Oracle Critical Security Patch Update Advisory - August 2026

Description

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.

This Critical Security Patch Update contains 943 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at August 2026 Critical Security Patch Update: Executive Summary and Analysis.

Affected Products and Patch Information

Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.

Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.

Affected Products and Versions Patch Availability Document
Enterprise Manager for MySQL Database, versions 13.5.1.0.0-13.5.6.0.0 Oracle Enterprise Manager
Helidon, versions 1.4.19, 1.4.20, 3.2.18, 3.2.19, 3.2.20, 4.5.0, 4.5.1, 4.5.3 Helidon
JD Edwards EnterpriseOne Orchestrator, versions 9.2.0.0-9.2.26.4 JD Edwards
JD Edwards EnterpriseOne Tools, versions 9.2.0.0-9.2.26.4 JD Edwards
JD Edwards EnterpriseOne US Payroll, version 9.2 JD Edwards
Management Cloud Engine, version 25.2.0.0.10 Management Cloud Engine
MySQL AI, versions 9.4.0-9.7.2, 26.7.0 MySQL
MySQL Cluster, versions 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2 MySQL
MySQL Connectors, version 26.7.0 MySQL
MySQL Shell, version 26.7.0 MySQL
Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Agile Engineering Data Management, version 6.2.1 Oracle Supply Chain Products
Oracle Agile PLM, version 9.3.6 Oracle Supply Chain Products
Oracle Agile PLM MCAD Connector, version 3.6 Oracle Supply Chain Products
Oracle Application Testing Suite, version 13.3.0.1 Oracle Application Testing Suite
Oracle Autonomous Health Framework, versions 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 Oracle Autonomous Health Framework
Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 Oracle Analytics
Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 Oracle Analytics
Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 Oracle Commerce
Oracle Commerce Platform, version 11.4.0 Oracle Commerce
Oracle Communications ASAP, versions 7.4.1, 8.0.0 Oracle Communications ASAP
Oracle Communications Network Analytics Data Director, versions 24.2.0, 24.3.4, 25.1.200 Oracle Communications Network Analytics Data Director
Oracle Communications Unified Assurance, versions 6.1.1-7.0.0 Oracle Communications Unified Assurance
Oracle Communications Unified Inventory Management, versions 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.1 Oracle Communications Unified Inventory Management
Oracle Database Server, versions 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 Database
Oracle Demand Planning, versions 12.1, 12.2 Oracle Supply Chain Products
Oracle E-Business Suite, versions 12.2.3-12.2.15 Oracle E-Business Suite
Oracle Enterprise Manager Base Platform, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Enterprise Manager for Systems Infrastructure, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Essbase, version 21.8.1.0.0 Database
Oracle Financial Services Behavior Detection Platform, versions 8.0.8.1, 8.1.2.11 Oracle Financial Services Behavior Detection Platform
Oracle Financial Services Compliance Studio, version 8.1.3.1 Oracle Financial Services Compliance Studio
Oracle Financial Services Enterprise Case Management, versions 8.0.8.2, 8.1.2.11 Oracle Financial Services Enterprise Case Management
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition, version 8.0.8.0 Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle GraalVM Enterprise Edition, version 21.3.19 Java SE
Oracle GraalVM for JDK, versions 17.0.20, 21.0.12 Java SE
Oracle Hospitality OPERA 5 Property Services, versions 5.6.28.0-5.6.28.1 Oracle Hospitality OPERA 5 Property Services
Oracle Hospitality Simphony, versions 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1 Oracle Hospitality Simphony
Oracle Hyperion Calculation Manager, version 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Data Relationship Management, versions 11.2.23.0.0, 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Financial Management, version 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Financial Reporting, version 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Infrastructure Technology, version 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Hyperion Profitability and Cost Management, version 11.2.25.0.0 Oracle Enterprise Performance Management
Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Internet Directory, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Java SE, versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2 Java SE
Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Outside In Technology, version 8.5.8 Fusion Middleware
Oracle Product Lifecycle Analytics, version 3.6.1 Oracle Supply Chain Products
Oracle Reports Developer, versions 12.2.1.19.0, 14.1.2.0.0 Fusion Middleware
Oracle Retail Advanced Inventory Planning, versions 15.0, 16.0 Retail Applications
Oracle Retail Assortment Planning, versions 15.0, 16.0 Retail Applications
Oracle Retail Fiscal Management, version 14.2 Retail Applications
Oracle Retail Item Planning, versions 15.0, 16.0 Retail Applications
Oracle Retail Regular Price Optimization, versions 15.0, 16.0 Retail Applications
Oracle SOA Suite, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Unified Directory, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Virtual Directory, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle VM VirtualBox, version 7.2.14 Virtualization
Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
PeopleSoft Enterprise CC Common Application Objects, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Common Objects, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Lease Administration, version 9.2 PeopleSoft
PeopleSoft Enterprise PeopleTools, versions 8.61-8.63 PeopleSoft
Primavera P6 Enterprise Project Portfolio Management, versions 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.3, 23.12.0.0-23.12.19.0, 24.12.0.0-24.12.15.0, 25.12.0.0-25.12.6.0 Oracle Construction and Engineering Suite
Service Delivery Platform, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Siebel Applications, versions 17.0-26.6 Siebel

Risk Matrix Content

Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.

Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.

Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).

Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.

Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.

The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.

Workarounds

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible. Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.

Skipped Security Patch Updates

Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Security Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.

Critical Security Patch Update Supported Products and Versions

Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.

Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.

Credit Statement

The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:

  • Alvin Lim of NCS Pte Ltd: CVE-2026-60884
  • Dang Minh Quang of Viettel Cyber Security: CVE-2026-71126
  • Diego Palacios: CVE-2026-71131, CVE-2026-71141
  • Dvir Gozlan working with TrendAI Zero Day Initiative: CVE-2026-60392
  • Fabian Lim of NCS Pte Ltd: CVE-2026-60884
  • Giovanni Vignone of Octane Security: CVE-2026-71125
  • Hugo Leclercq and Patrick Ventuzelo: CVE-2026-71062
  • Hyeongeun Ji of JeroScope: CVE-2026-71113
  • Jimi Sebree of Horizon3.ai: CVE-2026-60590, CVE-2026-60591
  • Johannes Wikner: CVE-2026-71151
  • Kai Aizen: CVE-2026-61308
  • Mat Powell of TrendAI Zero Day Initiative: CVE-2026-60412, CVE-2026-60413, CVE-2026-60414
  • Michael Green of MongoDB: CVE-2026-71073, CVE-2026-71079, CVE-2026-71084
  • Myeonghun Pak and Seongmin Kim of Team SaturnX: CVE-2026-71127, CVE-2026-71128, CVE-2026-71129, CVE-2026-71130, CVE-2026-71135, CVE-2026-71136, CVE-2026-71137, CVE-2026-71138, CVE-2026-71139, CVE-2026-71140
  • Paolo Gentry of Octane Security: CVE-2026-71125
  • Phan Vinh Khang of Viettel Cyber Security working with TrendAI Zero Day Initiative: CVE-2026-71116
  • Robert van Eijk of Octane Security: CVE-2026-71125
  • Shubham Antil of Octane Security: CVE-2026-71125
  • Vmpr0be working with TrendAI Zero Day Initiative: CVE-2026-71114, CVE-2026-71132
  • Weber Leon: CVE-2026-70906
  • Xiaobye (xiaobye_tw) of DEVCORE Research Team: CVE-2026-71114, CVE-2026-71115, CVE-2026-71134
  • z0v3r1n: CVE-2026-71129

Security-In-Depth Contributors

Oracle acknowledges people who have contributed to our Security-In-Depth program (see FAQ). People are acknowledged for Security-In-Depth contributions if they provide information, observations or suggestions pertaining to security vulnerability issues that result in significant modification of Oracle code or documentation in future releases, but are not of such a critical nature that they are distributed in Critical Security Patch Updates.

In this Critical Security Patch Update, Oracle recognizes the following for contributions to Oracle's Security-In-Depth program:

  • Gouri Sankar A [2 reports]
  • Qiguang Zhu

Upcoming Security Release Dates

Security patches are released on the third Tuesday of each month. The next four dates are:

  • 15 September 2026 (CSPU)
  • 20 October 2026 (CPU)
  • 17 November 2026 (CSPU)
  • 15 December 2026 (CSPU)

References

 

Modification History

Date Note
2026-August-18 Rev 1. Initial Release.

 

Oracle Database Products Risk Matrices

This Critical Security Patch Update contains 17 new security patches for Oracle Database Products divided as follows:

  • 6 new security patches for Oracle Database Products
  • 7 new security patches for Oracle Autonomous Health Framework
  • 4 new security patches for Oracle Essbase

 

Oracle Database Server Risk Matrix

This Critical Security Patch Update contains 6 new security patches, plus additional third party patches noted below, for Oracle Database Products.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71063 Portable Clusterware None TLS Yes 9.6 Adjacent
Network
Low None None Changed High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-71064 Portable Clusterware None TLS Yes 9.6 Adjacent
Network
Low None None Changed High High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-71102 Portable Clusterware None HTTP Yes 9.1 Network Low None None Un-
changed
None High High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-71062 RDBMS Authenticated User Oracle Net No 8.5 Network High Low None Changed High High High 23.4.0-23.26.3  
CVE-2026-59889 Fleet Patching and Provisioning (jackson-databind) None TLS No 8.1 Network Low Low None Un-
changed
High None High 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  
CVE-2026-71100 RDBMS None Oracle Net Yes 5.3 Network Low None None Un-
changed
Low None None 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3  

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • RDBMS (DBI): CVE-2026-9698 and CVE-2026-10879 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • RDBMS (jackson-databind): CVE-2026-59888 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • RDBMS (SQLite): CVE-2026-11824 and CVE-2026-11822 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle Autonomous Health Framework Risk Matrix

This Critical Security Patch Update contains 7 new security patches, plus additional third party patches noted below, for Oracle Autonomous Health Framework.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-70715 Oracle Autonomous Health Framework Trace File Analyzer TLS Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-70728 Oracle Autonomous Health Framework Trace File Analyzer HTTP No 8.5 Network Low Low None Changed High Low None 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-70731 Oracle Autonomous Health Framework Trace File Analyzer None No 8.4 Local Low Low None Changed None High High 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-70717 Oracle Autonomous Health Framework Cluster Health Analyzer TLS No 7.7 Adjacent
Network
High Low None Changed High High None 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-42764 Oracle Autonomous Health Framework AHFCOMMON (pyca-cryptography) TLS Yes 7.5 Network Low None None Un-
changed
None None High 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-70734 Oracle Autonomous Health Framework Trace File Analyzer None No 7.4 Local Low High Required Changed None High High 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  
CVE-2026-9563 Oracle Autonomous Health Framework Trace File Analyzer (Eclipse Parsson) HTTP No 6.5 Network Low Low None Un-
changed
None None High 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2  

Additional CVEs addressed are:

  • The patch for CVE-2026-42764 also addresses CVE-2026-69247.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Autonomous Health Framework
    • AHFCOMMON: CVE-2026-54283, CVE-2026-48710, CVE-2026-48817, CVE-2026-48818 and CVE-2026-54282 [VEX Justification: vulnerable_code_not_in_execute_path].
    • AHFCOMMON (Apache PyArrow): CVE-2026-25087 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • CLISDK (Soup Sieve): CVE-2026-49476 and CVE-2026-49477 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • Trace File Analyzer (Apache Log4j): CVE-2026-34481, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, CVE-2026-34480 and CVE-2026-49844 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • CLISDK (Python setuptools): CVE-2026-59890, CVE-2026-23949 and CVE-2026-24049 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle Essbase Risk Matrix

This Critical Security Patch Update contains 4 new security patches for Oracle Essbase.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-29167 Oracle Essbase Essbase Web Platform (Apache HTTP Server) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 21.8.1.0.0  
CVE-2026-70689 Oracle Essbase Infrastructure HTTP Yes 9.8 Network Low None None Un-
changed
High High High 21.8.1.0.0  
CVE-2026-70688 Oracle Essbase Calculator HTTP No 8.8 Network Low Low None Un-
changed
High High High 21.8.1.0.0  
CVE-2026-45447 Oracle Essbase Essbase Web Platform (OpenSSL) TLS Yes 7.5 Network Low None None Un-
changed
None None High 21.8.1.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-45447 also addresses CVE-2026-34180, CVE-2026-34182, CVE-2026-42766, CVE-2026-42767, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-7383, and CVE-2026-9076.
  • The patch for CVE-2026-29167 also addresses CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, and CVE-2026-49975.

 

Oracle Application Testing Suite Risk Matrix

This Critical Security Patch Update contains 7 new security patches for Oracle Application Testing Suite.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-70862 Oracle Application Testing Suite Test Manager for Web Apps HTTP Yes 9.1 Network Low None None Un-
changed
High High None 13.3.0.1  
CVE-2026-70863 Oracle Application Testing Suite Load Testing for Web Apps HTTPS No 8.8 Network Low Low None Un-
changed
High High High 13.3.0.1  
CVE-2026-70868 Oracle Application Testing Suite Load Testing for Web Apps HTTP Yes 8.1 Network High None None Un-
changed
High High High 13.3.0.1  
CVE-2026-70866 Oracle Application Testing Suite Load Testing for Web Apps None No 7.8 Local Low Low None Un-
changed
High High High 13.3.0.1  
CVE-2026-70864 Oracle Application Testing Suite Load Testing for Web Apps HTTP No 7.6 Network Low Low Required Changed High Low None 13.3.0.1  
CVE-2026-70865 Oracle Application Testing Suite Load Testing for Web Apps HTTPS No 7.5 Network High Low None Un-
changed
High High High 13.3.0.1  
CVE-2026-70867 Oracle Application Testing Suite Load Testing for Web Apps TLS Yes 7.1 Adjacent
Network
Low None None Un-
changed
High Low None 13.3.0.1  

 

Oracle Commerce Risk Matrix

This Critical Security Patch Update contains 66 new security patches for Oracle Commerce.  47 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-70995 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-70954 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-70953 Oracle Commerce Platform Dynamo Application Framework TCP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-70998 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.3 Network Low None None Changed High Low None 11.4.0  
CVE-2026-71037 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 9.3 Network Low None Required Changed High High None 11.4.0  
CVE-2026-70976 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.4.0  
CVE-2026-70977 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.4.0  
CVE-2026-70978 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-70979 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.4.0  
CVE-2026-70981 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.4.0  
CVE-2026-70984 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.4.0  
CVE-2026-70994 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.1 Network Low None None Un-
changed
High None High 11.4.0  
CVE-2026-71014 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-71015 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-71026 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-70997 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 9.1 Network Low None None Un-
changed
High None High 11.4.0  
CVE-2026-71036 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-70980 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.0 Network High None None Changed High High High 11.4.0  
CVE-2026-71000 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.7 Network Low Low Required Changed High High None 11.4.0  
CVE-2026-70996 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 8.6 Network Low None None Changed High None None 11.4.0  
CVE-2026-71002 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.5 Network Low Low None Changed Low High None 11.4.0  
CVE-2026-70993 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 8.2 Network Low None None Un-
changed
None Low High 11.4.0  
CVE-2026-71016 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 8.2 Network Low None Required Changed High Low None 11.4.0  
CVE-2026-71018 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 8.2 Network Low None Required Changed High Low None 11.4.0  
CVE-2026-71024 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 11.4.0  
CVE-2026-70999 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.4.0  
CVE-2026-71035 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-71028 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller None No 7.8 Local Low Low None Un-
changed
High High High 11.4.0  
CVE-2026-71010 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager None No 7.8 Local Low None Required Un-
changed
High High High 11.4.0  
CVE-2026-70988 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP No 7.7 Network Low Low None Changed High None None 11.4.0  
CVE-2026-71020 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP No 7.6 Network Low Low Required Changed High Low None 11.4.0  
CVE-2026-71021 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP No 7.6 Network Low Low Required Changed High Low None 11.4.0  
CVE-2026-71027 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP No 7.6 Network Low Low Required Changed High Low None 11.4.0  
CVE-2026-71022 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Workbench HTTP No 7.6 Network Low Low Required Changed High Low None 11.4.0  
CVE-2026-70985 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-70986 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-70987 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-71023 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 7.5 Network Low None None Un-
changed
None High None 11.4.0  
CVE-2026-71038 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2022-23437 Oracle Commerce Guided Search / Oracle Commerce Experience Manager MDEX (dom4j) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2024-9143 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge (OpenSSL) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 11.4.0  
CVE-2026-71034 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge SOAP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-70955 Oracle Commerce Platform Dynamo Application Framework TCP Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 11.4.0  
CVE-2026-71009 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.4.0  
CVE-2026-71030 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 7.2 Network Low None None Changed Low Low None 11.4.0  
CVE-2026-71032 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 7.2 Network Low None None Changed Low Low None 11.4.0  
CVE-2026-71003 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.4.0  
CVE-2026-71012 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.4.0  
CVE-2026-70992 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System None No 7.0 Local High Low None Un-
changed
High High High 11.4.0  
CVE-2026-70982 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 6.8 Network High None None Changed High None None 11.4.0  
CVE-2026-70983 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 6.8 Network High None None Changed High None None 11.4.0  
CVE-2026-70990 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 6.8 Network High None None Changed High None None 11.4.0  
CVE-2026-71007 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 6.8 Network Low High None Changed High None None 11.4.0  
CVE-2026-71008 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 6.8 Network Low High None Changed High None None 11.4.0  
CVE-2026-71017 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 6.5 Network High None None Un-
changed
High None Low 11.4.0  
CVE-2026-71001 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.4.0  
CVE-2026-70989 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System None No 6.5 Local Low Low None Changed High None None 11.4.0  
CVE-2026-70991 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System None No 6.3 Local Low None Required Changed High None None 11.4.0  
CVE-2026-71025 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71031 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71004 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71005 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71006 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71011 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71019 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Internal operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-71033 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller None No 5.5 Local Low Low None Un-
changed
High None None 11.4.0  

Additional CVEs addressed are:

  • The patch for CVE-2024-9143 also addresses CVE-2023-6129, CVE-2023-6237, CVE-2024-0727, CVE-2024-13176, CVE-2024-2511, CVE-2024-4741, CVE-2024-5535, and CVE-2024-6119.

 

Oracle Communications Risk Matrix

This Critical Security Patch Update contains 13 new security patches, plus additional third party patches noted below, for Oracle Communications.  9 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-42779 Management Cloud Engine Security (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.0.0.10  
CVE-2026-4800 Oracle Communications Unified Assurance Core (Lodash) HTTP Yes 8.1 Network High None None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-42587 Oracle Communications ASAP Security (Netty) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 7.4.1, 8.0.0  
CVE-2025-13151 Oracle Communications Unified Assurance Core (Libtasn1) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-71142 Oracle Communications Unified Inventory Management Security Component HTTP Yes 7.5 Network Low None None Un-
changed
High None None 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.1  
CVE-2025-13151 Oracle Communications Unified Inventory Management Security Component (Libtasn1) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.1  
CVE-2026-5795 Oracle Communications Unified Assurance Core (Eclipse Jetty) HTTP Yes 7.4 Network High None None Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-71143 Oracle Communications Unified Inventory Management Third Party HTTP Yes 7.4 Network High None None Un-
changed
High High None 7.5.0, 7.5.1, 7.6.0-7.8.0, 8.0.1  
CVE-2026-59084 Oracle Communications Unified Assurance Core (Apache Tomcat) HTTP No 7.3 Network Low Low Required Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-29167 Oracle Communications Unified Assurance Core (Apache HTTP Server) HTTP No 7.2 Network Low High None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-42779 Oracle Communications Unified Assurance Core (Apache Mina) HTTP No 7.2 Network Low High None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-4176 Oracle Communications Unified Assurance Core (Perl) HTTP No 7.2 Network Low High None Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-55956 Management Cloud Engine Security (Apache Tomcat) HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 25.2.0.0.10  

Additional CVEs addressed are:

  • The patch for CVE-2026-4176 also addresses CVE-2026-27171 and CVE-2026-3381.
  • The patch for CVE-2026-55956 also addresses CVE-2026-50229, CVE-2026-53404, CVE-2026-53434, CVE-2026-55276, and CVE-2026-55955.
  • The patch for CVE-2026-59084 also addresses CVE-2026-59083.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-42779 also addresses CVE-2026-42778.
  • The patch for CVE-2026-29167 also addresses CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, and CVE-2026-49975.
  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Management Cloud Engine
    • Security (Spring Framework): CVE-2026-41855, CVE-2026-41838, CVE-2026-41839, CVE-2026-41840, CVE-2026-41841, CVE-2026-41842, CVE-2026-41843, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852, CVE-2026-41853 and CVE-2026-41854 [VEX Justification: vulnerable_code_not_in_execute_path].
  • Oracle Communications Network Analytics Data Director
    • Third Party (logback): CVE-2026-10532 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle Construction and Engineering Risk Matrix

This Critical Security Patch Update contains 1 new security patch for Oracle Construction and Engineering.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-41240 Primavera P6 Enterprise Project Portfolio Management Web Access (DOMPurify) HTTP Yes 8.2 Network Low None Required Changed High Low None 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.3, 23.12.0.0-23.12.19.0, 24.12.0.0-24.12.15.0, 25.12.0.0-25.12.6.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-41240 also addresses CVE-2025-15599, CVE-2026-0540, CVE-2026-41238, and CVE-2026-41239.

 

Oracle E-Business Suite Risk Matrix

This Critical Security Patch Update contains 120 new security patches for Oracle E-Business Suite.  27 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the August 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (August 2026), My Oracle Support Note KA923.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60782 Oracle Payments File Transmission HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70926 Oracle Workflow Workflow Notification Mailer SMTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70812 Oracle Call Center Technology Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70813 Oracle Call Center Technology Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70747 Oracle Customers Online Customer Tab HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62450 Oracle Flow Manufacturing Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70686 Oracle General Ledger Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70941 Oracle Payroll Internal Operations None No 8.8 Local Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-70918 Oracle Product Hub Outbound Data HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70948 Oracle Purchasing Other issue HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70761 Oracle Risk Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70707 Oracle Sales for Handhelds Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70710 Oracle Sales Foundation Security API HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60976 Oracle Scripting Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70729 Oracle Teleservice Service Request Form HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61319 Oracle U.S. Federal Financials Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62462 Oracle Work in Process Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70792 Oracle Yard Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62607 Oracle Customer Care Internal Operations HTTP No 8.7 Network Low High None Changed High High None 12.2.3-12.2.15  
CVE-2026-70778 Oracle Customer Care Internal Operations HTTP No 8.7 Network Low Low Required Changed High High None 12.2.3-12.2.15  
CVE-2026-62599 Oracle Trading Community Third Party Data Integration HTTP Yes 8.6 Network Low None None Changed High None None 12.2.3-12.2.15  
CVE-2026-70718 Oracle Bills of Material Internal Operations HTTP No 8.5 Network High Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-70807 Oracle Call Center Technology Internal Operations HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-70770 Oracle Warehouse Management Internal Operations HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-70722 Oracle Advanced Inbound Telephony Internal Operations HTTPS Yes 8.2 Network Low None None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-62448 Oracle Email Center Message Component HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-70773 Oracle HCM Common Architecture Knowledge Integration HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-61340 Oracle MES for Process Manufacturing Internal Operations HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-62605 Oracle Partner Management Internal Operations HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-70702 Oracle Payments File Transmission HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70795 Oracle Applications Platform Engineering Valid Session Oracle Net Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70814 Oracle Call Center Technology Internal Operations HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70815 Oracle Internet Procurement Connector Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70835 Oracle iRecruitment Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70782 Oracle Labor Distribution Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70701 Oracle Payables Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70830 Oracle Process Manufacturing Systems Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70805 Oracle Project Planning and Control Change Management HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70811 Oracle Purchasing Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.5-12.2.15  
CVE-2026-62491 Oracle Purchasing Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70762 Oracle Risk Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62600 Oracle Sales Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70708 Oracle Sales Foundation Security API HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70704 Oracle Trading Community Party Search UI HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70931 Oracle Workflow Workflow Notification Mailer HTTP No 8.1 Network Low Low None Un-
changed
None High High 12.2.3-12.2.15  
CVE-2026-70690 Oracle HRMS (US) US Payroll - General HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-70802 Oracle Public Sector Human Resources Regression Testing HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-71101 Oracle HRMS (US) US Payroll Tax Issues None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70798 Oracle Purchasing Internal Operations None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61331 Oracle Financials Common Modules Common Components HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70687 Oracle Marketing Audience HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70692 Oracle Marketing Encyclopedia System Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70827 Oracle MES for Process Manufacturing Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70694 Oracle Payments File Transmission HTTP No 7.7 Network High High None Changed High High None 12.2.3-12.2.15  
CVE-2026-70695 Oracle Payments File Transmission HTTP No 7.7 Network High High None Changed High High None 12.2.3-12.2.15  
CVE-2026-70945 Oracle Payroll Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70804 Oracle Public Sector Human Resources Regression Testing HTTP No 7.7 Network High High None Changed High High None 12.2.3-12.2.15  
CVE-2026-70771 Oracle Warehouse Management Internal Operations HTTPS No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-70725 Oracle Advanced Inbound Telephony Internal Operations HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 12.2.3-12.2.15  
CVE-2026-61296 Oracle Enterprise Asset Management Linear Asset Management HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-60748 Oracle General Ledger Internal Operations HTTP No 7.6 Network Low High None Changed High Low None 12.2.3-12.2.15  
CVE-2026-70764 Oracle General Ledger Internal Operations HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 12.2.3-12.2.15  
CVE-2026-70803 Oracle General Ledger Internal Operations HTTP No 7.6 Network Low Low None Un-
changed
Low High Low 12.2.3-12.2.15  
CVE-2026-70786 Oracle Service Fulfillment Manager Fulfillment Engine HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-70791 Oracle Transportation Execution Internal Operations HTTP No 7.6 Network Low Low Required Changed Low High None 12.2.3-12.2.15  
CVE-2026-70681 Oracle Applications DBA JRI and other Java utils HTTP Yes 7.5 Network High None Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60769 Oracle General Ledger Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70713 Oracle iSetup General Ledger Update Transform, Reports HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70777 Oracle iSupplier Portal Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70763 Oracle Operations Intelligence Daily Business Intelligence HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70930 Oracle Order Management Product Diagnostic Tools HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70700 Oracle Payables Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.3-12.2.15  
CVE-2026-70696 Oracle Payments File Transmission TCP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70829 Oracle Process Manufacturing Systems Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70947 Oracle Purchasing Other issue HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70706 Oracle Sales Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70810 Oracle Scripting Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70799 Oracle SDP Number Portability Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70772 Oracle Warehouse Management Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70927 Oracle Workflow Workflow Notification Mailer HTTP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.3-12.2.15  
CVE-2026-60759 Oracle Internet Procurement Connector Internal Operations HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70779 Oracle iSupplier Portal Internal Operations HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70699 Oracle Payments File Transmission HTTPS Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70783 Oracle Service Contracts Internal Operations HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-70790 Oracle Telecommunications Billing Integrator Internal Operations HTTP Yes 7.4 Network Low None Required Changed None High None 12.2.3-12.2.15  
CVE-2026-70800 Oracle SDP Number Portability Internal Operations None No 7.3 Local Low High None Changed Low High Low 12.2.3-12.2.15  
CVE-2026-70820 Oracle Call Center Technology Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62540 Oracle Cost Management Cost Planning HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70796 Oracle General Ledger Internal Operations None No 7.2 Local High High None Changed High High None 12.2.3-12.2.15  
CVE-2026-71104 Oracle HRMS (Netherlands) Netherlands Payroll HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70932 Oracle Order Management Product Diagnostic Tools None No 7.2 Local High High None Changed High High None 12.2.3-12.2.15  
CVE-2026-70781 Oracle Proposals Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70797 Oracle Purchasing Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-70680 Oracle Applications DBA Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-61306 Oracle Complex Maintenance, Repair and Overhaul Production HTTP No 7.1 Network High Low None Changed High None Low 12.2.3-12.2.15  
CVE-2026-70806 Oracle E-Business Tax Internal Operations None No 7.1 Local Low Low None Un-
changed
None High High 12.2.3-12.2.15  
CVE-2026-70837 Oracle Financials for Asia/Pacific Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-70816 Oracle Financials for EMEA Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70839 Oracle Financials for EMEA Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70801 Oracle Flow Manufacturing Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60693 Oracle General Ledger Internal Operations HTTP No 7.1 Network High Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-70833 Oracle Landed Cost Management Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70844 Oracle Loans Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70845 Oracle Loans Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-70760 Oracle Order Management Product Diagnostic Tools HTTP No 7.1 Network High Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-60781 Oracle Payments File Transmission HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-62601 Oracle Sales Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70808 Oracle Scripting Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-70809 Oracle Scripting Internal Operations HTTP No 7.1 Network High Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-70774 Oracle Warehouse Management Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-62458 Oracle Work in Process Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
None Low High 12.2.3-12.2.15  
CVE-2026-62449 Oracle Work in Process Internal Operations None No 7.0 Local High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62475 Oracle Shipping Execution Internal Operations HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61198 Oracle Learning Management Internal Operations HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-70732 Oracle Mobile Application Server MWA Terminal Server HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70720 Oracle Production Scheduling Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60830 Oracle Workflow Worklist HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-70775 Oracle Installed Base User Interface HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61139 Oracle Public Sector Financials (International) Authorization HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-70726 Oracle Cash Management Internal Operations None No 6.0 Local Low High None Un-
changed
High High None 12.2.3-12.2.15  

 

Oracle Enterprise Manager Risk Matrix

This Critical Security Patch Update contains 11 new security patches for Oracle Enterprise Manager.  6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.

Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the August 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update August 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU329.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-2332 Oracle Enterprise Manager Base Platform API Gateway (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 24.1  
CVE-2026-2332 Oracle Enterprise Manager Base Platform Agent Next Gen (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 13.5, 24.1  
CVE-2026-2332 Oracle Enterprise Manager Base Platform Monitoring Service (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 13.5, 24.1  
CVE-2026-61284 Oracle Enterprise Manager Base Platform Application Config Console HTTP No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-70737 Oracle Enterprise Manager for Systems Infrastructure Storage Server Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-61286 Oracle Enterprise Manager Base Platform Event Management HTTP Yes 8.6 Network Low None None Un-
changed
Low High Low 13.5, 24.1  
CVE-2026-70684 Oracle Enterprise Manager Base Platform Agent Next Gen HTTP Yes 8.1 Network High None None Un-
changed
High High High 13.5, 24.1  
CVE-2026-61300 Oracle Enterprise Manager Base Platform Agent Next Gen None No 7.8 Local Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-60822 Oracle Enterprise Manager for Systems Infrastructure Agent None No 7.8 Local Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-34481 Enterprise Manager for MySQL Database EM Plugin: General (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 13.5.1.0.0-13.5.6.0.0  
CVE-2026-61298 Oracle Enterprise Manager Base Platform Enterprise Manager Install None No 5.6 Local High Low None Changed High None None 13.5, 24.1  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle Financial Services Applications Risk Matrix

This Critical Security Patch Update contains 8 new security patches for Oracle Financial Services Applications.  6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-33557 Oracle Financial Services Behavior Detection Platform Third Party (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 8.0.8.1, 8.1.2.11  
CVE-2026-33557 Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition User Interface (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 8.0.8.0  
CVE-2026-70922 Oracle Financial Services Enterprise Case Management Web UI HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.0.8.2, 8.1.2.11  
CVE-2026-41855 Oracle Financial Services Compliance Studio Reports (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.1.3.1  
CVE-2026-34481 Oracle Financial Services Behavior Detection Platform Third Party (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.8.1, 8.1.2.11  
CVE-2026-34481 Oracle Financial Services Enterprise Case Management ECM (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.8.2, 8.1.2.11  
CVE-2026-34481 Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition User Interface (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.8.0  
CVE-2026-33929 Oracle Financial Services Enterprise Case Management Web UI (Apache PDFBox) HTTP No 4.3 Network Low Low None Un-
changed
None Low None 8.0.8.2, 8.1.2.11  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2026-41855 also addresses CVE-2026-41838, CVE-2026-41839, CVE-2026-41840, CVE-2026-41841, CVE-2026-41842, CVE-2026-41843, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852, CVE-2026-41853, and CVE-2026-41854.

 

Oracle Food and Beverage Applications Risk Matrix

This Critical Security Patch Update contains 2 new security patches for Oracle Food and Beverage Applications.  Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60591 Oracle Hospitality Simphony POS HTTP Yes 9.1 Network Low None None Un-
changed
None High High 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1  
CVE-2026-60590 Oracle Hospitality Simphony POS HTTP Yes 7.5 Network Low None None Un-
changed
High None None 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1  

 

Oracle Fusion Middleware Risk Matrix

This Critical Security Patch Update contains 262 new security patches, plus additional third party patches noted below, for Oracle Fusion Middleware.  182 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61241 Oracle Internet Directory OID LDAP Server LDAP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73930 Helidon Imperative Web Server HTTP Yes 9.9 Network Low None None Changed Low High Low 4.5.3  
CVE-2026-60720 Oracle Identity Manager OIM Legacy UI HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61066 Oracle Identity Manager OIM Legacy UI RMI No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60990 Oracle Identity Manager Connector Core TLS No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60995 Oracle Identity Manager Connector Core TLS No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61248 Oracle Internet Directory OID LDAP Server LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61003 Oracle Managed File Transfer MFT Runtime Server T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-62608 Oracle Reports Developer Security and Authentication CORBA No 9.9 Network Low Low None Changed High High High 12.2.1.19.0  
CVE-2026-60916 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 9.9 Network Low None None Changed Low High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60730 Oracle WebCenter Portal Composer HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61021 Oracle WebCenter Sites WebCenter Sites HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60702 Oracle WebLogic Server Core T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-71074 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 3.2.18  
CVE-2026-71152 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 4.5.0  
CVE-2026-71164 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 3.2.18  
CVE-2026-73905 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 4.5.0  
CVE-2026-73912 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 4.5.0  
CVE-2026-73921 Helidon Imperative Web Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 1.4.20  
CVE-2026-70905 Oracle Access Manager Agent infrastructure SAML Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60721 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60727 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61258 Oracle Internet Directory OID LDAP Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-62634 Oracle Reports Developer Security and Authentication CORBA Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62639 Oracle Reports Developer Security and Authentication CORBA Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62614 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62626 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62632 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62633 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62635 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-70669 Oracle Reports Developer Security and Authentication HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62611 Oracle Reports Developer Security and Authentication IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62622 Oracle Reports Developer Security and Authentication IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62624 Oracle Reports Developer Security and Authentication IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62640 Oracle Reports Developer Security and Authentication IIOP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62609 Oracle Reports Developer Security and Authentication TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62621 Oracle Reports Developer Security and Authentication TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62630 Oracle Reports Developer Security and Authentication TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-62617 Oracle Reports Developer Security and Authentication UDP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-60958 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60946 Oracle WebCenter Enterprise Capture Client Bundle RMI Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60947 Oracle WebCenter Enterprise Capture Client Bundle RMI Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60921 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60970 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60971 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-70970 Oracle WebCenter Portal Runtime Tools HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61018 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60698 Oracle WebLogic Server Core IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60977 Oracle WebLogic Server WLS Core Components RMI Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0  
CVE-2026-60672 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60696 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-70670 Oracle Reports Developer Security and Authentication IIOP Yes 9.6 Adjacent
Network
Low None None Changed High High High 14.1.2.0.0  
CVE-2026-61001 Oracle Web Services Manager Web Services Security HTTP No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60905 Oracle WebCenter Content Content Server HTTP Yes 9.6 Network Low None Required Changed High High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60861 Service Delivery Platform Messaging Enabler Oracle Net No 9.6 Network Low Low None Changed High High None 14.1.2.0.0, 12.2.1.4.0  
CVE-2026-71166 Helidon Imperative Web Server HTTP Yes 9.4 Network Low None None Un-
changed
High High Low 3.2.18  
CVE-2026-71167 Helidon Imperative Web Server HTTP Yes 9.4 Network Low None None Un-
changed
High High Low 4.5.0  
CVE-2026-73920 Helidon Imperative Web Server HTTP Yes 9.4 Network Low None None Un-
changed
High High Low 4.5.0  
CVE-2026-62629 Oracle Reports Developer Security and Authentication HTTP Yes 9.4 Network Low None None Un-
changed
Low High High 14.1.2.0.0  
CVE-2026-71065 Helidon Imperative Web Server HTTP Yes 9.3 Network Low None None Changed High Low None 3.2.18  
CVE-2026-62613 Oracle Reports Developer Security and Authentication CORBA Yes 9.3 Adjacent
Network
Low None None Changed High High None 12.2.1.19.0  
CVE-2026-62637 Oracle Reports Developer Security and Authentication CORBA Yes 9.3 Adjacent
Network
Low None None Changed High High None 14.1.2.0.0  
CVE-2026-62618 Oracle Reports Developer Security and Authentication HTTP Yes 9.3 Network Low None None Changed High Low None 12.2.1.19.0  
CVE-2026-70673 Oracle Reports Developer Security and Authentication HTTP Yes 9.3 Network Low None None Changed High Low None 14.1.2.0.0  
CVE-2026-73865 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 3.2.18  
CVE-2026-73866 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 4.5.0  
CVE-2026-73916 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 3.2.18  
CVE-2026-73917 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 4.5.0  
CVE-2026-73922 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 1.4.19  
CVE-2026-73924 Helidon Imperative Web Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 1.4.19  
CVE-2026-62610 Oracle Reports Developer Security and Authentication HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.19.0  
CVE-2026-62638 Oracle Reports Developer Security and Authentication HTTP Yes 9.1 Network Low None None Un-
changed
None High High 14.1.2.0.0  
CVE-2026-70668 Oracle Reports Developer Security and Authentication SOAP Yes 9.1 Network Low None None Un-
changed
High High None 14.1.2.0.0  
CVE-2026-60737 Oracle Web Services Manager Web Services Security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60728 Oracle WebCenter Portal Portlet Services HTTP Yes 9.1 Network Low None None Un-
changed
High None High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61008 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61034 Oracle WebCenter Sites WebCenter Sites HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61029 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.0 Network High None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60726 Oracle Access Manager Authentication Engine HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60715 Oracle Identity Manager OIM Legacy UI HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61118 Oracle Identity Manager OIM Legacy UI HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60716 Oracle Identity Manager OIM Legacy UI T3, IIOP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60722 Oracle Identity Manager OIM Legacy UI T3, IIOP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-62612 Oracle Reports Developer Security and Authentication HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62619 Oracle Reports Developer Security and Authentication HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62623 Oracle Reports Developer Security and Authentication UDP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 12.2.1.19.0  
CVE-2026-62631 Oracle Reports Developer Security and Authentication UDP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-70674 Oracle Reports Developer Security and Authentication UDP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-61002 Oracle SOA Suite B2B Engine HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61231 Oracle Virtual Directory Virtual Directory Server LDAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60729 Oracle WebCenter Portal Composer HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61213 Oracle WebCenter Portal Runtime Tools HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60731 Oracle WebCenter Portal Composer RMI No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61017 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61022 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61032 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61040 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61042 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61058 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60707 Oracle Identity Manager Security HTTP No 8.7 Network Low High None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60996 Oracle Identity Manager Connector Connectors and Connector Server HTTPS No 8.7 Network Low High None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60903 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60934 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60935 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60954 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60980 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60981 Oracle WebCenter Content Content Server HTTP No 8.7 Network Low Low Required Changed High High None 14.1.2.0.0, 12.2.1.4.0  
CVE-2026-61193 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61215 Oracle WebCenter Portal Runtime Tools HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61219 Oracle WebCenter Portal Runtime Tools HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60860 Service Delivery Platform Messaging Enabler TCP Yes 8.7 Network High None None Changed None High High 14.1.2.0.0, 12.2.1.4.0  
CVE-2026-73939 Helidon Imperative Web Server HTTP Yes 8.6 Network Low None None Changed None High None 3.2.20  
CVE-2026-62620 Oracle Reports Developer Security and Authentication HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.19.0  
CVE-2026-62625 Oracle Reports Developer Security and Authentication SOAP Yes 8.6 Network Low None None Un-
changed
High Low Low 12.2.1.19.0  
CVE-2026-62636 Oracle Reports Developer Security and Authentication SOAP Yes 8.6 Network Low None None Un-
changed
High Low Low 14.1.2.0.0  
CVE-2026-62628 Oracle Reports Developer Security and Authentication TCP Yes 8.6 Network Low None None Changed High None None 12.2.1.19.0  
CVE-2026-61228 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61230 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61033 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.6 Network Low None None Un-
changed
High Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61045 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.6 Network Low None None Un-
changed
High Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60699 Oracle WebLogic Server Core T3, IIOP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-71155 Helidon Imperative Web Server HTTP No 8.5 Network Low Low None Changed High Low None 3.2.18  
CVE-2026-62615 Oracle Reports Developer Security and Authentication HTTP No 8.5 Network High Low None Changed High High High 12.2.1.19.0  
CVE-2026-60841 Oracle Unified Directory OUD Core LDAP No 8.5 Network High Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60849 Oracle Unified Directory OUD Core LDAP No 8.5 Network High Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61212 Oracle WebCenter Portal Runtime Tools HTTP No 8.5 Network High Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60928 Oracle WebCenter Content Content Server None No 8.4 Local Low Low None Changed High High None 14.1.2.0.0  
CVE-2026-73929 Helidon Imperative Web Server HTTP Yes 8.3 Network Low None None Changed Low Low Low 4.5.3  
CVE-2026-73931 Helidon Imperative Web Server HTTP Yes 8.3 Network Low None None Changed Low Low Low 4.5.3  
CVE-2026-71159 Helidon Imperative Web Server HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 3.2.18  
CVE-2026-73925 Helidon Imperative Web Server HTTP Yes 8.2 Network Low None None Un-
changed
Low High None 1.4.19  
CVE-2026-73937 Helidon Imperative Web Server HTTP/2 Yes 8.2 Network Low None None Un-
changed
Low None High 4.5.0  
CVE-2026-60944 Oracle WebCenter Content Content Server HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60955 Oracle WebCenter Content Content Server HTTP No 8.2 Network Low High None Changed Low High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61222 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61011 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.2 Network Low None None Un-
changed
None High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61016 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.2 Network Low None None Un-
changed
None High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61038 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61054 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-71110 Helidon Imperative Web Server HTTPS No 8.1 Network Low Low None Un-
changed
High High None 4.5.0  
CVE-2026-60992 Oracle Identity Manager Connector Core TLS Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-70671 Oracle Reports Developer Security and Authentication HTTP No 8.1 Network Low Low None Un-
changed
High High None 14.1.2.0.0  
CVE-2026-70675 Oracle Reports Developer Security and Authentication HTTP Yes 8.1 Network High None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-70924 Oracle Web Services Manager Web Services Security HTTPS Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61177 Oracle WebCenter Portal Runtime Tools HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61229 Oracle WebCenter Portal Runtime Tools HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60680 Oracle WebLogic Server Core HTTP No 8.1 Network Low Low None Un-
changed
None High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60415 Oracle WebLogic Server Core T3, IIOP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60998 Oracle Identity Manager Connector Microsoft Active Directory LDAP No 8.0 Network High High None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60961 Oracle WebCenter Content Content Server HTTP Yes 8.0 Adjacent
Network
High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-71111 Oracle Identity Manager Installer None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60991 Oracle Identity Manager Connector Core None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60412 Oracle Outside In Technology Outside In Core None No 7.8 Local Low None Required Un-
changed
High High High 8.5.8  
CVE-2026-60413 Oracle Outside In Technology Outside In Core None No 7.8 Local Low None Required Un-
changed
High High High 8.5.8  
CVE-2026-60414 Oracle Outside In Technology Outside In Core None No 7.8 Local Low None Required Un-
changed
High High High 8.5.8  
CVE-2026-60392 Oracle Outside In Technology Outside In PDF Export SDK None No 7.8 Local Low None Required Un-
changed
High High High 8.5.8  
CVE-2026-61291 Oracle WebCenter Content Content Server None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60969 Oracle Unified Directory OUD Core LDAP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60983 Oracle WebCenter Content Content Server HTTP No 7.7 Network Low Low None Changed High None None 14.1.2.0.0, 12.2.1.4.0  
CVE-2026-60733 Oracle WebCenter Portal Composer HTTP No 7.7 Network High Low None Changed Low High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61199 Oracle WebCenter Portal Runtime Tools HTTP No 7.7 Network Low Low None Changed High None None 14.1.2.0.0  
CVE-2026-60909 Oracle WebCenter Content Content Server HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61208 Oracle WebCenter Portal Runtime Tools HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61227 Oracle WebCenter Portal Runtime Tools HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-70908 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.2.18  
CVE-2026-71153 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 1.4.20  
CVE-2026-71158 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 3.2.18  
CVE-2026-71160 Helidon Imperative Web Server HTTP No 7.5 Network High Low None Un-
changed
High High High 3.2.18  
CVE-2026-73878 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 3.2.18  
CVE-2026-73879 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None High None 4.5.1  
CVE-2026-73882 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.2.19  
CVE-2026-73883 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 3.2.18  
CVE-2026-73884 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 4.5.0  
CVE-2026-73902 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.2.19  
CVE-2026-73903 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None High None 4.5.1  
CVE-2026-73907 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 3.2.18  
CVE-2026-73908 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 4.5.0  
CVE-2026-73915 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 4.5.0  
CVE-2026-73927 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.2.20  
CVE-2026-73936 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
None None High 4.5.1  
CVE-2026-73938 Helidon Imperative Web Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 4.5.0  
CVE-2026-73887 Helidon Imperative Web Server HTTP/2 Yes 7.5 Network Low None None Un-
changed
High None None 4.5.0  
CVE-2026-73890 Helidon Imperative Web Server HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 4.5.0  
CVE-2026-73934 Helidon Imperative Web Server HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 3.2.19  
CVE-2026-73935 Helidon Imperative Web Server HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 4.5.1  
CVE-2026-42587 Helidon Imperative Web Server (Netty) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 3.2.18  
CVE-2026-60993 Oracle Identity Manager Connector Core TLS Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60850 Oracle Unified Directory OUD Core LDAP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60889 Oracle Unified Directory OUD Core LDAP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60914 Oracle Unified Directory OUD Core LDAP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60906 Oracle WebCenter Content Content Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61007 Oracle WebCenter Sites WebCenter Sites HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60679 Oracle WebLogic Server Core T3, IIOP No 7.5 Network High Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60915 Helidon Imperative Web Server HTTP Yes 7.4 Network High None None Un-
changed
High High None 4.5.0  
CVE-2026-70672 Oracle Reports Developer Security and Authentication HTTP Yes 7.4 Network High None None Un-
changed
High High None 14.1.2.0.0  
CVE-2026-60933 Oracle WebCenter Content Content Server HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-73891 Helidon Imperative Web Server HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 4.5.0  
CVE-2026-73894 Helidon Imperative Web Server HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 4.5.0  
CVE-2026-73918 Helidon Imperative Web Server HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 4.5.0  
CVE-2026-73933 Helidon Imperative Web Server HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 4.5.3  
CVE-2026-33186 Helidon Imperative Web Server (gRPC) HTTP/2 Yes 7.3 Network Low None None Un-
changed
Low Low Low 4.5.0  
CVE-2026-73875 Helidon Imperative Web Server HTTP Yes 7.2 Network Low None None Changed Low Low None 3.2.19  
CVE-2026-73876 Helidon Imperative Web Server HTTP Yes 7.2 Network Low None None Changed Low Low None 4.5.1  
CVE-2026-73885 Helidon Imperative Web Server HTTP Yes 7.2 Network Low None None Changed Low Low None 3.2.18  
CVE-2026-73886 Helidon Imperative Web Server HTTP Yes 7.2 Network Low None None Changed Low Low None 4.5.0  
CVE-2026-73928 Helidon Imperative Web Server HTTP Yes 7.2 Network Low None None Changed Low Low None 4.5.3  
CVE-2026-60994 Oracle Identity Manager Connector Core None No 7.2 Local High Low Required Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-62616 Oracle Reports Developer Security and Authentication SMTP Yes 7.2 Network Low None None Changed None Low Low 12.2.1.19.0  
CVE-2026-62627 Oracle Reports Developer Security and Authentication HTTP No 7.1 Network High Low None Changed High Low None 12.2.1.19.0  
CVE-2026-60949 Oracle WebCenter Content Content Server HTTP No 7.1 Network High Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61288 Oracle WebCenter Content Content Server HTTP Yes 7.1 Network Low None Required Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61290 Oracle WebCenter Content Content Server HTTP No 7.1 Network High Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-70858 Oracle WebCenter Content Content Server HTTP Yes 7.1 Network Low None Required Changed Low Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61295 Oracle WebCenter Content Content Server None No 7.1 Local Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61124 Oracle WebCenter Portal Runtime Tools HTTP Yes 7.1 Network Low None Required Un-
changed
None High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-71029 Helidon Imperative Web Server HTTP Yes 6.8 Network High None None Changed High None None 3.2.18  
CVE-2026-60895 Oracle Unified Directory OUD Core LDAP No 6.8 Network High Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60865 Service Delivery Platform Messaging Enabler HTTP No 6.8 Network Low High None Changed High None None 14.1.2.0.0, 12.2.1.4.0  
CVE-2026-71162 Helidon Imperative Web Server HTTP Yes 6.5 Network High None None Un-
changed
High Low None 3.2.18  
CVE-2026-73867 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 3.2.18  
CVE-2026-73868 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.5.0  
CVE-2026-73892 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.5.0  
CVE-2026-73893 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.5.0  
CVE-2026-73897 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.5.0  
CVE-2026-73904 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 4.5.1  
CVE-2026-73914 Helidon Imperative Web Server HTTP Yes 6.5 Network Low None None Un-
changed
Low None Low 4.5.0  
CVE-2026-73896 Helidon Imperative Web Server HTTP/2 Yes 6.5 Network Low None None Un-
changed
Low None Low 4.5.0  
CVE-2026-60866 Service Delivery Platform Messaging Enabler HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 14.1.2.0.0  
CVE-2026-70923 Helidon Imperative Web Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 3.2.19  
CVE-2026-73869 Helidon Imperative Web Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 3.2.18  
CVE-2026-73870 Helidon Imperative Web Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 4.5.0  
CVE-2026-73898 Helidon Imperative Web Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 4.5.0  
CVE-2026-71154 Helidon Imperative Web Server None No 6.1 Local Low Low None Un-
changed
High Low None 4.5.0  
CVE-2026-70716 Helidon Imperative Web Server HTTP Yes 5.9 Network High None None Un-
changed
None High None 4.5.0  
CVE-2026-73909 Helidon Imperative Web Server HTTP Yes 5.9 Network High None None Un-
changed
High None None 3.2.19  
CVE-2026-71165 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 3.2.18  
CVE-2026-73874 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 4.5.0  
CVE-2026-73881 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 4.5.0  
CVE-2026-73911 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 4.5.0  
CVE-2026-73913 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 4.5.0  
CVE-2026-73919 Helidon Imperative Web Server HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 3.2.18  
CVE-2026-71156 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
None Low None 3.2.19  
CVE-2026-71157 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.0  
CVE-2026-71161 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 3.2.18  
CVE-2026-73871 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.2.18  
CVE-2026-73872 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.0  
CVE-2026-73877 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.2.18  
CVE-2026-73888 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.0  
CVE-2026-73889 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.0  
CVE-2026-73895 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.2.18  
CVE-2026-73899 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.2.19  
CVE-2026-73900 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.1  
CVE-2026-73906 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.0  
CVE-2026-73910 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 4.5.1  
CVE-2026-73932 Helidon Imperative Web Server HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 4.5.3  
CVE-2026-70727 Helidon Imperative Web Server HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 3.2.18  
CVE-2026-73901 Helidon Imperative Web Server HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 4.5.1  
CVE-2026-73880 Helidon Imperative Web Server None No 4.4 Local Low High None Un-
changed
High None None 4.5.1  
CVE-2026-71124 Oracle Access Manager Authorization Engine TCP No 4.3 Network Low Low None Un-
changed
None None Low 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-73873 Helidon Imperative Web Server HTTP No 4.2 Network High Low None Un-
changed
Low Low None 3.2.18  
CVE-2026-60853 Helidon Imperative Web Server HTTP Yes 3.7 Network High None None Un-
changed
Low None None 3.2.20  
CVE-2026-73923 Helidon Imperative Web Server HTTP Yes 3.7 Network High None None Un-
changed
None Low None 1.4.20  

Additional CVEs addressed are:

  • The patch for CVE-2026-33186 also addresses CVE-2023-44487.
  • The patch for CVE-2026-60727 also addresses CVE-2025-61757.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-60679 also addresses CVE-2023-21839 and CVE-2024-20931.
  • The patch for CVE-2026-61001 also addresses CVE-2026-21992.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Web Services Manager
    • Web Services Security: CVE-2026-71093.

 

Oracle Analytics Risk Matrix

This Critical Security Patch Update contains 16 new security patches for Oracle Analytics.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71059 Oracle BI Publisher Web Service API SOAP No 9.9 Network Low Low None Changed High High High 8.2.0.0.0, 26.1.0.0.0  
CVE-2026-71058 Oracle BI Publisher Web Service API HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-71055 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0  
CVE-2026-71057 Oracle BI Publisher BI Platform Security HTTP No 8.5 Network Low Low None Changed High None Low 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0  
CVE-2026-61305 Oracle BI Publisher BI Platform Security HTTP No 8.3 Network Low Low None Un-
changed
High High Low 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-71095 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.1.4.0  
CVE-2026-71096 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP No 8.2 Network High Low None Changed High High None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-61302 Oracle Business Intelligence Enterprise Edition Pod Admin HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-71122 Oracle Business Intelligence Enterprise Edition Platform Security HTTP No 8.0 Network High High None Changed High High High 26.01.0.0.0  
CVE-2026-71097 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.8 Local Low Low None Un-
changed
High High High 26.01.0.0.0  
CVE-2026-71056 Oracle Business Intelligence Enterprise Edition BI Search HTTP No 7.7 Network Low Low None Changed High None None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-71107 Oracle Business Intelligence Enterprise Edition Analytics Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-71061 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-71094 Oracle Business Intelligence Enterprise Edition Presentation Services None No 7.3 Local Low Low Required Un-
changed
High High High 12.2.1.4.0  
CVE-2026-71099 Oracle Business Intelligence Enterprise Edition Analytics Web Answers HTTP No 7.2 Network Low High None Un-
changed
High High High 26.01.0.0.0  
CVE-2026-71098 Oracle Business Intelligence Enterprise Edition Platform Security None No 7.0 Local High Low None Un-
changed
High High High 26.01.0.0.0  

 

Oracle Hospitality Applications Risk Matrix

This Critical Security Patch Update contains 1 new security patch for Oracle Hospitality Applications.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71106 Oracle Hospitality OPERA 5 Property Services Opera Servlet HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 5.6.28.0-5.6.28.1  

 

Oracle Hyperion Risk Matrix

This Critical Security Patch Update contains 262 new security patches for Oracle Hyperion.  107 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-70880 Oracle Hyperion Data Relationship Management Access and security TCP Yes 10.0 Network Low None None Changed High High High 11.2.25.0.000  
CVE-2026-70921 Oracle Hyperion Financial Management Security TLS Yes 10.0 Network Low None None Changed High High None 11.2.25.0.000  
CVE-2026-61206 Oracle Hyperion Calculation Manager Security HTTP No 9.9 Network Low Low None Changed High High High 11.2.25.0.000  
CVE-2026-70920 Oracle Hyperion Financial Management Security SQL No 9.9 Network Low Low None Changed High High High 11.2.25.0.000  
CVE-2026-60858 Oracle Hyperion Calculation Manager Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70871 Oracle Hyperion Data Relationship Management Access and security TCP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70873 Oracle Hyperion Data Relationship Management Access and security TCP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70817 Oracle Hyperion Financial Management Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70739 Oracle Hyperion Financial Reporting Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70740 Oracle Hyperion Financial Reporting Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70745 Oracle Hyperion Financial Reporting Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62457 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2023-50164 Oracle Hyperion Infrastructure Technology Common Security (Apache Struts) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62539 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62541 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62543 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62544 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62582 Oracle Hyperion Calculation Manager Security HTTP No 9.6 Network Low Low None Changed High High None 11.2.25.0.000  
CVE-2026-70958 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 9.6 Network Low None Required Changed High High High 11.2.25.0.000  
CVE-2026-62463 Oracle Hyperion Infrastructure Technology Lifecycle Management HTTP No 9.6 Network Low Low None Changed High High None 11.2.25.0.000  
CVE-2026-70872 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70883 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70876 Oracle Hyperion Data Relationship Management Access and security HTTPS No 9.1 Network Low High None Changed High High High 11.2.25.0.000  
CVE-2026-70884 Oracle Hyperion Data Relationship Management Access and security SOAP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70854 Oracle Hyperion Financial Management Security HTTP Yes 9.1 Network Low None None Un-
changed
None High High 11.2.25.0.000  
CVE-2026-70741 Oracle Hyperion Financial Reporting Server RMI Yes 9.1 Network Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70730 Oracle Hyperion Profitability and Cost Management Deployment HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-61276 Oracle Hyperion Calculation Manager Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70874 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70877 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70886 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70899 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70940 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-71150 Oracle Hyperion Financial Management Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70818 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70819 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70821 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70928 Oracle Hyperion Financial Management Security SQL No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70944 Oracle Hyperion Financial Management Security TCP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70787 Oracle Hyperion Financial Reporting Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70742 Oracle Hyperion Financial Reporting Server HTTPS No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62500 Oracle Hyperion Infrastructure Technology Common Events HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70956 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70965 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70966 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70882 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.7 Network Low Low Required Changed High High None 11.2.25.0.000  
CVE-2026-70900 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 8.7 Network High None None Changed High High None 11.2.25.0.000  
CVE-2026-70903 Oracle Hyperion Data Relationship Management Access and security HTTPS No 8.7 Network Low Low Required Changed High High None 11.2.25.0.000  
CVE-2026-62535 Oracle Hyperion Infrastructure Technology Installation and Configuration MySQL Protocol Yes 8.6 Network Low None None Changed High None None 11.2.25.0.000  
CVE-2026-70721 Oracle Hyperion Profitability and Cost Management Deployment HTTP Yes 8.6 Network Low None None Changed High None None 11.2.25.0.000  
CVE-2026-70885 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.5 Network High Low None Changed High High High 11.2.25.0.000  
CVE-2026-70840 Oracle Hyperion Financial Management Security None No 8.4 Local Low Low None Changed High High None 11.2.25.0.000  
CVE-2026-70842 Oracle Hyperion Financial Management Security None No 8.4 Local Low Low None Changed High High None 11.2.25.0.000  
CVE-2026-62598 Oracle Hyperion Calculation Manager Security SFTP No 8.2 Network High Low None Changed High High None 11.2.25.0.000  
CVE-2026-70887 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70892 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.2 Network High Low None Changed High High None 11.2.25.0.000  
CVE-2026-70870 Oracle Hyperion Data Relationship Management Web Client - Unicode HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 11.2.23.0.000  
CVE-2026-70897 Oracle Hyperion Data Relationship Management Access and security HTTPS Yes 8.2 Network Low None None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70893 Oracle Hyperion Data Relationship Management Access and security SQL No 8.2 Network High Low None Changed High High None 11.2.25.0.000  
CVE-2026-70909 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70952 Oracle Hyperion Financial Management Security HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70743 Oracle Hyperion Financial Reporting Server HTTPS Yes 8.2 Network Low None None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-62485 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 8.2 Network Low None Required Changed High Low None 11.2.25.0.000  
CVE-2026-70964 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.2 Network High Low None Changed High High None 11.2.25.0.000  
CVE-2026-61281 Oracle Hyperion Calculation Manager Security HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 11.2.25.0.000  
CVE-2026-61293 Oracle Hyperion Calculation Manager Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70878 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70881 Oracle Hyperion Data Relationship Management Access and security HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70901 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70904 Oracle Hyperion Data Relationship Management Access and security SOAP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70929 Oracle Hyperion Financial Management Security HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70925 Oracle Hyperion Financial Management Security SQL No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70943 Oracle Hyperion Financial Management Security TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70744 Oracle Hyperion Financial Reporting Server HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70746 Oracle Hyperion Financial Reporting Server HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70749 Oracle Hyperion Financial Reporting Server HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62471 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62501 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62502 Oracle Hyperion Infrastructure Technology Common Events HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62477 Oracle Hyperion Infrastructure Technology Common Security HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70957 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70959 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 8.1 Network Low Low None Un-
changed
None High High 11.2.25.0.000  
CVE-2023-26464 Oracle Hyperion Infrastructure Technology Installation and Configuration (Apache Log4j) HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62531 Oracle Hyperion Infrastructure Technology Lifecycle Management HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70738 Oracle Hyperion Profitability and Cost Management Deployment HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62602 Oracle Hyperion Calculation Manager Security SSH Yes 8.0 Adjacent
Network
High None None Changed High High None 11.2.25.0.000  
CVE-2026-70685 Oracle Hyperion Calculation Manager Security None No 7.9 Local Low None None Changed High Low None 11.2.25.0.000  
CVE-2026-70879 Oracle Hyperion Data Relationship Management Access and security None No 7.8 Local High Low None Changed High High High 11.2.25.0.000  
CVE-2026-70750 Oracle Hyperion Financial Reporting Server None No 7.8 Local Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62581 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 7.8 Local Low Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62571 Oracle Hyperion Calculation Manager Security HTTP No 7.7 Network Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-70894 Oracle Hyperion Data Relationship Management Access and security None No 7.7 Local Low None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70828 Oracle Hyperion Financial Management Security HTTP No 7.7 Network Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-70942 Oracle Hyperion Financial Management Security HTTP No 7.7 Network Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-62467 Oracle Hyperion Infrastructure Technology Common Events HTTP No 7.7 Network Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-70723 Oracle Hyperion Profitability and Cost Management Deployment HTTP No 7.7 Network Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-70678 Oracle Hyperion Calculation Manager Security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.25.0.000  
CVE-2026-70960 Oracle Hyperion Financial Management Security HTTP No 7.6 Network Low Low Required Changed High Low None 11.2.25.0.000  
CVE-2026-70875 Oracle Hyperion Data Relationship Management Access and security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70889 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70890 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70891 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70896 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-34481 Oracle Hyperion Data Relationship Management Installation/Configuration (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 11.2.25.0.000  
CVE-2026-70822 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70832 Oracle Hyperion Financial Management Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70937 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70946 Oracle Hyperion Financial Management Security HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-71117 Oracle Hyperion Financial Management Security None No 7.5 Local High High None Changed High High High 11.2.25.0.000  
CVE-2026-60391 Oracle Hyperion Financial Reporting Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70752 Oracle Hyperion Financial Reporting Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2022-34169 Oracle Hyperion Infrastructure Technology Common Security (Apache Xalan-Java) HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62550 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62552 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62554 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70973 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-60393 Oracle Hyperion Infrastructure Technology Lifecycle Management HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62481 Oracle Hyperion Infrastructure Technology Common Events SQL No 7.5 Network High Low None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62545 Oracle Hyperion Infrastructure Technology Installation and Configuration TCP Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70898 Oracle Hyperion Data Relationship Management Access and security HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70823 Oracle Hyperion Financial Management Security HTTPS Yes 7.4 Network High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62492 Oracle Hyperion Infrastructure Technology Common Security HTTPS Yes 7.4 Network High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62538 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTPS Yes 7.4 Network High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62551 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 11.2.25.0.000  
CVE-2026-62459 Oracle Hyperion Calculation Manager Security HTTP No 7.2 Network High High None Changed High Low Low 11.2.25.0.000  
CVE-2026-70834 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70939 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70950 Oracle Hyperion Financial Management Security HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70735 Oracle Hyperion Profitability and Cost Management Deployment HTTP No 7.2 Network Low High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-61259 Oracle Hyperion Calculation Manager Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70705 Oracle Hyperion Calculation Manager Security None No 7.1 Local Low None None Changed High None None 11.2.25.0.000  
CVE-2026-70902 Oracle Hyperion Data Relationship Management Access and security None No 7.1 Local Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70933 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70934 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70935 Oracle Hyperion Financial Management Security HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70936 Oracle Hyperion Financial Management Security None No 7.1 Local Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62522 Oracle Hyperion Infrastructure Technology Common Security HTTP No 7.1 Network High Low None Changed High Low None 11.2.25.0.000  
CVE-2026-70971 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-62536 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 7.1 Local Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62537 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 7.1 Local Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70967 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 7.1 Local Low Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70733 Oracle Hyperion Profitability and Cost Management Deployment HTTP No 7.1 Network Low Low None Un-
changed
High None Low 11.2.25.0.000  
CVE-2026-70736 Oracle Hyperion Profitability and Cost Management Deployment HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70676 Oracle Hyperion Calculation Manager Security HTTP Yes 7.0 Network High None None Un-
changed
Low High Low 11.2.25.0.000  
CVE-2026-70914 Oracle Hyperion Financial Management Security None No 7.0 Local High None Required Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70843 Oracle Hyperion Financial Management Security TLS Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70751 Oracle Hyperion Financial Reporting Server HTTP Yes 6.8 Network High None Required Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70780 Oracle Hyperion Financial Reporting Server TLS Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70972 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 6.8 Network High Low None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-61313 Oracle Hyperion Calculation Manager Security None No 6.7 Local Low High None Changed High Low None 11.2.25.0.000  
CVE-2026-71109 Oracle Hyperion Financial Management Security None No 6.7 Local Low High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-70888 Oracle Hyperion Data Relationship Management Access and security HTTP No 6.6 Network High High None Un-
changed
High High High 11.2.25.0.000  
CVE-2022-23305 Oracle Hyperion Financial Management Security (Apache Log4j) TCP No 6.6 Network High High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-62578 Oracle Hyperion Calculation Manager Security HTTP Yes 6.5 Adjacent
Network
Low None None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70895 Oracle Hyperion Data Relationship Management Access and security None No 6.5 Local Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-70824 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70825 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70826 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70831 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70849 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low High None Un-
changed
High None High 11.2.25.0.000  
CVE-2026-70938 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70969 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70975 Oracle Hyperion Financial Management Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71121 Oracle Hyperion Financial Management Security HTTP Yes 6.5 Network Low None None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-70847 Oracle Hyperion Financial Management Security None No 6.5 Local Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-71091 Oracle Hyperion Financial Management Security SQL No 6.5 Network Low High None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-60682 Oracle Hyperion Financial Reporting Repository HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-70767 Oracle Hyperion Financial Reporting Server HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70769 Oracle Hyperion Financial Reporting Server HTTP Yes 6.5 Network High None None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70788 Oracle Hyperion Financial Reporting Server HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62506 Oracle Hyperion Infrastructure Technology Common Security HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62523 Oracle Hyperion Infrastructure Technology Common Security HTTP Yes 6.5 Network Low None Required Un-
changed
High None None 11.2.25.0.000  
CVE-2026-70968 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 6.5 Network Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62572 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 6.5 Local Low Low None Changed High None None 11.2.25.0.000  
CVE-2026-62555 Oracle Hyperion Infrastructure Technology Installation and Configuration SQL No 6.5 Network Low High None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-62576 Oracle Hyperion Infrastructure Technology Installation and Configuration TLS Yes 6.5 Network High None None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-71090 Oracle Hyperion Financial Management Security HTTP No 6.4 Network High Low None Un-
changed
Low Low High 11.2.25.0.000  
CVE-2026-71119 Oracle Hyperion Financial Management Security None No 6.4 Local High High None Un-
changed
High High High 11.2.25.0.000  
CVE-2026-71103 Oracle Hyperion Financial Management Security HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 11.2.25.0.000  
CVE-2026-70753 Oracle Hyperion Financial Reporting Server HTTP No 6.3 Network Low Low Required Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-62558 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 6.3 Local High None Required Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70838 Oracle Hyperion Financial Management Security None No 6.1 Local Low Low None Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70765 Oracle Hyperion Financial Reporting Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.2.25.0.000  
CVE-2026-70768 Oracle Hyperion Financial Reporting Server HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.2.25.0.000  
CVE-2026-62499 Oracle Hyperion Infrastructure Technology Common Security HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.2.25.0.000  
CVE-2026-62568 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.2.25.0.000  
CVE-2026-70961 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.2.25.0.000  
CVE-2026-71013 Oracle Hyperion Financial Management Security None No 6.0 Local Low High None Un-
changed
High High None 11.2.25.0.000  
CVE-2026-70677 Oracle Hyperion Calculation Manager Security HTTP Yes 5.9 Network High None Required Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70789 Oracle Hyperion Financial Reporting Server HTTP Yes 5.9 Network High None Required Un-
changed
High Low None 11.2.25.0.000  
CVE-2026-70841 Oracle Hyperion Financial Management Security None No 5.6 Local High Low None Changed High None None 11.2.25.0.000  
CVE-2026-70836 Oracle Hyperion Financial Management Security None No 5.5 Local Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62553 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 5.5 Local Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62564 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 5.5 Local Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62573 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 5.5 Local Low Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62441 Oracle Hyperion Calculation Manager Security HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62603 Oracle Hyperion Calculation Manager Security SFTP Yes 5.4 Adjacent
Network
Low None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-71123 Oracle Hyperion Financial Management Security HTTP Yes 5.4 Network Low None Required Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-70759 Oracle Hyperion Financial Reporting Server HTTP Yes 5.4 Network Low None Required Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-70766 Oracle Hyperion Financial Reporting Server HTTP Yes 5.4 Network Low None Required Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-61342 Oracle Hyperion Calculation Manager Security HTTP Yes 5.3 Network High None Required Un-
changed
High None None 11.2.25.0.000  
CVE-2026-62446 Oracle Hyperion Calculation Manager Security HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70679 Oracle Hyperion Calculation Manager Security HTTP Yes 5.3 Network Low None None Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-70911 Oracle Hyperion Financial Management Security HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70974 Oracle Hyperion Financial Management Security HTTP No 5.3 Network High Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71108 Oracle Hyperion Financial Management Security HTTP No 5.3 Network High Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71120 Oracle Hyperion Financial Management Security HTTP No 5.3 Network High Low None Un-
changed
None None High 11.2.25.0.000  
CVE-2026-71148 Oracle Hyperion Financial Management Security HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70912 Oracle Hyperion Financial Management Security None No 5.3 Local High Low Required Changed None High None 11.2.25.0.000  
CVE-2026-70754 Oracle Hyperion Financial Reporting Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70758 Oracle Hyperion Financial Reporting Server None No 5.3 Local High Low None Un-
changed
Low High None 11.2.25.0.000  
CVE-2026-70784 Oracle Hyperion Financial Reporting Server None No 5.3 Local High Low None Un-
changed
Low High None 11.2.25.0.000  
CVE-2026-62509 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62510 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62566 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62579 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62460 Oracle Hyperion Calculation Manager Security HTTP No 5.0 Network Low Low None Changed Low None None 11.2.25.0.000  
CVE-2026-71085 Oracle Hyperion Financial Management Security HTTP No 4.9 Network Low High None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71118 Oracle Hyperion Financial Management Security HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62520 Oracle Hyperion Infrastructure Technology Common Events HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2021-31805 Oracle Hyperion Infrastructure Technology Common Events (Apache Struts 1) HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-71105 Oracle Hyperion Financial Management Security None No 4.7 Local High Low None Un-
changed
None None High 11.2.25.0.000  
CVE-2026-70794 Oracle Hyperion Financial Reporting Server None No 4.7 Local High Low None Un-
changed
None High None 11.2.25.0.000  
CVE-2026-62575 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 4.7 Local High Low None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71060 Oracle Hyperion Financial Management Security HTTP No 4.4 Network High High None Un-
changed
High None None 11.2.25.0.000  
CVE-2026-71145 Oracle Hyperion Financial Management Security HTTP No 4.4 Network High Low Required Changed Low Low None 11.2.25.0.000  
CVE-2026-70683 Oracle Hyperion Calculation Manager Security HTTP Yes 4.3 Network Low None Required Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-71147 Oracle Hyperion Financial Management Security HTTP Yes 4.2 Network High None Required Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-71149 Oracle Hyperion Financial Management Security None No 4.2 Local High Low Required Un-
changed
Low Low Low 11.2.25.0.000  
CVE-2026-70793 Oracle Hyperion Financial Reporting Server HTTP No 4.2 Network High Low None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-70963 Oracle Hyperion Infrastructure Technology Installation and Configuration HTTP No 4.2 Network High Low None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-70714 Oracle Hyperion Calculation Manager Security None No 4.1 Local High High None Un-
changed
None High None 11.2.25.0.000  
CVE-2021-4104 Oracle Hyperion Infrastructure Technology Common Events (Apache Log4j) HTTP No 4.1 Network High High None Un-
changed
Low Low Low 11.2.25.0.000  
CVE-2026-70719 Oracle Hyperion Calculation Manager Security None No 4.0 Local Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70916 Oracle Hyperion Financial Management Security None No 4.0 Local Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70917 Oracle Hyperion Financial Management Security None No 4.0 Local Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62584 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 4.0 Local Low None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62532 Oracle Hyperion Calculation Manager Security SQL No 3.8 Network Low High None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62533 Oracle Hyperion Calculation Manager Security HTTP Yes 3.7 Network High None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70682 Oracle Hyperion Calculation Manager Security HTTP Yes 3.7 Network High None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70848 Oracle Hyperion Financial Management Security HTTP Yes 3.7 Network High None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70785 Oracle Hyperion Financial Reporting Server HTTP Yes 3.7 Network High None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70711 Oracle Hyperion Calculation Manager Security None No 3.6 Local High None Required Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62529 Oracle Hyperion Calculation Manager Security HTTP No 3.5 Network Low Low Required Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-62569 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.4 Local Low High None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-70853 Oracle Hyperion Financial Management Security HTTP No 3.3 Network High High None Un-
changed
Low None Low 11.2.25.0.000  
CVE-2026-62526 Oracle Hyperion Infrastructure Technology Common Security HTTP No 3.3 Network High High None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-62577 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.3 Local Low Low None Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-70962 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.3 Local Low Low None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62461 Oracle Hyperion Calculation Manager Security HTTP Yes 3.1 Network High None Required Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62606 Oracle Hyperion Calculation Manager Security HTTP No 3.1 Network High Low None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-62604 Oracle Hyperion Calculation Manager Security HTTPS Yes 3.1 Adjacent
Network
High None None Un-
changed
Low None None 11.2.25.0.000  
CVE-2026-70851 Oracle Hyperion Financial Management Security HTTP No 3.1 Network High Low None Un-
changed
None None Low 11.2.25.0.000  
CVE-2026-70850 Oracle Hyperion Financial Management Security None No 3.0 Local High High None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-71144 Oracle Hyperion Financial Management Security None No 3.0 Local High High None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62511 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.0 Local High High None Un-
changed
Low Low None 11.2.25.0.000  
CVE-2026-62570 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.0 Local High High None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-62583 Oracle Hyperion Infrastructure Technology Installation and Configuration None No 3.0 Local High High None Un-
changed
None Low Low 11.2.25.0.000  
CVE-2026-62580 Oracle Hyperion Calculation Manager Security HTTP No 2.6 Adjacent
Network
High Low None Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-70776 Oracle Hyperion Financial Reporting Server HTTP No 2.6 Network High Low Required Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-70919 Oracle Hyperion Financial Management Security None No 2.5 Local High None Required Un-
changed
None Low None 11.2.25.0.000  
CVE-2026-71146 Oracle Hyperion Financial Management Security None No 1.9 Local High High None Un-
changed
None None Low 11.2.25.0.000  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle Java SE Risk Matrix

This Critical Security Patch Update contains 5 new security patches for Oracle Java SE.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

The CVSS scores below assume that a user running a Java applet or Java Web Start application has administrator privileges (typical on Windows). When the user does not run with administrator privileges (typical on Solaris and Linux), the corresponding CVSS impact scores for Confidentiality, Integrity, and Availability are "Low" instead of "High", lowering the CVSS Base Score. For example, a Base Score of 9.6 becomes 7.1.

Java Management Service, available to all users, can help you find vulnerable Java versions in your systems. Java SE Subscribers and customers running in Oracle Cloud can use Java Management Service to update Java Runtimes and to do further security reviews like identifying potentially vulnerable third party libraries used by your Java programs. Existing Java Management Service user click here to log in to your dashboard. The Java Management Service Documentation provides a list of features available to everyone and those available only to customers. Learn more about using Java Management Service to monitor and secure your Java Installations.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-62574 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Install None No 7.8 Local Low Low None Un-
changed
High High High Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 See Note 1
CVE-2026-70906 Oracle Java SE 2D Multiple Yes 7.5 Network Low None None Un-
changed
None None High Oracle Java SE: 25.0.4, 26.0.2 See Note 1
CVE-2026-61308 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Networking HTTP Yes 6.8 Network High None None Changed High None None Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 See Note 1
CVE-2026-70907 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition JSSE TLS Yes 5.3 Network Low None None Un-
changed
None None Low Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 See Note 2
CVE-2026-60589 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Security Multiple Yes 3.7 Network High None None Un-
changed
Low None None Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 See Note 2

Notes:

  1. This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security.
  2. This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service.


 

Oracle JD Edwards Risk Matrix

This Critical Security Patch Update contains 6 new security patches for Oracle JD Edwards.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61272 JD Edwards EnterpriseOne Tools Web Runtime SEC HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.4  
CVE-2026-61273 JD Edwards EnterpriseOne Tools Installation Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2.0.0-9.2.26.4  
CVE-2026-61270 JD Edwards EnterpriseOne Orchestrator E1 IOT Orchestrator Security HTTP No 8.1 Network Low Low None Un-
changed
High High None 9.2.0.0-9.2.26.4  
CVE-2026-61265 JD Edwards EnterpriseOne Orchestrator E1 IOT Orchestrator Security TLS Yes 8.1 Network High None None Un-
changed
High High High 9.2.0.0-9.2.26.4  
CVE-2026-61268 JD Edwards EnterpriseOne Tools Business Logic Infra SEC HTTP No 8.1 Network Low Low None Un-
changed
High High None 9.2.0.0-9.2.26.4  
CVE-2026-60956 JD Edwards EnterpriseOne US Payroll Payroll JDENET No 7.5 Network High Low None Un-
changed
High High High 9.2  

 

Oracle MySQL Risk Matrix

This Critical Security Patch Update contains 9 new security patches for Oracle MySQL.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60592 MySQL Cluster Cluster: NDB Operator MySQL Protocol Yes 8.2 Network Low None None Un-
changed
None Low High 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2025-14821 MySQL Cluster Cluster: General (libssh) None No 7.8 Local Low Low None Un-
changed
High High High 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-70724 MySQL Cluster Cluster: General HTTP Yes 7.5 Network High None Required Un-
changed
High High High 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2  
CVE-2025-13151 MySQL Cluster Cluster: General (Libtasn1) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-65914 MySQL AI AI: Console (DOMPurify) HTTP Yes 7.2 Network Low None None Changed Low Low None 9.4.0-9.7.2, 26.7.0  
CVE-2026-71084 MySQL Connectors Connector/ODBC None No 6.8 Local Low None None Un-
changed
Low None High 26.7.0  
CVE-2026-71079 MySQL Connectors Connector/ODBC MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High 26.7.0  
CVE-2026-0968 MySQL Shell Shell: Core Client (libssh) MySQL Protocol Yes 5.9 Network High None None Un-
changed
None High None 26.7.0  
CVE-2026-71073 MySQL Connectors Connector/ODBC None No 5.5 Local Low None Required Un-
changed
None None High 26.7.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-65914 also addresses CVE-2026-0540, CVE-2026-41238, CVE-2026-41239, CVE-2026-41240, CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, CVE-2026-65898, CVE-2026-65899, CVE-2026-65900, CVE-2026-65901, CVE-2026-65902, CVE-2026-65903, CVE-2026-65912, and CVE-2026-65913.
  • The patch for CVE-2026-0968 also addresses CVE-2025-14821, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, and CVE-2026-0967.
  • The patch for CVE-2025-14821 also addresses CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, and CVE-2026-0968.

 

Oracle PeopleSoft Risk Matrix

This Critical Security Patch Update contains 15 new security patches for Oracle PeopleSoft.  7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60821 PeopleSoft Enterprise PeopleTools Business Interlink HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.61-8.63  
CVE-2026-60967 PeopleSoft Enterprise PeopleTools nVision HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 8.61-8.63  
CVE-2026-60879 PeopleSoft Enterprise PeopleTools Configuration Manager SQL No 8.8 Network Low Low None Un-
changed
High High High 8.61-8.63  
CVE-2026-61307 PeopleSoft Enterprise CC Common Application Objects Common Application Objects Oracle Net Yes 8.1 Network High None None Un-
changed
High High High 9.2  
CVE-2026-71112 PeopleSoft Enterprise FIN Common Objects Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 9.2  
CVE-2026-60831 PeopleSoft Enterprise PeopleTools Integration Broker HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.61-8.63  
CVE-2026-60742 PeopleSoft Enterprise PeopleTools PIA Core Technology HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.61-8.63  
CVE-2026-71092 PeopleSoft Enterprise FIN Lease Administration Lease Administration None No 7.5 Local High Low None Changed High High None 9.2  
CVE-2026-60975 PeopleSoft Enterprise PeopleTools Security None No 7.5 Local High Low None Changed High High None 8.61, 8.62  
CVE-2026-60856 PeopleSoft Enterprise PeopleTools Install and Packaging HTTP Yes 7.4 Network High None None Un-
changed
High High None 8.61-8.63  
CVE-2026-70861 PeopleSoft Enterprise FIN Common Objects Brazil Common Objects T3, IIOP No 7.2 Network Low High None Un-
changed
High High High 9.1  
CVE-2026-60883 PeopleSoft Enterprise PeopleTools PeopleCode HTTP No 7.2 Network Low High None Un-
changed
High High High 8.61-8.63  
CVE-2026-60873 PeopleSoft Enterprise PeopleTools Data Mover None No 7.2 Local High High Required Changed High High Low 8.61-8.63  
CVE-2026-60902 PeopleSoft Enterprise PeopleTools Tuxedo None No 7.0 Local High Low None Un-
changed
High High High 8.61-8.63  
CVE-2026-60884 PeopleSoft Enterprise PeopleTools Panel Processor HTTP No 4.4 Network High Low Required Changed Low Low None 8.61-8.63  

 

Oracle Retail Applications Risk Matrix

This Critical Security Patch Update contains 5 new security patches for Oracle Retail Applications.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-34481 Oracle Retail Advanced Inventory Planning Operations & Maintenance (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0, 16.0  
CVE-2026-34481 Oracle Retail Assortment Planning Application Core (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0, 16.0  
CVE-2026-34481 Oracle Retail Fiscal Management NF Issuing (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 14.2  
CVE-2026-34481 Oracle Retail Item Planning Application Core (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0, 16.0  
CVE-2026-34481 Oracle Retail Regular Price Optimization Operations & Maintenance (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0, 16.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle Siebel CRM Risk Matrix

This Critical Security Patch Update contains 50 new security patches for Oracle Siebel CRM.  21 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61317 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 9.9 Network Low Low None Changed High High High 22.3-26.6  
CVE-2026-62452 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 9.9 Network Low None None Changed High Low Low 22.3-26.6  
CVE-2026-62512 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 9.9 Network Low Low None Changed High High High 22.3-26.6  
CVE-2026-62588 Siebel CRM Integration Open Integration HTTP No 9.9 Network Low Low None Changed High High High 25.12-26.6  
CVE-2026-62585 Siebel CRM Administration Data Archival HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.12-26.6  
CVE-2026-61318 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 9.8 Network Low None None Un-
changed
High High High 22.3-26.6  
CVE-2026-62592 Siebel CRM Integration Open Integration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.12-26.6  
CVE-2026-70855 Siebel Apps - Self Service Helpdesk/Training HTTP Yes 9.3 Network Low None Required Changed High High None 17.0-26.6  
CVE-2026-60754 Siebel Apps - Marketing Marketing HTTP Yes 9.1 Network Low None None Un-
changed
High None High 17.0-26.6  
CVE-2026-60751 Siebel Apps - Marketing Marketing HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-60767 Siebel Apps - Marketing Marketing HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-61330 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 22.3-26.6  
CVE-2026-61341 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 22.3-26.6  
CVE-2026-70949 Siebel CRM Deployment Server Infrastructure HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-70951 Siebel CRM End User Document Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-61332 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.7 Network Low High None Changed High High None 22.3-26.6  
CVE-2026-62589 Siebel CRM Integration Open Integration HTTP Yes 8.7 Network High None None Changed High High None 25.12-26.6  
CVE-2026-62586 Siebel CRM Administration Data Archival HTTP Yes 8.6 Network Low None None Changed High None None 25.12-26.6  
CVE-2026-60758 Siebel Artificial Intelligence AI HTTP No 8.5 Network Low Low None Changed High Low None 25.12-26.6  
CVE-2026-61326 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.5 Network Low Low None Changed High Low None 22.3-26.6  
CVE-2026-60798 Siebel CRM Deployment Migration HTTP No 8.5 Network Low Low None Changed High Low None 17.0-26.6  
CVE-2026-62590 Siebel CRM Integration Open Integration HTTP No 8.5 Network High Low None Changed High High High 25.12-26.6  
CVE-2026-62596 Siebel CRM Integration Open Integration HTTP No 8.5 Network Low Low None Changed High Low None 25.12-26.6  
CVE-2026-70859 Siebel CRM Integration REST HTTP No 8.5 Network High Low None Changed High High High 17.0-26.6  
CVE-2026-62455 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.3 Network Low Low None Un-
changed
Low High High 22.3-26.6  
CVE-2026-60796 Siebel CRM Integration REST HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 17.0-26.6  
CVE-2026-60779 Siebel Apps - Marketing Marketing HTTP No 8.1 Network Low Low None Un-
changed
None High High 17.0-26.6  
CVE-2026-61321 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.1 Network Low Low None Un-
changed
High High None 22.3-26.6  
CVE-2026-62442 Siebel CRM Cloud Applications Siebel Cloud Manager HTTPS Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 22.3-26.6  
CVE-2026-60791 Siebel CRM Deployment Application Interface TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 17.0-26.6  
CVE-2026-60757 Siebel CRM End User Search TLS Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 17.0-26.6  
CVE-2026-62591 Siebel CRM Integration Open Integration HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 25.12-26.6  
CVE-2026-62595 Siebel CRM Integration Open Integration TLS Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 25.12-26.6  
CVE-2026-62454 Siebel CRM Cloud Applications Siebel Cloud Manager None No 7.8 Local Low Low None Un-
changed
High High High 22.3-26.6  
CVE-2026-60753 Siebel CRM Deployment Installation None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-70857 Siebel CRM End User Open UI HTTPS No 7.7 Network High Low Required Changed High High None 17.0-26.6  
CVE-2026-62593 Siebel CRM Integration Open Integration HTTP No 7.7 Network Low Low None Changed High None None 25.12-26.6  
CVE-2026-62594 Siebel CRM Integration Open Integration HTTP No 7.7 Network High High None Changed None High High 25.12-26.6  
CVE-2026-60765 Siebel Apps - Marketing Marketing HTTP No 7.5 Network High Low None Un-
changed
High High High 17.0-26.6  
CVE-2026-60808 Siebel Apps - Marketing Email Marketing None No 7.5 Local High Low None Changed High High None 17.0-26.6  
CVE-2026-70856 Siebel CRM Deployment Migration HTTP Yes 7.5 Network High None Required Un-
changed
High High High 17.0-26.6  
CVE-2026-70910 Siebel CRM Integration REST HTTP Yes 7.5 Network Low None None Un-
changed
High None None 17.0-26.6  
CVE-2026-60803 Siebel Apps - Marketing Marketing HTTP Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.6  
CVE-2026-60792 Siebel CRM Deployment Server Infrastructure HTTP Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.6  
CVE-2026-60820 Siebel CRM Integration REST HTTP Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.6  
CVE-2026-60766 Siebel CRM Integration REST HTTPS Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.6  
CVE-2026-60797 Siebel CRM Integration REST HTTPS Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.6  
CVE-2026-61339 Siebel CRM Cloud Applications Siebel Cloud Manager None No 7.3 Local Low Low None Changed High Low None 22.3-26.6  
CVE-2026-60752 Siebel Apps - Marketing Marketing HTTP No 7.1 Network Low Low None Un-
changed
High None Low 17.0-26.6  
CVE-2026-62587 Siebel CRM Administration Data Archival HTTP No 7.1 Network Low Low None Un-
changed
High Low None 25.12-26.6  

 

Oracle Supply Chain Risk Matrix

This Critical Security Patch Update contains 46 new security patches for Oracle Supply Chain.  18 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71040 Oracle Agile PLM Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.3.6  
CVE-2024-10095 Oracle Agile PLM MCAD Connector CAX Client (Telerik UI for WPF) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 3.6  
CVE-2022-37434 Oracle Agile PLM MCAD Connector CAX Client (zlib) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 3.6  
CVE-2026-70846 Oracle Demand Planning Internal Operations HTTP No 9.6 Network Low Low None Changed High High None 12.1, 12.2  
CVE-2026-71052 Oracle Agile Engineering Data Management Web Services Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 6.2.1  
CVE-2026-71039 Oracle Agile PLM Application Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.3.6  
CVE-2026-71044 Oracle Agile PLM Export HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.3.6  
CVE-2026-71045 Oracle Agile PLM Security HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 9.3.6  
CVE-2026-71046 Oracle Agile PLM Security None No 8.8 Local Low Low None Changed High High High 9.3.6  
CVE-2026-71067 Oracle Agile PLM MCAD Connector CAX Client HTTP No 8.8 Network Low Low None Un-
changed
High High High 3.6  
CVE-2026-71051 Oracle Product Lifecycle Analytics Installation Issues None No 8.8 Local Low Low None Changed High High High 3.6.1  
CVE-2026-71050 Oracle Product Lifecycle Analytics Installation Issues Oracle Net No 8.7 Network Low High None Changed High High None 3.6.1  
CVE-2026-71049 Oracle Product Lifecycle Analytics Installation Issues Oracle Net No 8.5 Network Low Low None Changed High Low None 3.6.1  
CVE-2026-70703 Oracle Agile Engineering Data Management Engineering Communication Interface HTTP No 8.2 Network High Low None Changed High High None 6.2.1  
CVE-2026-70852 Oracle Demand Planning Internal Operations HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.1, 12.2  
CVE-2026-71053 Oracle Agile Engineering Data Management Web Services Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 6.2.1  
CVE-2026-71042 Oracle Agile PLM PGC / Excel Plugin HTTP No 8.1 Network Low Low None Un-
changed
None High High 9.3.6  
CVE-2026-71068 Oracle Agile PLM MCAD Connector CAX Client HTTP Yes 8.1 Network High None None Un-
changed
High High High 3.6  
CVE-2026-71048 Oracle Product Lifecycle Analytics Installation Issues HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 3.6.1  
CVE-2026-70691 Oracle Agile Engineering Data Management Engineering Communication Interface Multiple Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High 6.2.1  
CVE-2026-71043 Oracle Agile PLM Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.3.6  
CVE-2026-71069 Oracle Agile PLM MCAD Connector CAX Client HTTP No 7.5 Network High Low None Un-
changed
High High High 3.6  
CVE-2026-34481 Oracle Agile PLM MCAD Connector CAX Client (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 3.6  
CVE-2022-40152 Oracle Agile PLM MCAD Connector CAX Client (Jackson dataformat XML) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.6  
CVE-2022-40150 Oracle Agile PLM MCAD Connector CAX Client (Jettison) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 3.6  
CVE-2026-70697 Oracle Agile Engineering Data Management Engineering Communication Interface None No 7.0 Local High Low None Un-
changed
High High High 6.2.1  
CVE-2026-71041 Oracle Agile PLM Gantt Chart None No 7.0 Local High Low None Un-
changed
High High High 9.3.6  
CVE-2026-70698 Oracle Agile Engineering Data Management Install None No 6.7 Local Low High None Un-
changed
High High High 6.2.1  
CVE-2026-71070 Oracle Agile PLM MCAD Connector CAX Client HTTP No 6.5 Network Low Low None Un-
changed
High None None 3.6  
CVE-2026-70712 Oracle Agile Engineering Data Management Install None No 6.4 Local High High None Un-
changed
High High High 6.2.1  
CVE-2026-70693 Oracle Agile Engineering Data Management Engineering Communication Interface None No 6.3 Local High High Required Un-
changed
High High High 6.2.1  
CVE-2026-71075 Oracle Agile PLM MCAD Connector CAX Client TLS Yes 5.9 Adjacent
Network
High None None Un-
changed
High Low None 3.6  
CVE-2026-71076 Oracle Agile PLM MCAD Connector CAX Client HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.6  
CVE-2026-71087 Oracle Agile PLM MCAD Connector CAX Client HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 3.6  
CVE-2026-71077 Oracle Agile PLM MCAD Connector CAX Client HTTPS Yes 5.3 Adjacent
Network
High None None Un-
changed
High None None 3.6  
CVE-2026-70709 Oracle Agile Engineering Data Management Engineering Communication Interface HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 6.2.1  
CVE-2026-71088 Oracle Agile PLM MCAD Connector CAX Client HTTP No 4.8 Network High Low Required Un-
changed
High None None 3.6  
CVE-2026-71071 Oracle Agile PLM MCAD Connector CAX Client HTTP No 4.6 Adjacent
Network
Low Low None Un-
changed
Low Low None 3.6  
CVE-2026-71066 Oracle Agile PLM MCAD Connector CAX Client None No 4.5 Local High None Required Un-
changed
Low Low Low 3.6  
CVE-2026-71078 Oracle Agile PLM MCAD Connector CAX Client None No 4.2 Local High Low Required Un-
changed
Low Low Low 3.6  
CVE-2026-71080 Oracle Agile PLM MCAD Connector CAX Client HTTP Yes 3.7 Adjacent
Network
High None Required Un-
changed
Low Low None 3.6  
CVE-2026-71072 Oracle Agile PLM MCAD Connector CAX Client None No 3.3 Local Low Low None Un-
changed
None None Low 3.6  
CVE-2026-71089 Oracle Agile PLM MCAD Connector CAX Client None No 3.3 Local Low None Required Un-
changed
Low None None 3.6  
CVE-2026-71082 Oracle Agile PLM MCAD Connector CAX Client None No 2.5 Local High Low None Un-
changed
Low None None 3.6  
CVE-2026-71081 Oracle Agile PLM MCAD Connector CAX Client None No 1.9 Local High High None Un-
changed
None Low None 3.6  
CVE-2026-71083 Oracle Agile PLM MCAD Connector CAX Client None No 1.8 Local High High Required Un-
changed
Low None None 3.6  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2024-10095 also addresses CVE-2024-7575.

 

Oracle Virtualization Risk Matrix

This Critical Security Patch Update contains 21 new security patches for Oracle Virtualization.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-71131 Oracle VM VirtualBox Core None No 8.6 Local Low None Required Changed High High High 7.2.14  
CVE-2026-71129 Oracle VM VirtualBox Core None No 8.2 Local Low High None Changed High High High 7.2.14  
CVE-2026-71130 Oracle VM VirtualBox Core RDP Yes 8.2 Network Low None None Un-
changed
High Low None 7.2.14  
CVE-2026-71126 Oracle VM VirtualBox Core None No 7.8 Local High Low None Changed High High High 7.2.14  
CVE-2026-71141 Oracle VM VirtualBox Core None No 7.7 Local Low None Required Changed Low High Low 7.2.14  
CVE-2026-71116 Oracle VM VirtualBox Core None No 7.5 Local High High None Changed High High High 7.2.14  
CVE-2026-71113 Oracle VM VirtualBox Core RDP Yes 7.5 Network Low None None Un-
changed
None None High 7.2.14  
CVE-2026-71136 Oracle VM VirtualBox Core None No 7.3 Local Low High None Changed Low Low High 7.2.14  
CVE-2026-71138 Oracle VM VirtualBox Core None No 7.3 Local Low High None Changed Low Low High 7.2.14  
CVE-2026-71125 Oracle VM VirtualBox Core None No 6.1 Local Low None Required Un-
changed
None Low High 7.2.14  
CVE-2026-71114 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed High None None 7.2.14  
CVE-2026-71115 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed High None None 7.2.14  
CVE-2026-71127 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.14  
CVE-2026-71128 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.14  
CVE-2026-71135 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.14  
CVE-2026-71137 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.14  
CVE-2026-71134 Oracle VM VirtualBox Core None No 5.7 Local Low High None Changed Low Low Low 7.2.14  
CVE-2026-71151 Oracle VM VirtualBox Core None No 5.6 Local High Low None Changed High None None 7.2.14  
CVE-2026-71132 Oracle VM VirtualBox Core None No 5.3 Local High High None Changed High None None 7.2.14  
CVE-2026-71139 Oracle VM VirtualBox Core None No 4.4 Local Low High None Un-
changed
None None High 7.2.14  
CVE-2026-71140 Oracle VM VirtualBox Core None No 3.4 Local Low High None Un-
changed
Low Low None 7.2.14