVE-2026-58029, CVE-2026-58030, CVE-2026-58032, CVE-2026-58033, CVE-2026-58037, CVE-2026-58038, CVE-2026-58517, CVE-2026-58521, and CVE-2026-8857.
  • The patch for CVE-2026-39822 also addresses CVE-2026-42505.
  • The patch for CVE-2026-54518 also addresses CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, and CVE-2026-54517.
  • The patch for CVE-2026-44024 also addresses CVE-2026-44025, CVE-2026-44160, and CVE-2026-44161.

 

Oracle E-Business Suite Risk Matrix

This Critical Security Patch Update contains 159 new security patches for Oracle E-Business Suite.  19 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (September 2026), My Oracle Support Note KA923.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83327 Oracle Applications Framework Personalization SOAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83452 Oracle Document Management and Collaboration Internal Operations HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83462 Oracle Mobile Application Server MWA Terminal Server TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83120 Oracle Alert Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83163 Oracle Application Object Library Attachments / File Upload HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83205 Oracle Applications Framework Personalization HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83329 Oracle Applications Framework Personalization HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.9-12.2.15  
CVE-2026-83331 Oracle Applications Framework Personalization HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.9-12.2.15  
CVE-2026-83338 Oracle Applications Manager Oracle Diagnostics Interfaces HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83168 Oracle Applications Manager Oracle Diagnostics Interfaces HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-87150 Oracle Bills of Material Setup Workbench HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83445 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-87162 Oracle Contract Lifecycle Management for Public Sector Award/PO HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.13-12.2.15  
CVE-2026-87165 Oracle Contract Lifecycle Management for Public Sector ECC For Award and IDV HTTP No 8.8 Network Low Low None Un-
changed
High High High V16  
CVE-2026-83479 Oracle Contracts Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.14-12.2.15  
CVE-2026-83164 Oracle Customer Interaction History Outcome-Result HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83165 Oracle Customer Interaction History User Interface HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83456 Oracle Demand Signal Repository Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83194 Oracle Depot Repair Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.10-12.2.15  
CVE-2026-83454 Oracle Document Management and Collaboration Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83121 Oracle Marketing Audience HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83444 Oracle Product Hub Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-87155 Oracle Product Hub Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-87163 Oracle Purchasing Other issue HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83125 Oracle Report Manager Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83122 Oracle Report Manager Internal Operations HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83124 Oracle Sales Online Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83090 Oracle Spares Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83136 Oracle Spares Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83137 Oracle Spares Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83119 Oracle User Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.6-12.2.15  
CVE-2026-83189 Oracle User Management Proxy User Delegation HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83135 Oracle iStore Shopping Cart HTTP No 8.7 Network Low Low Required Changed High High None 12.2.3-12.2.15  
CVE-2026-83449 Oracle Bills of Material Internal Operations HTTP No 8.5 Network Low Low None Changed High None Low 12.2.3-12.2.15  
CVE-2026-83425 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTP No 8.5 Network Low Low None Changed High None Low 12.2.12-12.2.15  
CVE-2026-87161 Oracle HRMS (India) Internal Operations HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-83490 Oracle iRecruitment Internal Operations HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-83083 Oracle Marketing Audience HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-83451 Oracle Product Workbench Internal Operations HTTP No 8.5 Network High Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-83172 Oracle Sales Online OSO Other HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-87125 Oracle Financials for Asia/Pacific Internal Operations HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.8-12.2.15  
CVE-2026-83435 Oracle Bills of Material Internal Operations HTTP No 8.2 Network High Low None Changed High High None 12.2.13-12.2.15  
CVE-2026-83438 Oracle Engineering Internal Operations HTTP No 8.2 Network High Low None Changed High High None 12.2.3-12.2.15  
CVE-2026-83465 Oracle Mobile Application Server MWA Terminal Server HTTP Yes 8.2 Network Low None Required Changed None Low High 12.2.3-12.2.15  
CVE-2026-83461 Oracle Mobile Application Server MWA Terminal Server TCP Yes 8.2 Network Low None None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83089 Oracle Alert Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83072 Oracle Applications Framework Search Bean [Incl. Advanced] HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83447 Oracle Bills of Material Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83448 Oracle Bills of Material Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83174 Oracle CRM Technical Foundation Application Framework HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83428 Oracle Demand Signal Repository Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83429 Oracle Demand Signal Repository Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83455 Oracle Demand Signal Repository Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83457 Oracle Demand Signal Repository Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
None High High 12.2.3-12.2.15  
CVE-2026-83432 Oracle Depot Repair Estimate and Actual Charges HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83446 Oracle Financials Common Modules Common Components HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-87159 Oracle HRMS (India) Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-87152 Oracle Installed Base Create Item Instance HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83132 Oracle iStore Shopping Cart HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83464 Oracle Mobile Application Server MWA Terminal Server TCP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83177 Oracle One-to-One Fulfillment Documents HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83169 Oracle One-to-One Fulfillment Java Server Issues HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-87157 Oracle Order Management Product Diagnostic Tools HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.4-12.2.15  
CVE-2026-87153 Oracle Product Hub Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-87154 Oracle Product Hub Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83430 Oracle Product Workbench Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83434 Oracle Product Workbench Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83152 Oracle Project Intelligence Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-87167 Oracle Purchasing G-Invoicing HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.11-12.2.15  
CVE-2026-87168 Oracle Purchasing G-Invoicing HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.10-12.2.15  
CVE-2026-87166 Oracle Purchasing Other issue HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-87265 Oracle Purchasing Other issue HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83477 Oracle Work in Process Workbenches TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83483 Oracle Advanced Benefits Self-serv What-if Analysis HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-83178 Oracle Application Object Library Core HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-83157 Oracle Applications Manager Command Line - RapidClone HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-83450 Oracle Bills of Material Setup Workbench HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-83170 Oracle One-to-One Fulfillment Documents UDP No 8.0 Adjacent
Network
Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83138 Oracle Spares Management Internal Operations HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-83118 Applications DBA AD Utilities None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83159 Applications DBA ADPatch None No 7.8 Local Low None Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83356 Enterprise Command Center Framework Security HTTP No 7.7 Network Low Low None Changed High None None V16  
CVE-2026-87151 Oracle Bills of Material Setup Workbench HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83166 Oracle Customer Interaction History Outcome-Result HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83437 Oracle Engineering Change Management HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83141 Oracle Field Service Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-87124 Oracle iRecruitment Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83134 Oracle iStore Shopping Cart HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83084 Oracle Marketing Audience HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83116 Oracle Order Management Product Diagnostic Tools HTTP No 7.7 Network Low Low None Changed High None None 12.2.5-12.2.15  
CVE-2026-83485 Oracle Product Hub Item Catalog HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83486 Oracle Product Hub Item Catalog HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83487 Oracle Product Hub Item Catalog HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83142 Oracle Proposals Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-87127 Oracle Purchasing G-Invoicing HTTP No 7.7 Network Low Low None Changed High None None 12.2.10-12.2.15  
CVE-2026-83129 Oracle Sales Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83127 Oracle Sales Offline Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83131 Oracle Web Applications Desktop Integrator File download HTTPS No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-83091 Oracle Field Service Internal Operations HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 12.2.3-12.2.15  
CVE-2026-83126 Oracle Sales Online Internal Operations HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-83167 Oracle Application Object Library Core HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83115 Oracle Applications Manager Command Line - RapidClone HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83341 Oracle Applications Manager Command Line - RapidClone HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83133 Oracle iStore Shopping Cart HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83110 Oracle Marketing Audience HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83463 Oracle Mobile Application Server MWA Terminal Server TCP Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83114 Oracle Quality Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83128 Oracle Sales Offline Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83204 Oracle Sourcing Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83184 Oracle Application Object Library Core HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83162 Oracle Application Object Library Core HTTPS Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83185 Oracle Common Applications CRM User Management Framework HTTP No 7.3 Network Low Low Required Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83117 Applications DBA AD Utilities HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83328 Oracle Applications Framework Personalization HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83176 Oracle Common Applications CRM User Management Framework HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83481 Oracle Contracts Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.14-12.2.15  
CVE-2026-83482 Oracle Contracts Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.14-12.2.15  
CVE-2026-83188 Oracle Depot Repair Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83453 Oracle Document Management and Collaboration Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83112 Oracle Lease and Finance Management Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.7-12.2.15  
CVE-2026-83082 Oracle Marketing Audience HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83440 Oracle Product Hub Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83442 Oracle Product Hub Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-83332 Oracle Applications Framework Personalization HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.9-12.2.15  
CVE-2026-83158 Oracle Applications Manager Command Line - RapidClone None No 7.1 Local Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83179 Oracle Common Applications Calendar Applications Calendar HTTP No 7.1 Network High Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-83186 Oracle Common Applications Calendar Applications Calendar HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-83187 Oracle Common Applications Calendar Applications Calendar HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-87149 Oracle Contract Lifecycle Management for Public Sector Award/PO HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.8-12.2.15  
CVE-2026-83436 Oracle Depot Repair Recall Management HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83092 Oracle Field Service Internal Operations HTTP No 7.1 Network High Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-87160 Oracle HRMS (India) Internal Operations HTTPS No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-83171 Oracle One-to-One Fulfillment Documents HTTP No 7.1 Network High Low None Changed High None Low 12.2.3-12.2.15  
CVE-2026-83173 Oracle One-to-One Fulfillment Documents HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-87158 Oracle Order Management Enterprise Command Center HTTP No 7.1 Network Low Low None Un-
changed
High Low None V16  
CVE-2026-83111 Oracle Partner Management Internal Operations HTTP No 7.1 Network High Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-87156 Oracle Product Hub Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-83161 Oracle Project Intelligence Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-83113 Oracle Quality Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-87126 Oracle Report Manager Reports Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83123 Oracle Report Manager Internal Operations HTTPS No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83130 Oracle Site Hub Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-83484 Oracle US Federal Human Resources Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-83044 Oracle XML Gateway Install HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83300 Oracle XML Gateway Install HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83345 Oracle XML Gateway Install HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83352 Oracle XML Gateway Install HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-83076 Oracle HR Intelligence Internal Operations HTTP No 6.8 Network High Low None Un-
changed
None High High 12.2.3-12.2.15  
CVE-2026-83491 Oracle iRecruitment Internal Operations TCP Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83441 Oracle Product Hub Internal Operations HTTP No 6.8 Network High Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83175 Oracle Application Object Library Core HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83443 Oracle Assets Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83433 Oracle Depot Repair Depot Repair Diagnostics HTTP No 6.5 Network Low High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-83140 Oracle Field Service Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-83200 Oracle Process Manufacturing Intelligence Internal Operations Oracle Net No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70755 Oracle Web Applications Desktop Integrator File download HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-87169 Oracle Contract Lifecycle Management for Public Sector Wage Determination Online HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-83198 Oracle Field Service Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-83431 Oracle Product Workbench WebUI HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  

 

Oracle Enterprise Manager Risk Matrix

This Critical Security Patch Update contains 7 new security patches for Oracle Enterprise Manager.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.

Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the September 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update September 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU350.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-41635 Oracle Enterprise Manager Base Platform Agent Next Gen (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 13.5, 24.1  
CVE-2026-83355 Oracle Enterprise Manager for Fusion Middleware Metrics HTTP Yes 9.8 Network Low None None Un-
changed
High High High 13.5, 24.1  
CVE-2026-2332 Oracle Enterprise Manager Base Platform OMS (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 24.1  
CVE-2026-83068 Oracle Enterprise Manager for Oracle Database Core HTTP No 7.7 Network Low Low None Changed High None None 24.1  
CVE-2026-62597 Oracle Enterprise Manager Base Platform Event Management SOAP No 6.5 Network Low Low None Un-
changed
None High None 13.5, 24.1  
CVE-2026-49844 Oracle Enterprise Manager Base Platform OMS (Apache Log4j) HTTP Yes 5.9 Network High None None Un-
changed
None High None 13.5, 24.1  
CVE-2025-68161 Oracle Enterprise Manager Base Platform Diagnostic Kit (Apache Log4j) HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 13.5, 24.1  

Additional CVEs addressed are:

  • The patch for CVE-2026-41635 also addresses CVE-2026-41409 and CVE-2026-42779.

 

Oracle Financial Services Applications Risk Matrix

This Critical Security Patch Update contains 6 new security patches for Oracle Financial Services Applications.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-87164 Oracle Banking Branch Reports HTTP No 8.0 Network High Low Required Changed High High High 14.5.0.0.0-14.9.0.0.0  
CVE-2026-83081 Oracle Banking Corporate Lending Core HTTPS Yes 8.0 Adjacent
Network
High None None Changed High High None 14.5.0.0.0-14.9.0.0.0  
CVE-2026-83489 Oracle Banking Origination Onboarding Batch Processes HTTP No 7.5 Network High Low None Un-
changed
High High High 14.5.0.0.0-14.9.0.0.0  
CVE-2026-34480 Oracle Banking Treasury Management Infrastructure (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 14.5.0.0.0-14.9.0.0.0  
CVE-2026-83080 Oracle Banking Branch Reports HTTP No 7.1 Network High Low Required Un-
changed
High High High 14.5.0.0.0-14.9.0.0.0  
CVE-2026-83206 Oracle Banking Corporate Lending Process Management Base HTTP No 7.1 Network High Low Required Un-
changed
High High High 14.5.0.0.0-14.9.0.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-34480 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, and CVE-2026-34479.

 

Oracle Fusion Middleware Risk Matrix

This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware.  78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71133 Oracle Access Manager Authentication Engine HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83099 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83059 Oracle Internet Directory OID LDAP Server LDAP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83020 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83021 Oracle WebLogic Server Web Container HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0  
CVE-2026-71163 Oracle Access Manager Authentication Engine HTTP No 9.9 Network Low Low None Changed High High Low 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73945 Oracle Access Manager Authentication Engine HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83055 Oracle Internet Directory OID LDAP Server LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83056 Oracle Internet Directory OID LDAP Server LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83057 Oracle Internet Directory OID LDAP Server LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83058 Oracle Internet Directory OID LDAP Server LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73948 Oracle WebCenter Portal Composer HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83039 Oracle WebCenter Portal Composer HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83031 Oracle WebCenter Sites WebCenter Sites HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83038 Oracle WebLogic Server TopLink Integration HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-82999 Service Delivery Platform Messaging Enabler HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-82997 Service Delivery Platform Messaging Enabler T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-82998 Service Delivery Platform Messaging Enabler T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73950 Oracle Access Manager Authentication Engine HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73947 Oracle Access Manager Authentication Engine HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73940 Oracle Access Manager Authentication Engine T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-47065 Oracle Access Manager Third Party (Apache Mina) TCP/IP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83232 Oracle Data Integrator Console / Repository Explorer HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83094 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83095 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83098 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83100 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83108 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-70913 Oracle Identity Manager Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83042 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83054 Oracle Internet Directory OID LDAP Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83060 Oracle Internet Directory OID LDAP Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83061 Oracle Internet Directory OID LDAP Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83062 Oracle Internet Directory OID LDAP Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83066 Oracle Internet Directory OID LDAP Server T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73961 Oracle JDeveloper ADF Faces HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-82994 Oracle Platform Security for Java Centralized Thirdparty Jars LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-82995 Oracle Platform Security for Java Centralized Thirdparty Jars SOAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83339 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73956 Oracle WebCenter Portal Composer HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73953 Oracle WebCenter Portal Portlet Services HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73963 Oracle WebCenter Portal Portlet Services HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83035 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83036 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83037 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-70756 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-70757 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-70748 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83000 Service Delivery Platform Messaging Enabler HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83151 Service Delivery Platform Messaging Enabler SOAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73962 Oracle Access Manager Authentication Engine HTTPS No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83029 Oracle Managed File Transfer MFT Runtime Server HTTP No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83043 Oracle WebCenter Portal Composer HTTP Yes 9.6 Network Low None Required Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83040 Oracle WebCenter Portal Portlet Services SOAP Yes 9.6 Network Low None Required Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83027 Oracle Identity Manager Connector Core TLS Yes 9.3 Adjacent
Network
Low None None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73957 Oracle WebCenter Portal Portlet Services HTTP Yes 9.3 Network Low None Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73944 Oracle Access Manager Authentication Engine HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73946 Oracle Access Manager Authentication Engine HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83001 Oracle Access Manager Authentication Engine HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83103 Oracle Forms Forms Services, C/S, Charmode HTTP No 9.1 Network Low High None Changed High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83107 Oracle Forms Forms Services, C/S, Charmode HTTP No 9.1 Network Low High None Changed High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83104 Oracle Forms Forms Services, C/S, Charmode TCP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83006 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73952 Oracle WebCenter Portal Portlet Services HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83064 Oracle WebCenter Portal Runtime Tools HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83105 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 9.0 Network High None None Changed High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83411 Oracle Coherence Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83410 Oracle Coherence Core Multiple No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83069 Oracle Fusion Middleware Control Framework HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-71047 Oracle Identity Manager Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73942 Oracle Identity Manager OIM Legacy UI HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83340 Oracle Identity Manager Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-70915 Oracle Identity Manager Core T3, IIOP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83306 Oracle JDeveloper Resource Catalog Services HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83423 Oracle JDeveloper Security Framework HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83005 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83009 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83013 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83008 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73959 Oracle WebCenter Portal Composer HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73949 Oracle WebCenter Portal Portlet Services HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83053 Oracle WebCenter Portal Runtime Tools HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83032 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83033 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73926 Oracle Access Manager Authentication Engine HTTP No 8.7 Network Low High None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83025 Oracle Identity Manager Connector Core TCP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73941 Oracle Access Manager Authentication Engine HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83093 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83023 Oracle Identity Manager Connector Core HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83002 Oracle Access Manager Authentication Engine HTTP No 8.5 Network High Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83007 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83003 Oracle WebCenter Enterprise Capture Client Bundle SOAP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83045 Oracle WebCenter Portal Runtime Tools HTTP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83049 Oracle WebCenter Portal Security Framework HTTP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83026 Oracle Identity Manager Connector Core TLS Yes 8.3 Adjacent
Network
High None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83030 Oracle Managed File Transfer MFT Runtime Server T3, IIOP No 8.3 Network Low Low None Un-
changed
Low High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83266 Oracle JDeveloper Resource Catalog Services HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83265 Oracle Web Services Manager Web Services Agent HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83047 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83439 Helidon helidon-security-providers-idcs-mapper HTTP No 8.1 Network Low Low None Un-
changed
High High None 3.0.0-3.2.20,4.0.0-4.5.4  
CVE-2026-73958 Oracle Access Manager Authentication Engine HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83412 Oracle Coherence Core TCP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83101 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83422 Oracle Identity Manager OIM Legacy UI HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83067 Oracle JDeveloper ADF Shared Components HTTP No 8.1 Network Low Low None Un-
changed
None High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83011 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83010 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.1 Network Low High Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73951 Oracle WebCenter Portal Portlet Services HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83096 Oracle Forms Forms Services, C/S, Charmode HTTP No 7.9 Network High Low Required Changed High High Low 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83022 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 7.9 Adjacent
Network
High None Required Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83024 Oracle Identity Manager Connector Core None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83337 Oracle Middleware Common Libraries and Tools Remote Diagnostic Agent None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-82996 Oracle Platform Security for Java Centralized Thirdparty Jars None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83353 Oracle WebCenter Content Content Server None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83012 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83041 Oracle WebCenter Portal Portlet Services HTTP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83048 Oracle WebCenter Portal Runtime Tools HTTP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73943 Oracle Identity Manager OIM Legacy UI HTTP No 7.6 Network Low High None Changed High Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83052 Oracle WebCenter Portal Runtime Tools HTTP No 7.6 Network Low High None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83330 Helidon WebSocket HTTP Yes 7.5 Network Low None None Un-
changed
None None High 4.0.0-4.5.4  
CVE-2026-87289 Helidon helidon-webserver-static-content HTTP Yes 7.5 Network Low None None Un-
changed
None None High 4.0.0-4.5.4  
CVE-2026-83276 Helidon helidon-webclient-http2 HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 4.0.0-4.5.4  
CVE-2026-83280 Helidon helidon-webserver-http2 HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 4.0.0-4.5.4  
CVE-2026-83281 Helidon helidon-webserver TCP Yes 7.5 Network Low None None Un-
changed
None None High 4.0.0-4.5.4  
CVE-2026-83415 Oracle Coherence Core HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83106 Oracle Forms Forms Services, C/S, Charmode HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83028 Oracle Identity Manager Connector Core TLS Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83424 Oracle JDeveloper Oracle JDeveloper HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83051 Oracle WebCenter Portal Runtime Tools HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83065 Oracle WebCenter Portal Runtime Tools HTTPS Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-83034 Oracle WebCenter Sites WebCenter Sites HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83102 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83334 Oracle Web Services Manager Web Services Security SOAP Yes 7.4 Network High None None Un-
changed
High None High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83344 Oracle Identity Manager Connector Database Application Table HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83063 Oracle Internet Directory OID LDAP Server LDAP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83004 Oracle WebCenter Enterprise Capture Client Bundle None No 7.2 Local High Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83046 Oracle WebCenter Portal Runtime Tools HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83050 Oracle WebCenter Portal Runtime Tools HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83231 Helidon helidon-dbclient-mongodb HTTP Yes 7.0 Network High None None Un-
changed
High Low Low 3.0.0-3.2.20,4.0.0-4.5.4  
CVE-2026-83278 Helidon helidon-integrations-neo4j HTTPS Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 3.0.0-3.2.20,4.0.0-4.5.4  
CVE-2026-83460 Helidon LRA HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.0.0-4.5.4  
CVE-2026-83097 Oracle Forms Forms Services, C/S, Charmode HTTP No 6.5 Network Low High None Un-
changed
None High High 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83354 Oracle Coherence Core HTTP No 6.3 Network High Low None Changed High None None 15.1.1.0.0  
CVE-2026-83488 Helidon helidon-microprofile-security HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 4.0.0-4.5.4  
CVE-2026-83346 Oracle Fusion Middleware Control Framework HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-83458 Helidon JSON HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 4.0.0-4.5.4  
CVE-2026-83480 Helidon WebSocket HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 4.0.0-4.5.4  
CVE-2026-83459 Helidon helidon-media-multipart HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 3.0.0-3.2.20  
CVE-2026-83109 Oracle Forms Forms Services, C/S, Charmode HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 12.2.1.19.0, 14.1.2.0.0  
CVE-2026-83416 Oracle Coherence Core HTTP No 4.3 Network Low Low None Un-
changed
None None Low 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-83369 Oracle Access Manager Access SDK HTTP No 3.1 Network High Low None Un-
changed
None None Low 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-83414 Oracle Coherence Core None No 2.5 Local High Low None Un-
changed
Low None None 15.1.1.0.0  
CVE-2026-83413 Oracle Coherence Core None No 1.9 Local High High None Un-
changed
None Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  

 

Oracle Analytics Risk Matrix

This Critical Security Patch Update contains 50 new security patches for Oracle Analytics.  8 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83282 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0  
CVE-2026-83269 Oracle BI Publisher BI Platform Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83283 Oracle Business Intelligence Enterprise Edition Platform Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-83268 Oracle BI Publisher BI Platform Security HTTP No 9.1 Network Low High None Changed High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83304 Oracle Business Intelligence Enterprise Edition Analytics Web General HTTP Yes 8.9 Network High None None Changed High High Low 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83315 Oracle BI Publisher BI Platform Security SOAP No 8.8 Network Low Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83335 Oracle Business Intelligence Enterprise Edition Analytics Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83301 Oracle Business Intelligence Enterprise Edition Service Administration UI HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-83310 Oracle BI Publisher BI Platform Security HTTP No 8.7 Network Low Low Required Changed High High None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83305 Oracle BI Publisher BI Platform Security HTTP Yes 8.6 Network Low None None Un-
changed
High Low Low 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83284 Oracle BI Publisher BI Platform Security SOAP Yes 8.6 Network Low None None Un-
changed
Low Low High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83267 Oracle BI Publisher BI Publisher Security HTTP No 8.5 Network Low Low None Changed High Low None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83302 Oracle BI Publisher BI Publisher Security HTTP No 8.5 Network Low Low None Changed High None Low 12.2.1.4.0  
CVE-2026-83309 Oracle BI Publisher Web Server HTTP No 8.5 Network Low Low None Changed High Low None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83303 Oracle BI Publisher BI Platform Security SOAP No 8.5 Network Low Low None Changed Low High None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83311 Oracle BI Publisher BI Platform Security SOAP No 8.5 Network Low Low None Changed High Low None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83321 Oracle Business Intelligence Enterprise Edition Analytics Actions HTTP No 8.5 Network Low Low None Changed High Low None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83307 Oracle BI Publisher BI Platform Security HTTP No 8.3 Network Low Low None Un-
changed
High High Low 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83285 Oracle Business Intelligence Enterprise Edition BI Search HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.1.4.0  
CVE-2026-83297 Oracle BI Publisher BI Platform Security LDAP No 8.1 Network Low Low None Un-
changed
High High None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83308 Oracle BI Publisher BI Platform Security SOAP No 8.1 Network Low Low None Un-
changed
None High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83314 Oracle BI Publisher Web Service API SOAP No 8.1 Network Low Low None Un-
changed
None High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83299 Oracle Business Intelligence Enterprise Edition Analytics Web General HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-83286 Oracle Business Intelligence Enterprise Edition Platform Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83336 Oracle Business Intelligence Enterprise Edition Analytics Server None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83288 Oracle Business Intelligence Enterprise Edition BI Search None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83293 Oracle Business Intelligence Enterprise Edition FNDN None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-83317 Oracle Business Intelligence Enterprise Edition Installation None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83071 Oracle Business Intelligence Enterprise Edition Machine Learning None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83290 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83291 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.8 Local Low Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83294 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.8 Local Low None Required Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83313 Oracle BI Publisher BI Platform Security HTTP No 7.7 Network Low Low None Changed High None None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83312 Oracle BI Publisher E-Business Suite - XDO HTTP No 7.7 Network Low Low None Changed High None None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83319 Oracle BI Publisher Web Service API SOAP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0  
CVE-2026-83287 Oracle Business Intelligence Enterprise Edition Presentation Services SOAP No 7.7 Network Low Low None Changed High None None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83320 Oracle BI Publisher Administration HTTP No 7.6 Network Low Low Required Changed High Low None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83318 Oracle BI Publisher Administration HTTP No 7.5 Network High Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83270 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83296 Oracle Business Intelligence Enterprise Edition BI Search HTTP No 7.5 Network High Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83292 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 7.5 Network High Low None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83323 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.5 Local High Low Required Changed High High High 26.01.0.0.0  
CVE-2026-83289 Oracle Business Intelligence Enterprise Edition Analytics Web General SOAP No 7.5 Network High Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83295 Oracle Business Intelligence Enterprise Edition Presentation Services SOAP No 7.5 Network High Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-83298 Oracle BI Publisher BI Platform Security HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-83273 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 7.2 Network Low High None Un-
changed
High High High 26.01.0.0.0  
CVE-2026-83322 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 7.2 Network Low High None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83325 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 7.2 Network Low High None Un-
changed
High High High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83324 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP No 7.1 Network High Low None Changed Low High None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-83316 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.0 Local High Low None Un-
changed
High High High 26.01.0.0.0  

 

Oracle Hyperion Risk Matrix

This Critical Security Patch Update contains 102 new security patches for Oracle Hyperion.  50 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-87230 Oracle Hyperion Financial Management Security HTTP Yes 10.0 Network Low None None Changed High High None 11.2.26.0.000  
CVE-2026-87172 Oracle Hyperion Financial Management Security HTTP No 9.9 Network Low Low None Changed High High High 11.2.26.0.000  
CVE-2026-87188 Oracle Hyperion Financial Management Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87184 Oracle Hyperion Financial Management Security SQL Yes 9.8 Network Low None None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87186 Oracle Hyperion Financial Management Security TCP Yes 9.6 Adjacent
Network
Low None None Changed High High High 11.2.26.0.000  
CVE-2026-87128 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87129 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87170 Oracle Hyperion Financial Management Security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87214 Oracle Hyperion Financial Management Security HTTP No 9.1 Network Low High None Changed High High High 11.2.26.0.000  
CVE-2026-87217 Oracle Hyperion Financial Management Security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87223 Oracle Hyperion Financial Management Security HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.2.26.0.000  
CVE-2026-87189 Oracle Hyperion Financial Management Security Oracle Net No 9.1 Network Low High None Changed High High High 11.2.26.0.000  
CVE-2026-87173 Oracle Hyperion Financial Management Security TCP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87175 Oracle Hyperion Financial Management Security TCP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87176 Oracle Hyperion Financial Management Security TCP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87179 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87180 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87181 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87185 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87201 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87204 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87224 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87226 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87227 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87182 Oracle Hyperion Financial Management Security None No 8.8 Local Low Low None Changed High High High 11.2.26.0.000  
CVE-2026-87202 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87238 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87187 Oracle Hyperion Financial Management Security TCP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87171 Oracle Hyperion Financial Management Security HTTPS Yes 8.7 Network High None None Changed High High None 11.2.26.0.000  
CVE-2026-87178 Oracle Hyperion Financial Management Security SQL No 8.7 Network Low High None Changed High High None 11.2.26.0.000  
CVE-2026-87177 Oracle Hyperion Financial Management Security HTTP No 8.5 Network Low Low None Changed High Low None 11.2.26.0.000  
CVE-2026-87219 Oracle Hyperion Financial Management Security None No 8.4 Local Low Low None Changed High High None 11.2.26.0.000  
CVE-2026-87210 Oracle Hyperion Financial Management Security TCP Yes 8.3 Adjacent
Network
Low None None Un-
changed
High High Low 11.2.26.0.000  
CVE-2026-87196 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87197 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87200 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
None High Low 11.2.26.0.000  
CVE-2026-87228 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87229 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
Low High None 11.2.26.0.000  
CVE-2026-87174 Oracle Hyperion Financial Management Security TCP Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87231 Oracle Hyperion Financial Management Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87234 Oracle Hyperion Financial Management Security HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87218 Oracle Hyperion Financial Management Security TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
None High High 11.2.26.0.000  
CVE-2026-87232 Oracle Hyperion Financial Management Security TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87241 Oracle Hyperion Financial Management Security TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87245 Oracle Hyperion Financial Management Security TCP/IP No 8.0 Adjacent
Network
Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87243 Oracle Hyperion Financial Management Security TLS Yes 8.0 Adjacent
Network
High None None Changed High High None 11.2.26.0.000  
CVE-2026-87216 Oracle Hyperion Financial Management Security None No 7.8 Local Low Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87141 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.7 Network Low Low None Changed High None None 11.2.26.0.000  
CVE-2026-87147 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.7 Network High High None Changed High High None 11.2.26.0.000  
CVE-2026-87134 Oracle Hyperion Data Relationship Management Access and security TCP No 7.7 Network Low Low None Changed High None None 11.2.26.0.000  
CVE-2026-87183 Oracle Hyperion Financial Management Security None No 7.7 Local Low High Required Changed High High High 11.2.26.0.000  
CVE-2026-87131 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.26.0.000  
CVE-2026-87132 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.26.0.000  
CVE-2026-87133 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.6 Network Low High None Changed High Low None 11.2.26.0.000  
CVE-2026-87137 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.26.0.000  
CVE-2026-87144 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.26.0.000  
CVE-2026-87233 Oracle Hyperion Financial Management Security HTTP No 7.6 Network Low High None Changed High None Low 11.2.26.0.000  
CVE-2026-87250 Oracle Hyperion Financial Management Security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.26.0.000  
CVE-2026-87136 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87139 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87140 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87148 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.2.26.0.000  
CVE-2026-87138 Oracle Hyperion Data Relationship Management Access and security SOAP Yes 7.5 Network Low None None Un-
changed
None None High 11.2.26.0.000  
CVE-2026-87190 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87193 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87194 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87199 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.2.26.0.000  
CVE-2026-87203 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87205 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87211 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87221 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.26.0.000  
CVE-2026-87222 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.2.26.0.000  
CVE-2026-87237 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87247 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87215 Oracle Hyperion Financial Management Security TCP Yes 7.5 Network Low None None Un-
changed
None None High 11.2.26.0.000  
CVE-2026-87130 Oracle Hyperion Data Relationship Management Access and security SMTP Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87143 Oracle Hyperion Data Relationship Management Access and security TCP Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87198 Oracle Hyperion Financial Management Security HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87206 Oracle Hyperion Financial Management Security HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87213 Oracle Hyperion Financial Management Security HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87212 Oracle Hyperion Financial Management Security SQL Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87235 Oracle Hyperion Financial Management Security SSH Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87195 Oracle Hyperion Financial Management Security TLS Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87242 Oracle Hyperion Financial Management Security TLS Yes 7.4 Network High None None Un-
changed
High High None 11.2.26.0.000  
CVE-2026-87145 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 11.2.26.0.000  
CVE-2026-87239 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87244 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87246 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87207 Oracle Hyperion Financial Management Security SQL No 7.2 Network Low High None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87135 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87146 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87142 Oracle Hyperion Data Relationship Management Access and security HTTPS Yes 7.1 Network Low None Required Un-
changed
None High Low 11.2.26.0.000  
CVE-2026-87191 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.26.0.000  
CVE-2026-87192 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.26.0.000  
CVE-2026-87208 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.2.26.0.000  
CVE-2026-87209 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.26.0.000  
CVE-2026-87225 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.26.0.000  
CVE-2026-87236 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.26.0.000  
CVE-2026-87249 Oracle Hyperion Financial Management Security HTTP Yes 7.1 Network Low None Required Un-
changed
None High Low 11.2.26.0.000  
CVE-2026-87220 Oracle Hyperion Financial Management Security TCP Yes 7.1 Adjacent
Network
Low None None Un-
changed
None Low High 11.2.26.0.000  
CVE-2026-87240 Oracle Hyperion Financial Management Security None No 7.0 Local High Low None Un-
changed
High High High 11.2.26.0.000  
CVE-2026-87248 Oracle Hyperion Financial Management Security None No 6.7 Local Low High None Un-
changed
High High High 11.2.26.0.000  

 

Oracle Java SE Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Java SE.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83357 Oracle GraalVM for JDK Compiler HTTP Yes 8.1 Network High None None Un-
changed
High High High Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1  
CVE-2026-83408 Oracle GraalVM for JDK Compiler HTTP Yes 8.1 Network High None None Un-
changed
High High High Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1  
CVE-2026-83368 Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Compiler HTTP Yes 7.0 Network High None None Un-
changed
High Low Low Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1  

 

Oracle PeopleSoft Risk Matrix

This Critical Security Patch Update contains 16 new security patches for Oracle PeopleSoft.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83017 PeopleSoft Enterprise PeopleTools Report Distribution HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.61-8.63  
CVE-2026-82993 PeopleSoft Enterprise PeopleTools Business Interlink HTTP No 8.5 Network Low Low None Changed High Low None 8.61-8.63  
CVE-2026-73954 PeopleSoft Enterprise PeopleTools Business Interlink HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.61-8.63  
CVE-2026-83014 PeopleSoft Enterprise PeopleTools Cube Manager HTTP No 8.1 Network Low Low None Un-
changed
None High High 8.61-8.63  
CVE-2026-83019 PeopleSoft Enterprise PeopleTools SQR HTTP No 8.1 Network Low Low None Un-
changed
High None High 8.61-8.63  
CVE-2026-83420 PeopleSoft Enterprise FIN Engineering Brazil Engineering None No 7.8 Local Low Low None Un-
changed
High High High 9.1  
CVE-2026-83147 PeopleSoft Enterprise FIN Inventory Brazil Inventory None No 7.8 Local Low Low None Un-
changed
High High High 9.1  
CVE-2026-83018 PeopleSoft Enterprise PeopleTools SQR None No 7.8 Local Low Low None Un-
changed
High High High 8.61-8.63  
CVE-2026-87264 PeopleSoft Enterprise PeopleTools Integration Broker HTTP No 7.7 Network Low Low None Changed None High None 8.61-8.63  
CVE-2026-83070 PeopleSoft Enterprise PRTL Interaction Hub Enterprise Portal HTTP No 7.7 Network Low Low None Changed High None None 9.1  
CVE-2026-25639 PeopleSoft Enterprise CC Common Application Objects Chatbot Framework (Axios) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 9.2  
CVE-2026-73960 PeopleSoft Enterprise PeopleTools Ren Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.61-8.63  
CVE-2026-73955 PeopleSoft Enterprise PeopleTools Charting HTTP No 7.3 Network Low Low Required Un-
changed
High High None 8.61-8.63  
CVE-2026-7598 PeopleSoft Enterprise PeopleTools File Processing (libssh2) SSH Yes 7.3 Network Low None None Un-
changed
Low Low Low 8.61-8.63  
CVE-2026-83016 PeopleSoft Enterprise PeopleTools SQR None No 7.2 Local High High Required Changed High High High 8.61-8.63  
CVE-2026-83015 PeopleSoft Enterprise PeopleTools Cube Manager None No 7.0 Local High Low None Un-
changed
High High High 8.61-8.63  

Additional CVEs addressed are:

  • The patch for CVE-2026-7598 also addresses CVE-2023-48795 and CVE-2023-6918.

 

Oracle Siebel CRM Risk Matrix

This Critical Security Patch Update contains 63 new security patches for Oracle Siebel CRM.  26 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83197 Siebel Apps - Financial Services Financial Accounts HTTP Yes 9.1 Network Low None None Un-
changed
High None High 17.0-26.7  
CVE-2026-83196 Siebel CRM Deployment Server Infrastructure HTTP No 9.1 Network Low High None Changed High High High 17.0-26.7  
CVE-2026-83201 Siebel CRM Deployment Server Infrastructure HTTP Yes 9.1 Network Low None None Un-
changed
High High None 17.0-26.7  
CVE-2026-83202 Siebel CRM Deployment Server Infrastructure HTTP Yes 9.1 Network Low None None Un-
changed
High High None 17.0-26.7  
CVE-2026-83229 Siebel CRM Deployment Siebel Management Console HTTP No 9.1 Network Low High None Changed High High High 17.0-26.7  
CVE-2026-83154 Siebel CRM End User Open UI SOAP Yes 9.1 Network Low None None Un-
changed
High High None 17.0-26.7  
CVE-2026-83212 Siebel Apps - Self Service Helpdesk/Training HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83086 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 22.3-26.7  
CVE-2026-83180 Siebel CRM Deployment Server Infrastructure HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83199 Siebel CRM Deployment Server Infrastructure HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83153 Siebel CRM Deployment Server Infrastructure HTTPS No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83208 Siebel CRM Deployment Migration SQL No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83210 Siebel CRM Deployment Server Infrastructure SQL No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83209 Siebel CRM Development Workflow HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83144 Siebel Apps - Customer Order Management Order Management HTTP No 8.7 Network Low Low Required Changed High High None 17.0-26.7  
CVE-2026-83145 Siebel Apps - Customer Order Management Order Management HTTP No 8.7 Network Low Low Required Changed High High None 17.0-26.7  
CVE-2026-83074 Siebel CRM Cloud Applications Siebel Cloud Manager SSH Yes 8.6 Network Low None None Changed High None None 22.3-26.7  
CVE-2026-83203 Siebel CRM End User Open UI HTTP Yes 8.6 Network Low None None Un-
changed
High Low Low 17.0-26.7  
CVE-2026-83078 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 22.3-26.7  
CVE-2026-83087 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.2 Network High Low None Changed High High None 22.3-26.7  
CVE-2026-83085 Siebel CRM Cloud Applications Siebel Cloud Manager TCP No 8.2 Adjacent
Network
Low Low None Changed High Low Low 22.3-26.7  
CVE-2026-83215 Siebel CRM Deployment Server Infrastructure HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 17.0-26.7  
CVE-2026-83181 Siebel CRM Development Workspaces HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 17.0-26.7  
CVE-2026-83143 Siebel Apps - Life Sciences eDetailing HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 17.0-26.7  
CVE-2026-83073 Siebel CRM Cloud Applications Siebel Cloud Manager TLS Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 22.3-26.7  
CVE-2026-83191 Siebel CRM Deployment Server Infrastructure TCP Yes 8.1 Network High None None Un-
changed
High High High 17.0-26.7  
CVE-2026-83192 Siebel CRM End User Open UI HTTP Yes 8.1 Network High None None Un-
changed
High High High 17.0-26.7  
CVE-2026-54513 Siebel CRM Integration Open Integration (jackson-databind) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.12-26.7  
CVE-2026-83220 Siebel CRM Integration Event Publish and Subscribe TLS Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 23.6-26.7  
CVE-2026-83079 Siebel CRM Cloud Applications Siebel Cloud Manager None No 7.9 Local Low High None Changed High High None 22.3-26.7  
CVE-2026-82992 Siebel CRM Deployment Installation None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83211 Siebel CRM Deployment Server Infrastructure None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83214 Siebel CRM Deployment Server Infrastructure None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83216 Siebel CRM Deployment Server Infrastructure None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83146 Siebel CRM End User Open UI HTTP No 7.7 Network High Low Required Changed High High None 17.0-26.7  
CVE-2026-83207 Siebel CRM Development Integration - Scripting HTTP No 7.6 Network Low Low None Un-
changed
Low Low High 17.0-26.7  
CVE-2026-83075 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 22.3-26.7  
CVE-2026-83183 Siebel CRM Deployment Server Infrastructure HTTP Yes 7.5 Network Low None None Un-
changed
None None High 17.0-26.7  
CVE-2026-83226 Siebel CRM Deployment Server Infrastructure HTTP No 7.5 Network High Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83223 Siebel CRM Deployment Siebel Remote HTTP No 7.5 Network High Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83222 Siebel CRM Deployment Server Infrastructure Multiple Yes 7.5 Network Low None None Un-
changed
None None High 17.0-26.7  
CVE-2026-83225 Siebel CRM Deployment Server Infrastructure TCP Yes 7.5 Network Low None None Un-
changed
None None High 17.0-26.7  
CVE-2026-83228 Siebel CRM Deployment Server Infrastructure TCP Yes 7.5 Network Low None None Un-
changed
None None High 17.0-26.7  
CVE-2026-83182 Siebel CRM Development Configuration Tools SQL No 7.5 Network High Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83213 Siebel CRM End User Reports HTTP Yes 7.5 Network Low None None Un-
changed
High None None 17.0-26.7  
CVE-2026-83227 Siebel CRM Integration EAI HTTP No 7.5 Network High Low None Un-
changed
High High High 17.0-26.7  
CVE-2026-83326 Siebel CRM Integration Open Integration HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.12-26.7  
CVE-2026-50010 Siebel CRM Integration Open Integration (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.12-26.7  
CVE-2026-83218 Siebel CRM Deployment Server Infrastructure HTTP Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.7  
CVE-2026-83193 Siebel Apps - Life Sciences Life Sciences None No 7.3 Local Low Low Required Un-
changed
High High High 17.0-26.7  
CVE-2026-83190 Siebel CRM Deployment Server Infrastructure None No 7.3 Local Low Low Required Un-
changed
High High High 17.0-26.7  
CVE-2026-83155 Siebel CRM Deployment Server Infrastructure TCP No 7.3 Adjacent
Network
Low Low None Un-
changed
High None High 17.0-26.7  
CVE-2026-73966 Siebel Apps - Marketing Marketing HTTP No 7.2 Network Low High None Un-
changed
High High High 17.0-26.7  
CVE-2026-83195 Siebel CRM Deployment Server Infrastructure TCP No 7.2 Network Low High None Un-
changed
High High High 17.0-26.7  
CVE-2026-83224 Siebel CRM Deployment Server Infrastructure HTTP No 7.1 Network Low Low None Un-
changed
High None Low 17.0-26.7  
CVE-2026-83230 Siebel CRM Deployment Siebel Management Console HTTP No 7.1 Network Low Low None Un-
changed
High Low None 17.0-26.7  
CVE-2026-83219 Siebel CRM Deployment Server Infrastructure None No 7.1 Local Low Low None Un-
changed
High High None 17.0-26.7  
CVE-2026-83217 Siebel CRM End User Open UI HTTP No 7.1 Network Low Low None Un-
changed
High Low None 17.0-26.7  
CVE-2026-83221 Siebel CRM Integration EAI SOAP No 7.1 Network Low Low None Un-
changed
High Low None 17.0-26.7  
CVE-2026-73965 Siebel CRM Deployment Cloud Gateway HTTP No 6.8 Network High Low None Un-
changed
High High None 17.0-26.7  
CVE-2026-55956 Siebel CRM Integration EAI (Apache Tomcat) HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 17.0-26.7  
CVE-2026-83077 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 6.4 Network Low Low None Changed Low Low None 22.3-26.7  
CVE-2026-54515 Siebel CRM Deployment Database Upgrade (jackson-databind) HTTP Yes 5.3 Network Low None None Un-
changed
None Low None 25.12-26.7  

Additional CVEs addressed are:

  • The patch for CVE-2026-54513 also addresses CVE-2026-54512.
  • The patch for CVE-2026-55956 also addresses CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, and CVE-2026-55955.
  • The patch for CVE-2026-50010 also addresses CVE-2026-44249, CVE-2026-45416, and CVE-2026-45536.
  • The patch for CVE-2026-54515 also addresses CVE-2026-54512, CVE-2026-54513, and CVE-2026-54514.

 

Oracle Supply Chain Risk Matrix

This Critical Security Patch Update contains 19 new security patches for Oracle Supply Chain.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83261 Oracle Product Lifecycle Analytics Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 3.6.1  
CVE-2026-83260 Oracle Agile PLM Event Java PX T3, IIOP No 9.1 Network Low High None Changed High High High 9.3.6  
CVE-2026-87259 Oracle Agile Engineering Data Management Engineering Communication Interface None No 8.4 Local Low Low None Changed High High None 6.2.1  
CVE-2026-83264 Oracle Product Lifecycle Analytics Installation Issues None No 8.4 Local Low Low None Changed High High None 3.6.1  
CVE-2026-87266 Oracle Agile PLM Application Server HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 9.3.6  
CVE-2026-87256 Oracle Agile PLM Application Server HTTP No 7.7 Network Low Low None Changed High None None 9.3.6  
CVE-2026-87257 Oracle Agile PLM SDK HTTP No 7.7 Network Low Low None Changed High None None 9.3.6  
CVE-2026-87258 Oracle Agile PLM Folders, Files & Attachments HTTP No 7.6 Network Low Low Required Changed High Low None 9.3.6  
CVE-2026-87254 Oracle Agile PLM Folders, Files & Attachments HTTP No 7.5 Network High Low None Un-
changed
High High High 9.3.6  
CVE-2026-83262 Oracle Product Lifecycle Analytics Installation Issues HTTP No 7.5 Network High Low None Un-
changed
High High High 3.6.1  
CVE-2026-83263 Oracle Product Lifecycle Analytics Installation Issues HTTP No 7.5 Network High Low None Un-
changed
High High High 3.6.1  
CVE-2026-87261 Oracle Agile Engineering Data Management Engineering Communication Interface None No 7.3 Local Low Low None Changed High Low None 6.2.1  
CVE-2026-87260 Oracle Agile Engineering Data Management Engineering Communication Interface TCP No 7.3 Adjacent
Network
Low Low None Un-
changed
High High None 6.2.1  
CVE-2026-83277 Oracle Agile PLM MCAD Connector CAX Client None No 7.3 Local Low Low None Changed Low High None 3.6  
CVE-2026-87262 Oracle Agile Engineering Data Management Engineering Communication Interface TCP Yes 7.1 Adjacent
Network
Low None None Un-
changed
High Low None 6.2.1  
CVE-2026-87252 Oracle Agile PLM Application Server HTTPS Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 9.3.6  
CVE-2026-87253 Oracle Agile PLM Web Client HTTP Yes 6.1 Network Low None Required Changed Low Low None 9.3.6  
CVE-2026-83274 Oracle Agile PLM MCAD Connector CAX Client None No 5.5 Local Low Low None Un-
changed
High None None 3.6  
CVE-2026-83279 Oracle Agile PLM MCAD Connector CAX Client None No 5.5 Local Low Low None Un-
changed
High None None 3.6  

 

Oracle Utilities Applications Risk Matrix

This Critical Security Patch Update contains 2 new security patches for Oracle Utilities Applications.  1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-83343 Oracle Utilities Network Management System System Wide HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3  
CVE-2026-83342 Oracle Utilities Network Management System System Wide None No 7.8 Local Low Low None Un-
changed
High High High 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, 25.12.0.0.0-25.12.0.0.3  

 

Oracle Virtualization Risk Matrix

This Critical Security Patch Update contains 19 new security patches for Oracle Virtualization.  1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-87273 Oracle VM VirtualBox Core None No 8.6 Local Low None Required Changed High High High 7.2.16  
CVE-2026-87268 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.16 See Note 1
CVE-2026-87269 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.16 See Note 1
CVE-2026-87270 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.16 See Note 1
CVE-2026-87271 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.16 See Note 1
CVE-2026-87272 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.16  
CVE-2026-87276 Oracle VM VirtualBox Core None No 7.5 Local High Low Required Changed High High High 7.2.16  
CVE-2026-87277 Oracle VM VirtualBox Core RDP Yes 7.5 Network Low None None Un-
changed
None None High 7.2.16  
CVE-2026-87278 Oracle VM VirtualBox Core None No 6.1 Local Low None Required Un-
changed
None Low High 7.2.16  
CVE-2026-87279 Oracle VM VirtualBox Core None No 6.1 Local Low Low None Un-
changed
None Low High 7.2.16  
CVE-2026-87282 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.16  
CVE-2026-87283 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.16  
CVE-2026-87285 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.16  
CVE-2026-87267 Oracle VM VirtualBox Core RDP No 5.3 Network High Low None Un-
changed
None None High 7.2.16  
CVE-2026-87275 Oracle VM VirtualBox Core None No 4.6 Local Low High None Changed Low None Low 7.2.16  
CVE-2026-87274 Oracle VM VirtualBox Core None No 4.4 Local High Low Required Un-
changed
None None High 7.2.16  
CVE-2026-87280 Oracle VM VirtualBox Core None No 4.2 Local Low High Required Un-
changed
None None High 7.2.16  
CVE-2026-87281 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed Low None None 7.2.16  
CVE-2026-87284 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed None None Low 7.2.16  

Notes:

  1. This vulnerability applies to Windows host only.