A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.
Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.
This Critical Security Patch Update contains 943 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at August 2026 Critical Security Patch Update: Executive Summary and Analysis.
Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.
Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.
Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.
Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.
Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).
Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.
Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.
The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible. Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.
Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Security Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.
Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.
Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.
The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:
Oracle acknowledges people who have contributed to our Security-In-Depth program (see FAQ). People are acknowledged for Security-In-Depth contributions if they provide information, observations or suggestions pertaining to security vulnerability issues that result in significant modification of Oracle code or documentation in future releases, but are not of such a critical nature that they are distributed in Critical Security Patch Updates.
In this Critical Security Patch Update, Oracle recognizes the following for contributions to Oracle's Security-In-Depth program:
Security patches are released on the third Tuesday of each month. The next four dates are:
| Date | Note |
|---|---|
| 2026-August-18 | Rev 1. Initial Release. |
This Critical Security Patch Update contains 17 new security patches for Oracle Database Products divided as follows:
This Critical Security Patch Update contains 6 new security patches, plus additional third party patches noted below, for Oracle Database Products. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.
| CVE ID | Component | Package and/or Privilege Required | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71063 | Portable Clusterware | None | TLS | Yes | 9.6 | Adjacent Network |
Low | None | None | Changed | High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-71064 | Portable Clusterware | None | TLS | Yes | 9.6 | Adjacent Network |
Low | None | None | Changed | High | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-71102 | Portable Clusterware | None | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-71062 | RDBMS | Authenticated User | Oracle Net | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 23.4.0-23.26.3 | |
| CVE-2026-59889 | Fleet Patching and Provisioning (jackson-databind) | None | TLS | No | 8.1 | Network | Low | Low | None | Un- changed |
High | None | High | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
| CVE-2026-71100 | RDBMS | None | Oracle Net | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 19.3-19.32, 21.3-21.23, 23.4.0-23.26.3 | |
This Critical Security Patch Update contains 7 new security patches, plus additional third party patches noted below, for Oracle Autonomous Health Framework. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-70715 | Oracle Autonomous Health Framework | Trace File Analyzer | TLS | Yes | 8.8 | Adjacent Network |
Low | None | None | Un- changed |
High | High | High | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-70728 | Oracle Autonomous Health Framework | Trace File Analyzer | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-70731 | Oracle Autonomous Health Framework | Trace File Analyzer | None | No | 8.4 | Local | Low | Low | None | Changed | None | High | High | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-70717 | Oracle Autonomous Health Framework | Cluster Health Analyzer | TLS | No | 7.7 | Adjacent Network |
High | Low | None | Changed | High | High | None | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-42764 | Oracle Autonomous Health Framework | AHFCOMMON (pyca-cryptography) | TLS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-70734 | Oracle Autonomous Health Framework | Trace File Analyzer | None | No | 7.4 | Local | Low | High | Required | Changed | None | High | High | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
| CVE-2026-9563 | Oracle Autonomous Health Framework | Trace File Analyzer (Eclipse Parsson) | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
None | None | High | 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2 | |
This Critical Security Patch Update contains 4 new security patches for Oracle Essbase. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-29167 | Oracle Essbase | Essbase Web Platform (Apache HTTP Server) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 21.8.1.0.0 | |
| CVE-2026-70689 | Oracle Essbase | Infrastructure | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 21.8.1.0.0 | |
| CVE-2026-70688 | Oracle Essbase | Calculator | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 21.8.1.0.0 | |
| CVE-2026-45447 | Oracle Essbase | Essbase Web Platform (OpenSSL) | TLS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 21.8.1.0.0 | |
This Critical Security Patch Update contains 7 new security patches for Oracle Application Testing Suite. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Component | Package and/or Privilege Required | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-70862 | Oracle Application Testing Suite | Test Manager for Web Apps | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 13.3.0.1 | |
| CVE-2026-70863 | Oracle Application Testing Suite | Load Testing for Web Apps | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 13.3.0.1 | |
| CVE-2026-70868 | Oracle Application Testing Suite | Load Testing for Web Apps | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 13.3.0.1 | |
| CVE-2026-70866 | Oracle Application Testing Suite | Load Testing for Web Apps | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 13.3.0.1 | |
| CVE-2026-70864 | Oracle Application Testing Suite | Load Testing for Web Apps | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 13.3.0.1 | |
| CVE-2026-70865 | Oracle Application Testing Suite | Load Testing for Web Apps | HTTPS | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 13.3.0.1 | |
| CVE-2026-70867 | Oracle Application Testing Suite | Load Testing for Web Apps | TLS | Yes | 7.1 | Adjacent Network |
Low | None | None | Un- changed |
High | Low | None | 13.3.0.1 | |
This Critical Security Patch Update contains 66 new security patches for Oracle Commerce. 47 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-70995 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-70954 | Oracle Commerce Platform | Dynamo Application Framework | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-70953 | Oracle Commerce Platform | Dynamo Application Framework | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-70998 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.3 | Network | Low | None | None | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71037 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 9.3 | Network | Low | None | Required | Changed | High | High | None | 11.4.0 | |
| CVE-2026-70976 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-70977 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-70978 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-70979 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-70981 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-70984 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.4.0 | |
| CVE-2026-70994 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 11.4.0 | |
| CVE-2026-71014 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-71015 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-71026 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-70997 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 11.4.0 | |
| CVE-2026-71036 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-70980 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 9.0 | Network | High | None | None | Changed | High | High | High | 11.4.0 | |
| CVE-2026-71000 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 11.4.0 | |
| CVE-2026-70996 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71002 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 8.5 | Network | Low | Low | None | Changed | Low | High | None | 11.4.0 | |
| CVE-2026-70993 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | Low | High | 11.4.0 | |
| CVE-2026-71016 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71018 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71024 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-70999 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-71035 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-71028 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-71010 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-70988 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71020 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71021 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71027 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-71022 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Workbench | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.4.0 | |
| CVE-2026-70985 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-70986 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-70987 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-71023 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 11.4.0 | |
| CVE-2026-71038 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2022-23437 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | MDEX (dom4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2024-9143 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge (OpenSSL) | HTTPS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 11.4.0 | |
| CVE-2026-71034 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Forge | SOAP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-70955 | Oracle Commerce Platform | Dynamo Application Framework | TCP | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-71009 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.4.0 | |
| CVE-2026-71030 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71032 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71003 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-71012 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-70992 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 11.4.0 | |
| CVE-2026-70982 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 6.8 | Network | High | None | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-70983 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 6.8 | Network | High | None | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-70990 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | HTTP | Yes | 6.8 | Network | High | None | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71007 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 6.8 | Network | Low | High | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71008 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 6.8 | Network | Low | High | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71017 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 6.5 | Network | High | None | None | Un- changed |
High | None | Low | 11.4.0 | |
| CVE-2026-71001 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.4.0 | |
| CVE-2026-70989 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | None | No | 6.5 | Local | Low | Low | None | Changed | High | None | None | 11.4.0 | |
| CVE-2026-70991 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Content Acquisition System | None | No | 6.3 | Local | Low | None | Required | Changed | High | None | None | 11.4.0 | |
| CVE-2026-71025 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71031 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71004 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71005 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71006 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71011 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Experience Manager | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71019 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Internal operations | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.4.0 | |
| CVE-2026-71033 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Endeca Application Controller | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 11.4.0 | |
This Critical Security Patch Update contains 13 new security patches, plus additional third party patches noted below, for Oracle Communications. 9 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-42779 | Management Cloud Engine | Security (Apache Mina) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 25.2.0.0.10 | |
| CVE-2026-4800 | Oracle Communications Unified Assurance | Core (Lodash) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-42587 | Oracle Communications ASAP | Security (Netty) | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.4.1, 8.0.0 | |
| CVE-2025-13151 | Oracle Communications Unified Assurance | Core (Libtasn1) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 6.1.1-7.0.0 | |
| CVE-2026-71142 | Oracle Communications Unified Inventory Management | Security Component | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.1 | |
| CVE-2025-13151 | Oracle Communications Unified Inventory Management | Security Component (Libtasn1) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.1 | |
| CVE-2026-5795 | Oracle Communications Unified Assurance | Core (Eclipse Jetty) | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
| CVE-2026-71143 | Oracle Communications Unified Inventory Management | Third Party | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 7.5.0, 7.5.1, 7.6.0-7.8.0, 8.0.1 | |
| CVE-2026-59084 | Oracle Communications Unified Assurance | Core (Apache Tomcat) | HTTP | No | 7.3 | Network | Low | Low | Required | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
| CVE-2026-29167 | Oracle Communications Unified Assurance | Core (Apache HTTP Server) | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-42779 | Oracle Communications Unified Assurance | Core (Apache Mina) | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-4176 | Oracle Communications Unified Assurance | Core (Perl) | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-55956 | Management Cloud Engine | Security (Apache Tomcat) | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 25.2.0.0.10 | |
This Critical Security Patch Update contains 1 new security patch for Oracle Construction and Engineering. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-41240 | Primavera P6 Enterprise Project Portfolio Management | Web Access (DOMPurify) | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.3, 23.12.0.0-23.12.19.0, 24.12.0.0-24.12.15.0, 25.12.0.0-25.12.6.0 | |
This Critical Security Patch Update contains 120 new security patches for Oracle E-Business Suite. 27 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the August 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (August 2026), My Oracle Support Note KA923.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-60782 | Oracle Payments | File Transmission | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70926 | Oracle Workflow | Workflow Notification Mailer | SMTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70812 | Oracle Call Center Technology | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70813 | Oracle Call Center Technology | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70747 | Oracle Customers Online | Customer Tab | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-62450 | Oracle Flow Manufacturing | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70686 | Oracle General Ledger | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70941 | Oracle Payroll | Internal Operations | None | No | 8.8 | Local | Low | Low | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70918 | Oracle Product Hub | Outbound Data | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70948 | Oracle Purchasing | Other issue | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70761 | Oracle Risk Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70707 | Oracle Sales for Handhelds | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70710 | Oracle Sales Foundation | Security API | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-60976 | Oracle Scripting | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70729 | Oracle Teleservice | Service Request Form | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-61319 | Oracle U.S. Federal Financials | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-62462 | Oracle Work in Process | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70792 | Oracle Yard Management | Internal Operations | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-62607 | Oracle Customer Care | Internal Operations | HTTP | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70778 | Oracle Customer Care | Internal Operations | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-62599 | Oracle Trading Community | Third Party Data Integration | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70718 | Oracle Bills of Material | Internal Operations | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70807 | Oracle Call Center Technology | Internal Operations | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70770 | Oracle Warehouse Management | Internal Operations | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70722 | Oracle Advanced Inbound Telephony | Internal Operations | HTTPS | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-62448 | Oracle Email Center | Message Component | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70773 | Oracle HCM Common Architecture | Knowledge Integration | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-61340 | Oracle MES for Process Manufacturing | Internal Operations | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-62605 | Oracle Partner Management | Internal Operations | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70702 | Oracle Payments | File Transmission | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70795 | Oracle Applications Platform Engineering | Valid Session | Oracle Net | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70814 | Oracle Call Center Technology | Internal Operations | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70815 | Oracle Internet Procurement Connector | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70835 | Oracle iRecruitment | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70782 | Oracle Labor Distribution | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70701 | Oracle Payables | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70830 | Oracle Process Manufacturing Systems | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70805 | Oracle Project Planning and Control | Change Management | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70811 | Oracle Purchasing | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.5-12.2.15 | |
| CVE-2026-62491 | Oracle Purchasing | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70762 | Oracle Risk Management | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-62600 | Oracle Sales | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70708 | Oracle Sales Foundation | Security API | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70704 | Oracle Trading Community | Party Search UI | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70931 | Oracle Workflow | Workflow Notification Mailer | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70690 | Oracle HRMS (US) | US Payroll - General | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70802 | Oracle Public Sector Human Resources | Regression Testing | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-71101 | Oracle HRMS (US) | US Payroll Tax Issues | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70798 | Oracle Purchasing | Internal Operations | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-61331 | Oracle Financials Common Modules | Common Components | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70687 | Oracle Marketing | Audience | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70692 | Oracle Marketing Encyclopedia System | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70827 | Oracle MES for Process Manufacturing | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70694 | Oracle Payments | File Transmission | HTTP | No | 7.7 | Network | High | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70695 | Oracle Payments | File Transmission | HTTP | No | 7.7 | Network | High | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70945 | Oracle Payroll | Internal Operations | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70804 | Oracle Public Sector Human Resources | Regression Testing | HTTP | No | 7.7 | Network | High | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70771 | Oracle Warehouse Management | Internal Operations | HTTPS | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70725 | Oracle Advanced Inbound Telephony | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
High | Low | Low | 12.2.3-12.2.15 | |
| CVE-2026-61296 | Oracle Enterprise Asset Management | Linear Asset Management | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-60748 | Oracle General Ledger | Internal Operations | HTTP | No | 7.6 | Network | Low | High | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70764 | Oracle General Ledger | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
High | Low | Low | 12.2.3-12.2.15 | |
| CVE-2026-70803 | Oracle General Ledger | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
Low | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70786 | Oracle Service Fulfillment Manager | Fulfillment Engine | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70791 | Oracle Transportation Execution | Internal Operations | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70681 | Oracle Applications DBA | JRI and other Java utils | HTTP | Yes | 7.5 | Network | High | None | Required | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-60769 | Oracle General Ledger | Internal Operations | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70713 | Oracle iSetup | General Ledger Update Transform, Reports | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70777 | Oracle iSupplier Portal | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70763 | Oracle Operations Intelligence | Daily Business Intelligence | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70930 | Oracle Order Management | Product Diagnostic Tools | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70700 | Oracle Payables | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 12.2.3-12.2.15 | |
| CVE-2026-70696 | Oracle Payments | File Transmission | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70829 | Oracle Process Manufacturing Systems | Internal Operations | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70947 | Oracle Purchasing | Other issue | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70706 | Oracle Sales | Internal Operations | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70810 | Oracle Scripting | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70799 | Oracle SDP Number Portability | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70772 | Oracle Warehouse Management | Internal Operations | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70927 | Oracle Workflow | Workflow Notification Mailer | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 12.2.3-12.2.15 | |
| CVE-2026-60759 | Oracle Internet Procurement Connector | Internal Operations | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70779 | Oracle iSupplier Portal | Internal Operations | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70699 | Oracle Payments | File Transmission | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70783 | Oracle Service Contracts | Internal Operations | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70790 | Oracle Telecommunications Billing Integrator | Internal Operations | HTTP | Yes | 7.4 | Network | Low | None | Required | Changed | None | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70800 | Oracle SDP Number Portability | Internal Operations | None | No | 7.3 | Local | Low | High | None | Changed | Low | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70820 | Oracle Call Center Technology | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-62540 | Oracle Cost Management | Cost Planning | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70796 | Oracle General Ledger | Internal Operations | None | No | 7.2 | Local | High | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-71104 | Oracle HRMS (Netherlands) | Netherlands Payroll | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70932 | Oracle Order Management | Product Diagnostic Tools | None | No | 7.2 | Local | High | High | None | Changed | High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70781 | Oracle Proposals | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70797 | Oracle Purchasing | Internal Operations | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70680 | Oracle Applications DBA | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-61306 | Oracle Complex Maintenance, Repair and Overhaul | Production | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | None | Low | 12.2.3-12.2.15 | |
| CVE-2026-70806 | Oracle E-Business Tax | Internal Operations | None | No | 7.1 | Local | Low | Low | None | Un- changed |
None | High | High | 12.2.3-12.2.15 | |
| CVE-2026-70837 | Oracle Financials for Asia/Pacific | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
Low | High | None | 12.2.3-12.2.15 | |
| CVE-2026-70816 | Oracle Financials for EMEA | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70839 | Oracle Financials for EMEA | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70801 | Oracle Flow Manufacturing | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-60693 | Oracle General Ledger | Internal Operations | HTTP | No | 7.1 | Network | High | Low | None | Un- changed |
High | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70833 | Oracle Landed Cost Management | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70844 | Oracle Loans | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70845 | Oracle Loans | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
None | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70760 | Oracle Order Management | Product Diagnostic Tools | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-60781 | Oracle Payments | File Transmission | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-62601 | Oracle Sales | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70808 | Oracle Scripting | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70809 | Oracle Scripting | Internal Operations | HTTP | No | 7.1 | Network | High | Low | None | Un- changed |
High | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-70774 | Oracle Warehouse Management | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
None | High | Low | 12.2.3-12.2.15 | |
| CVE-2026-62458 | Oracle Work in Process | Internal Operations | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
None | Low | High | 12.2.3-12.2.15 | |
| CVE-2026-62449 | Oracle Work in Process | Internal Operations | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-62475 | Oracle Shipping Execution | Internal Operations | HTTP | No | 6.6 | Network | High | High | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-61198 | Oracle Learning Management | Internal Operations | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-70732 | Oracle Mobile Application Server | MWA Terminal Server | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70720 | Oracle Production Scheduling | Internal Operations | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-60830 | Oracle Workflow | Worklist | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-70775 | Oracle Installed Base | User Interface | HTTP | No | 6.3 | Network | Low | Low | None | Un- changed |
Low | Low | Low | 12.2.3-12.2.15 | |
| CVE-2026-61139 | Oracle Public Sector Financials (International) | Authorization | HTTP | No | 6.3 | Network | Low | Low | None | Un- changed |
Low | Low | Low | 12.2.3-12.2.15 | |
| CVE-2026-70726 | Oracle Cash Management | Internal Operations | None | No | 6.0 | Local | Low | High | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
This Critical Security Patch Update contains 11 new security patches for Oracle Enterprise Manager. 6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.
Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the August 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update August 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU329.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-2332 | Oracle Enterprise Manager Base Platform | API Gateway (Eclipse Jetty) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 24.1 | |
| CVE-2026-2332 | Oracle Enterprise Manager Base Platform | Agent Next Gen (Eclipse Jetty) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 13.5, 24.1 | |
| CVE-2026-2332 | Oracle Enterprise Manager Base Platform | Monitoring Service (Eclipse Jetty) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 13.5, 24.1 | |
| CVE-2026-61284 | Oracle Enterprise Manager Base Platform | Application Config Console | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-70737 | Oracle Enterprise Manager for Systems Infrastructure | Storage Server Management | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-61286 | Oracle Enterprise Manager Base Platform | Event Management | HTTP | Yes | 8.6 | Network | Low | None | None | Un- changed |
Low | High | Low | 13.5, 24.1 | |
| CVE-2026-70684 | Oracle Enterprise Manager Base Platform | Agent Next Gen | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-61300 | Oracle Enterprise Manager Base Platform | Agent Next Gen | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-60822 | Oracle Enterprise Manager for Systems Infrastructure | Agent | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 13.5, 24.1 | |
| CVE-2026-34481 | Enterprise Manager for MySQL Database | EM Plugin: General (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 13.5.1.0.0-13.5.6.0.0 | |
| CVE-2026-61298 | Oracle Enterprise Manager Base Platform | Enterprise Manager Install | None | No | 5.6 | Local | High | Low | None | Changed | High | None | None | 13.5, 24.1 | |
This Critical Security Patch Update contains 8 new security patches for Oracle Financial Services Applications. 6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-33557 | Oracle Financial Services Behavior Detection Platform | Third Party (Apache Kafka) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 8.0.8.1, 8.1.2.11 | |
| CVE-2026-33557 | Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition | User Interface (Apache Kafka) | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 8.0.8.0 | |
| CVE-2026-70922 | Oracle Financial Services Enterprise Case Management | Web UI | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.0.8.2, 8.1.2.11 | |
| CVE-2026-41855 | Oracle Financial Services Compliance Studio | Reports (Spring Framework) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 8.1.3.1 | |
| CVE-2026-34481 | Oracle Financial Services Behavior Detection Platform | Third Party (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 8.0.8.1, 8.1.2.11 | |
| CVE-2026-34481 | Oracle Financial Services Enterprise Case Management | ECM (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 8.0.8.2, 8.1.2.11 | |
| CVE-2026-34481 | Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition | User Interface (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 8.0.8.0 | |
| CVE-2026-33929 | Oracle Financial Services Enterprise Case Management | Web UI (Apache PDFBox) | HTTP | No | 4.3 | Network | Low | Low | None | Un- changed |
None | Low | None | 8.0.8.2, 8.1.2.11 | |
This Critical Security Patch Update contains 2 new security patches for Oracle Food and Beverage Applications. Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-60591 | Oracle Hospitality Simphony | POS | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1 | |
| CVE-2026-60590 | Oracle Hospitality Simphony | POS | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 19.8-19.8.5, 19.9-19.9.3, 19.10-19.10.1 | |
This Critical Security Patch Update contains 262 new security patches, plus additional third party patches noted below, for Oracle Fusion Middleware. 182 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-61241 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73930 | Helidon | Imperative Web Server | HTTP | Yes | 9.9 | Network | Low | None | None | Changed | Low | High | Low | 4.5.3 | |
| CVE-2026-60720 | Oracle Identity Manager | OIM Legacy UI | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61066 | Oracle Identity Manager | OIM Legacy UI | RMI | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60990 | Oracle Identity Manager Connector | Core | TLS | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60995 | Oracle Identity Manager Connector | Core | TLS | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61248 | Oracle Internet Directory | OID LDAP Server | LDAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61003 | Oracle Managed File Transfer | MFT Runtime Server | T3, IIOP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-62608 | Oracle Reports Developer | Security and Authentication | CORBA | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.19.0 | |
| CVE-2026-60916 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | Yes | 9.9 | Network | Low | None | None | Changed | Low | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60730 | Oracle WebCenter Portal | Composer | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61021 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60702 | Oracle WebLogic Server | Core | T3, IIOP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-71074 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 3.2.18 | |
| CVE-2026-71152 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 4.5.0 | |
| CVE-2026-71164 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 3.2.18 | |
| CVE-2026-73905 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 4.5.0 | |
| CVE-2026-73912 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 4.5.0 | |
| CVE-2026-73921 | Helidon | Imperative Web Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 1.4.20 | |
| CVE-2026-70905 | Oracle Access Manager | Agent infrastructure | SAML | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60721 | Oracle Identity Manager | OIM Legacy UI | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60727 | Oracle Identity Manager | OIM Legacy UI | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61258 | Oracle Internet Directory | OID LDAP Server | LDAP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-62634 | Oracle Reports Developer | Security and Authentication | CORBA | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62639 | Oracle Reports Developer | Security and Authentication | CORBA | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62614 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62626 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62632 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62633 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62635 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-70669 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62611 | Oracle Reports Developer | Security and Authentication | IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62622 | Oracle Reports Developer | Security and Authentication | IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62624 | Oracle Reports Developer | Security and Authentication | IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62640 | Oracle Reports Developer | Security and Authentication | IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62609 | Oracle Reports Developer | Security and Authentication | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62621 | Oracle Reports Developer | Security and Authentication | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62630 | Oracle Reports Developer | Security and Authentication | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-62617 | Oracle Reports Developer | Security and Authentication | UDP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-60958 | Oracle WebCenter Enterprise Capture | Client Bundle | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60946 | Oracle WebCenter Enterprise Capture | Client Bundle | RMI | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60947 | Oracle WebCenter Enterprise Capture | Client Bundle | RMI | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60921 | Oracle WebCenter Enterprise Capture | Client Bundle | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60970 | Oracle WebCenter Enterprise Capture | Client Bundle | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60971 | Oracle WebCenter Enterprise Capture | Client Bundle | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-70970 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61018 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60698 | Oracle WebLogic Server | Core | IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-60977 | Oracle WebLogic Server | WLS Core Components | RMI | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 | |
| CVE-2026-60672 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-60696 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-70670 | Oracle Reports Developer | Security and Authentication | IIOP | Yes | 9.6 | Adjacent Network |
Low | None | None | Changed | High | High | High | 14.1.2.0.0 | |
| CVE-2026-61001 | Oracle Web Services Manager | Web Services Security | HTTP | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60905 | Oracle WebCenter Content | Content Server | HTTP | Yes | 9.6 | Network | Low | None | Required | Changed | High | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60861 | Service Delivery Platform | Messaging Enabler | Oracle Net | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 14.1.2.0.0, 12.2.1.4.0 | |
| CVE-2026-71166 | Helidon | Imperative Web Server | HTTP | Yes | 9.4 | Network | Low | None | None | Un- changed |
High | High | Low | 3.2.18 | |
| CVE-2026-71167 | Helidon | Imperative Web Server | HTTP | Yes | 9.4 | Network | Low | None | None | Un- changed |
High | High | Low | 4.5.0 | |
| CVE-2026-73920 | Helidon | Imperative Web Server | HTTP | Yes | 9.4 | Network | Low | None | None | Un- changed |
High | High | Low | 4.5.0 | |
| CVE-2026-62629 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.4 | Network | Low | None | None | Un- changed |
Low | High | High | 14.1.2.0.0 | |
| CVE-2026-71065 | Helidon | Imperative Web Server | HTTP | Yes | 9.3 | Network | Low | None | None | Changed | High | Low | None | 3.2.18 | |
| CVE-2026-62613 | Oracle Reports Developer | Security and Authentication | CORBA | Yes | 9.3 | Adjacent Network |
Low | None | None | Changed | High | High | None | 12.2.1.19.0 | |
| CVE-2026-62637 | Oracle Reports Developer | Security and Authentication | CORBA | Yes | 9.3 | Adjacent Network |
Low | None | None | Changed | High | High | None | 14.1.2.0.0 | |
| CVE-2026-62618 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.3 | Network | Low | None | None | Changed | High | Low | None | 12.2.1.19.0 | |
| CVE-2026-70673 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.3 | Network | Low | None | None | Changed | High | Low | None | 14.1.2.0.0 | |
| CVE-2026-73865 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 3.2.18 | |
| CVE-2026-73866 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 4.5.0 | |
| CVE-2026-73916 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 3.2.18 | |
| CVE-2026-73917 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 4.5.0 | |
| CVE-2026-73922 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 1.4.19 | |
| CVE-2026-73924 | Helidon | Imperative Web Server | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 1.4.19 | |
| CVE-2026-62610 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.19.0 | |
| CVE-2026-62638 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 14.1.2.0.0 | |
| CVE-2026-70668 | Oracle Reports Developer | Security and Authentication | SOAP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 14.1.2.0.0 | |
| CVE-2026-60737 | Oracle Web Services Manager | Web Services Security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60728 | Oracle WebCenter Portal | Portlet Services | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61008 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61034 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61029 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 9.0 | Network | High | None | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60726 | Oracle Access Manager | Authentication Engine | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60715 | Oracle Identity Manager | OIM Legacy UI | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61118 | Oracle Identity Manager | OIM Legacy UI | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60716 | Oracle Identity Manager | OIM Legacy UI | T3, IIOP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60722 | Oracle Identity Manager | OIM Legacy UI | T3, IIOP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-62612 | Oracle Reports Developer | Security and Authentication | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62619 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 8.8 | Network | Low | None | Required | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62623 | Oracle Reports Developer | Security and Authentication | UDP | Yes | 8.8 | Adjacent Network |
Low | None | None | Un- changed |
High | High | High | 12.2.1.19.0 | |
| CVE-2026-62631 | Oracle Reports Developer | Security and Authentication | UDP | Yes | 8.8 | Adjacent Network |
Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-70674 | Oracle Reports Developer | Security and Authentication | UDP | Yes | 8.8 | Adjacent Network |
Low | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-61002 | Oracle SOA Suite | B2B Engine | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61231 | Oracle Virtual Directory | Virtual Directory Server | LDAP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60729 | Oracle WebCenter Portal | Composer | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61213 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60731 | Oracle WebCenter Portal | Composer | RMI | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61017 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61022 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61032 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61040 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61042 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61058 | Oracle WebCenter Sites | WebCenter Sites | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60707 | Oracle Identity Manager | Security | HTTP | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60996 | Oracle Identity Manager Connector | Connectors and Connector Server | HTTPS | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60903 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60934 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60935 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60954 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60980 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60981 | Oracle WebCenter Content | Content Server | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 14.1.2.0.0, 12.2.1.4.0 | |
| CVE-2026-61193 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61215 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61219 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60860 | Service Delivery Platform | Messaging Enabler | TCP | Yes | 8.7 | Network | High | None | None | Changed | None | High | High | 14.1.2.0.0, 12.2.1.4.0 | |
| CVE-2026-73939 | Helidon | Imperative Web Server | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | None | High | None | 3.2.20 | |
| CVE-2026-62620 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.19.0 | |
| CVE-2026-62625 | Oracle Reports Developer | Security and Authentication | SOAP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 12.2.1.19.0 | |
| CVE-2026-62636 | Oracle Reports Developer | Security and Authentication | SOAP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 14.1.2.0.0 | |
| CVE-2026-62628 | Oracle Reports Developer | Security and Authentication | TCP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.19.0 | |
| CVE-2026-61228 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61230 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61033 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61045 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.6 | Network | Low | None | None | Un- changed |
High | Low | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60699 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-71155 | Helidon | Imperative Web Server | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 3.2.18 | |
| CVE-2026-62615 | Oracle Reports Developer | Security and Authentication | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.1.19.0 | |
| CVE-2026-60841 | Oracle Unified Directory | OUD Core | LDAP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60849 | Oracle Unified Directory | OUD Core | LDAP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-61212 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60928 | Oracle WebCenter Content | Content Server | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 14.1.2.0.0 | |
| CVE-2026-73929 | Helidon | Imperative Web Server | HTTP | Yes | 8.3 | Network | Low | None | None | Changed | Low | Low | Low | 4.5.3 | |
| CVE-2026-73931 | Helidon | Imperative Web Server | HTTP | Yes | 8.3 | Network | Low | None | None | Changed | Low | Low | Low | 4.5.3 | |
| CVE-2026-71159 | Helidon | Imperative Web Server | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 3.2.18 | |
| CVE-2026-73925 | Helidon | Imperative Web Server | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
Low | High | None | 1.4.19 | |
| CVE-2026-73937 | Helidon | Imperative Web Server | HTTP/2 | Yes | 8.2 | Network | Low | None | None | Un- changed |
Low | None | High | 4.5.0 | |
| CVE-2026-60944 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60955 | Oracle WebCenter Content | Content Server | HTTP | No | 8.2 | Network | Low | High | None | Changed | Low | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61222 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61011 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61016 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61038 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61054 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-71110 | Helidon | Imperative Web Server | HTTPS | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 4.5.0 | |
| CVE-2026-60992 | Oracle Identity Manager Connector | Core | TLS | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-70671 | Oracle Reports Developer | Security and Authentication | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 14.1.2.0.0 | |
| CVE-2026-70675 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 14.1.2.0.0 | |
| CVE-2026-70924 | Oracle Web Services Manager | Web Services Security | HTTPS | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61177 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61229 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60680 | Oracle WebLogic Server | Core | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-60415 | Oracle WebLogic Server | Core | T3, IIOP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-60998 | Oracle Identity Manager Connector | Microsoft Active Directory | LDAP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60961 | Oracle WebCenter Content | Content Server | HTTP | Yes | 8.0 | Adjacent Network |
High | None | None | Changed | High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-71111 | Oracle Identity Manager | Installer | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60991 | Oracle Identity Manager Connector | Core | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60412 | Oracle Outside In Technology | Outside In Core | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 8.5.8 | |
| CVE-2026-60413 | Oracle Outside In Technology | Outside In Core | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 8.5.8 | |
| CVE-2026-60414 | Oracle Outside In Technology | Outside In Core | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 8.5.8 | |
| CVE-2026-60392 | Oracle Outside In Technology | Outside In PDF Export SDK | None | No | 7.8 | Local | Low | None | Required | Un- changed |
High | High | High | 8.5.8 | |
| CVE-2026-61291 | Oracle WebCenter Content | Content Server | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60969 | Oracle Unified Directory | OUD Core | LDAP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60983 | Oracle WebCenter Content | Content Server | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 14.1.2.0.0, 12.2.1.4.0 | |
| CVE-2026-60733 | Oracle WebCenter Portal | Composer | HTTP | No | 7.7 | Network | High | Low | None | Changed | Low | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61199 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 14.1.2.0.0 | |
| CVE-2026-60909 | Oracle WebCenter Content | Content Server | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61208 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
High | Low | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61227 | Oracle WebCenter Portal | Runtime Tools | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-70908 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.18 | |
| CVE-2026-71153 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 1.4.20 | |
| CVE-2026-71158 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 3.2.18 | |
| CVE-2026-71160 | Helidon | Imperative Web Server | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 3.2.18 | |
| CVE-2026-73878 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 3.2.18 | |
| CVE-2026-73879 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 4.5.1 | |
| CVE-2026-73882 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.19 | |
| CVE-2026-73883 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 3.2.18 | |
| CVE-2026-73884 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 4.5.0 | |
| CVE-2026-73902 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.19 | |
| CVE-2026-73903 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 4.5.1 | |
| CVE-2026-73907 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 3.2.18 | |
| CVE-2026-73908 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 4.5.0 | |
| CVE-2026-73915 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.5.0 | |
| CVE-2026-73927 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.20 | |
| CVE-2026-73936 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.5.1 | |
| CVE-2026-73938 | Helidon | Imperative Web Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 4.5.0 | |
| CVE-2026-73887 | Helidon | Imperative Web Server | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 4.5.0 | |
| CVE-2026-73890 | Helidon | Imperative Web Server | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.5.0 | |
| CVE-2026-73934 | Helidon | Imperative Web Server | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.19 | |
| CVE-2026-73935 | Helidon | Imperative Web Server | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 4.5.1 | |
| CVE-2026-42587 | Helidon | Imperative Web Server (Netty) | HTTP/2 | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.2.18 | |
| CVE-2026-60993 | Oracle Identity Manager Connector | Core | TLS | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60850 | Oracle Unified Directory | OUD Core | LDAP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60889 | Oracle Unified Directory | OUD Core | LDAP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60914 | Oracle Unified Directory | OUD Core | LDAP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60906 | Oracle WebCenter Content | Content Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61007 | Oracle WebCenter Sites | WebCenter Sites | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-60679 | Oracle WebLogic Server | Core | T3, IIOP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 | |
| CVE-2026-60915 | Helidon | Imperative Web Server | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 4.5.0 | |
| CVE-2026-70672 | Oracle Reports Developer | Security and Authentication | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 14.1.2.0.0 | |
| CVE-2026-60933 | Oracle WebCenter Content | Content Server | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-73891 | Helidon | Imperative Web Server | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 4.5.0 | |
| CVE-2026-73894 | Helidon | Imperative Web Server | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 4.5.0 | |
| CVE-2026-73918 | Helidon | Imperative Web Server | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 4.5.0 | |
| CVE-2026-73933 | Helidon | Imperative Web Server | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 4.5.3 | |
| CVE-2026-33186 | Helidon | Imperative Web Server (gRPC) | HTTP/2 | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 4.5.0 | |
| CVE-2026-73875 | Helidon | Imperative Web Server | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 3.2.19 | |
| CVE-2026-73876 | Helidon | Imperative Web Server | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 4.5.1 | |
| CVE-2026-73885 | Helidon | Imperative Web Server | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 3.2.18 | |
| CVE-2026-73886 | Helidon | Imperative Web Server | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 4.5.0 | |
| CVE-2026-73928 | Helidon | Imperative Web Server | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 4.5.3 | |
| CVE-2026-60994 | Oracle Identity Manager Connector | Core | None | No | 7.2 | Local | High | Low | Required | Changed | High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-62616 | Oracle Reports Developer | Security and Authentication | SMTP | Yes | 7.2 | Network | Low | None | None | Changed | None | Low | Low | 12.2.1.19.0 | |
| CVE-2026-62627 | Oracle Reports Developer | Security and Authentication | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | Low | None | 12.2.1.19.0 | |
| CVE-2026-60949 | Oracle WebCenter Content | Content Server | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61288 | Oracle WebCenter Content | Content Server | HTTP | Yes | 7.1 | Network | Low | None | Required | Un- changed |
High | Low | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61290 | Oracle WebCenter Content | Content Server | HTTP | No | 7.1 | Network | High | Low | Required | Un- changed |
High | High | High | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-70858 | Oracle WebCenter Content | Content Server | HTTP | Yes | 7.1 | Network | Low | None | Required | Changed | Low | Low | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61295 | Oracle WebCenter Content | Content Server | None | No | 7.1 | Local | Low | None | None | Changed | High | None | None | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-61124 | Oracle WebCenter Portal | Runtime Tools | HTTP | Yes | 7.1 | Network | Low | None | Required | Un- changed |
None | High | Low | 12.2.1.4.0, 14.1.2.0.0 | |
| CVE-2026-71029 | Helidon | Imperative Web Server | HTTP | Yes | 6.8 | Network | High | None | None | Changed | High | None | None | 3.2.18 | |
| CVE-2026-60895 | Oracle Unified Directory | OUD Core | LDAP | No | 6.8 | Network | High | Low | None | Un- changed |
High | High | None | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-60865 | Service Delivery Platform | Messaging Enabler | HTTP | No | 6.8 | Network | Low | High | None | Changed | High | None | None | 14.1.2.0.0, 12.2.1.4.0 | |
| CVE-2026-71162 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | High | None | None | Un- changed |
High | Low | None | 3.2.18 | |
| CVE-2026-73867 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 3.2.18 | |
| CVE-2026-73868 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73892 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73893 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73897 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73904 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 4.5.1 | |
| CVE-2026-73914 | Helidon | Imperative Web Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | None | Low | 4.5.0 | |
| CVE-2026-73896 | Helidon | Imperative Web Server | HTTP/2 | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | None | Low | 4.5.0 | |
| CVE-2026-60866 | Service Delivery Platform | Messaging Enabler | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 14.1.2.0.0 | |
| CVE-2026-70923 | Helidon | Imperative Web Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 3.2.19 | |
| CVE-2026-73869 | Helidon | Imperative Web Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 3.2.18 | |
| CVE-2026-73870 | Helidon | Imperative Web Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 4.5.0 | |
| CVE-2026-73898 | Helidon | Imperative Web Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 4.5.0 | |
| CVE-2026-71154 | Helidon | Imperative Web Server | None | No | 6.1 | Local | Low | Low | None | Un- changed |
High | Low | None | 4.5.0 | |
| CVE-2026-70716 | Helidon | Imperative Web Server | HTTP | Yes | 5.9 | Network | High | None | None | Un- changed |
None | High | None | 4.5.0 | |
| CVE-2026-73909 | Helidon | Imperative Web Server | HTTP | Yes | 5.9 | Network | High | None | None | Un- changed |
High | None | None | 3.2.19 | |
| CVE-2026-71165 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 3.2.18 | |
| CVE-2026-73874 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73881 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73911 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73913 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 4.5.0 | |
| CVE-2026-73919 | Helidon | Imperative Web Server | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 3.2.18 | |
| CVE-2026-71156 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | Low | None | 3.2.19 | |
| CVE-2026-71157 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.0 | |
| CVE-2026-71161 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 3.2.18 | |
| CVE-2026-73871 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.2.18 | |
| CVE-2026-73872 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.0 | |
| CVE-2026-73877 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.2.18 | |
| CVE-2026-73888 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.0 | |
| CVE-2026-73889 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.0 | |
| CVE-2026-73895 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.2.18 | |
| CVE-2026-73899 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.2.19 | |
| CVE-2026-73900 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.1 | |
| CVE-2026-73906 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.0 | |
| CVE-2026-73910 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 4.5.1 | |
| CVE-2026-73932 | Helidon | Imperative Web Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 4.5.3 | |
| CVE-2026-70727 | Helidon | Imperative Web Server | HTTPS | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.2.18 | |
| CVE-2026-73901 | Helidon | Imperative Web Server | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 4.5.1 | |
| CVE-2026-73880 | Helidon | Imperative Web Server | None | No | 4.4 | Local | Low | High | None | Un- changed |
High | None | None | 4.5.1 | |
| CVE-2026-71124 | Oracle Access Manager | Authorization Engine | TCP | No | 4.3 | Network | Low | Low | None | Un- changed |
None | None | Low | 12.2.1.4.0, 14.1.2.1.0 | |
| CVE-2026-73873 | Helidon | Imperative Web Server | HTTP | No | 4.2 | Network | High | Low | None | Un- changed |
Low | Low | None | 3.2.18 | |
| CVE-2026-60853 | Helidon | Imperative Web Server | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | 3.2.20 | |
| CVE-2026-73923 | Helidon | Imperative Web Server | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
None | Low | None | 1.4.20 | |
This Critical Security Patch Update contains 16 new security patches for Oracle Analytics. 3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71059 | Oracle BI Publisher | Web Service API | SOAP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 8.2.0.0.0, 26.1.0.0.0 | |
| CVE-2026-71058 | Oracle BI Publisher | Web Service API | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-71055 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-71057 | Oracle BI Publisher | BI Platform Security | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | None | Low | 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 | |
| CVE-2026-61305 | Oracle BI Publisher | BI Platform Security | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-71095 | Oracle Business Intelligence Enterprise Edition | BI Platform Security | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
High | High | Low | 12.2.1.4.0 | |
| CVE-2026-71096 | Oracle Business Intelligence Enterprise Edition | BI Platform Security | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-61302 | Oracle Business Intelligence Enterprise Edition | Pod Admin | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-71122 | Oracle Business Intelligence Enterprise Edition | Platform Security | HTTP | No | 8.0 | Network | High | High | None | Changed | High | High | High | 26.01.0.0.0 | |
| CVE-2026-71097 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 26.01.0.0.0 | |
| CVE-2026-71056 | Oracle Business Intelligence Enterprise Edition | BI Search | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0 | |
| CVE-2026-71107 | Oracle Business Intelligence Enterprise Edition | Analytics Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-71061 | Oracle Business Intelligence Enterprise Edition | BI Platform Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 8.2.0.0.0, 26.01.0.0.0 | |
| CVE-2026-71094 | Oracle Business Intelligence Enterprise Edition | Presentation Services | None | No | 7.3 | Local | Low | Low | Required | Un- changed |
High | High | High | 12.2.1.4.0 | |
| CVE-2026-71099 | Oracle Business Intelligence Enterprise Edition | Analytics Web Answers | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 26.01.0.0.0 | |
| CVE-2026-71098 | Oracle Business Intelligence Enterprise Edition | Platform Security | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 26.01.0.0.0 | |
This Critical Security Patch Update contains 1 new security patch for Oracle Hospitality Applications. This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71106 | Oracle Hospitality OPERA 5 Property Services | Opera Servlet | HTTP | Yes | 8.8 | Network | Low | None | Required | Un- changed |
High | High | High | 5.6.28.0-5.6.28.1 | |
This Critical Security Patch Update contains 262 new security patches for Oracle Hyperion. 107 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-70880 | Oracle Hyperion Data Relationship Management | Access and security | TCP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-70921 | Oracle Hyperion Financial Management | Security | TLS | Yes | 10.0 | Network | Low | None | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-61206 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-70920 | Oracle Hyperion Financial Management | Security | SQL | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-60858 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70871 | Oracle Hyperion Data Relationship Management | Access and security | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70873 | Oracle Hyperion Data Relationship Management | Access and security | TCP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70817 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70739 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70740 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70745 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62457 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2023-50164 | Oracle Hyperion Infrastructure Technology | Common Security (Apache Struts) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62539 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62541 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62543 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62544 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62582 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70958 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 9.6 | Network | Low | None | Required | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-62463 | Oracle Hyperion Infrastructure Technology | Lifecycle Management | HTTP | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70872 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70883 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70876 | Oracle Hyperion Data Relationship Management | Access and security | HTTPS | No | 9.1 | Network | Low | High | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-70884 | Oracle Hyperion Data Relationship Management | Access and security | SOAP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70854 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
None | High | High | 11.2.25.0.000 | |
| CVE-2026-70741 | Oracle Hyperion Financial Reporting | Server | RMI | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70730 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-61276 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70874 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70877 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70886 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70899 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70940 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-71150 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70818 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70819 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70821 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70928 | Oracle Hyperion Financial Management | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70944 | Oracle Hyperion Financial Management | Security | TCP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70787 | Oracle Hyperion Financial Reporting | Server | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70742 | Oracle Hyperion Financial Reporting | Server | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62500 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70956 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70965 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70966 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70882 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70900 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70903 | Oracle Hyperion Data Relationship Management | Access and security | HTTPS | No | 8.7 | Network | Low | Low | Required | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-62535 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | MySQL Protocol | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70721 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70885 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-70840 | Oracle Hyperion Financial Management | Security | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70842 | Oracle Hyperion Financial Management | Security | None | No | 8.4 | Local | Low | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-62598 | Oracle Hyperion Calculation Manager | Security | SFTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70887 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70892 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70870 | Oracle Hyperion Data Relationship Management | Web Client - Unicode | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 11.2.23.0.000 | |
| CVE-2026-70897 | Oracle Hyperion Data Relationship Management | Access and security | HTTPS | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70893 | Oracle Hyperion Data Relationship Management | Access and security | SQL | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70909 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70952 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70743 | Oracle Hyperion Financial Reporting | Server | HTTPS | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-62485 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 8.2 | Network | Low | None | Required | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70964 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-61281 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-61293 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70878 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70881 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70901 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70904 | Oracle Hyperion Data Relationship Management | Access and security | SOAP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70929 | Oracle Hyperion Financial Management | Security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70925 | Oracle Hyperion Financial Management | Security | SQL | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70943 | Oracle Hyperion Financial Management | Security | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70744 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70746 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70749 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62471 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62501 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62502 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62477 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70957 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70959 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 11.2.25.0.000 | |
| CVE-2023-26464 | Oracle Hyperion Infrastructure Technology | Installation and Configuration (Apache Log4j) | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62531 | Oracle Hyperion Infrastructure Technology | Lifecycle Management | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70738 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62602 | Oracle Hyperion Calculation Manager | Security | SSH | Yes | 8.0 | Adjacent Network |
High | None | None | Changed | High | High | None | 11.2.25.0.000 | |
| CVE-2026-70685 | Oracle Hyperion Calculation Manager | Security | None | No | 7.9 | Local | Low | None | None | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70879 | Oracle Hyperion Data Relationship Management | Access and security | None | No | 7.8 | Local | High | Low | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-70750 | Oracle Hyperion Financial Reporting | Server | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62581 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62571 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70894 | Oracle Hyperion Data Relationship Management | Access and security | None | No | 7.7 | Local | Low | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70828 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70942 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-62467 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70723 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70678 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70960 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.6 | Network | Low | Low | Required | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70875 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70889 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70890 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70891 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70896 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-34481 | Oracle Hyperion Data Relationship Management | Installation/Configuration (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 11.2.25.0.000 | |
| CVE-2026-70822 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70832 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70937 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70946 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-71117 | Oracle Hyperion Financial Management | Security | None | No | 7.5 | Local | High | High | None | Changed | High | High | High | 11.2.25.0.000 | |
| CVE-2026-60391 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70752 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2022-34169 | Oracle Hyperion Infrastructure Technology | Common Security (Apache Xalan-Java) | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62550 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62552 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62554 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70973 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-60393 | Oracle Hyperion Infrastructure Technology | Lifecycle Management | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62481 | Oracle Hyperion Infrastructure Technology | Common Events | SQL | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62545 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | TCP | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70898 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70823 | Oracle Hyperion Financial Management | Security | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62492 | Oracle Hyperion Infrastructure Technology | Common Security | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62538 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62551 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 7.3 | Network | Low | None | None | Un- changed |
Low | Low | Low | 11.2.25.0.000 | |
| CVE-2026-62459 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 7.2 | Network | High | High | None | Changed | High | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70834 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70939 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70950 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70735 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-61259 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70705 | Oracle Hyperion Calculation Manager | Security | None | No | 7.1 | Local | Low | None | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70902 | Oracle Hyperion Data Relationship Management | Access and security | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70933 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70934 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70935 | Oracle Hyperion Financial Management | Security | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70936 | Oracle Hyperion Financial Management | Security | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62522 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | No | 7.1 | Network | High | Low | None | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70971 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-62536 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62537 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70967 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 7.1 | Local | Low | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70733 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 11.2.25.0.000 | |
| CVE-2026-70736 | Oracle Hyperion Profitability and Cost Management | Deployment | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70676 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 7.0 | Network | High | None | None | Un- changed |
Low | High | Low | 11.2.25.0.000 | |
| CVE-2026-70914 | Oracle Hyperion Financial Management | Security | None | No | 7.0 | Local | High | None | Required | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70843 | Oracle Hyperion Financial Management | Security | TLS | Yes | 6.8 | Adjacent Network |
High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70751 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 6.8 | Network | High | None | Required | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70780 | Oracle Hyperion Financial Reporting | Server | TLS | Yes | 6.8 | Adjacent Network |
High | None | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70972 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 6.8 | Network | High | Low | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-61313 | Oracle Hyperion Calculation Manager | Security | None | No | 6.7 | Local | Low | High | None | Changed | High | Low | None | 11.2.25.0.000 | |
| CVE-2026-71109 | Oracle Hyperion Financial Management | Security | None | No | 6.7 | Local | Low | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-70888 | Oracle Hyperion Data Relationship Management | Access and security | HTTP | No | 6.6 | Network | High | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2022-23305 | Oracle Hyperion Financial Management | Security (Apache Log4j) | TCP | No | 6.6 | Network | High | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-62578 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 6.5 | Adjacent Network |
Low | None | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70895 | Oracle Hyperion Data Relationship Management | Access and security | None | No | 6.5 | Local | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70824 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70825 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70826 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70831 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70849 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | High | None | Un- changed |
High | None | High | 11.2.25.0.000 | |
| CVE-2026-70938 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70969 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70975 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71121 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70847 | Oracle Hyperion Financial Management | Security | None | No | 6.5 | Local | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-71091 | Oracle Hyperion Financial Management | Security | SQL | No | 6.5 | Network | Low | High | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-60682 | Oracle Hyperion Financial Reporting | Repository | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70767 | Oracle Hyperion Financial Reporting | Server | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70769 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 6.5 | Network | High | None | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70788 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 6.5 | Network | Low | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62506 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62523 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | Yes | 6.5 | Network | Low | None | Required | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-70968 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62572 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 6.5 | Local | Low | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-62555 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | SQL | No | 6.5 | Network | Low | High | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-62576 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | TLS | Yes | 6.5 | Network | High | None | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-71090 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.4 | Network | High | Low | None | Un- changed |
Low | Low | High | 11.2.25.0.000 | |
| CVE-2026-71119 | Oracle Hyperion Financial Management | Security | None | No | 6.4 | Local | High | High | None | Un- changed |
High | High | High | 11.2.25.0.000 | |
| CVE-2026-71103 | Oracle Hyperion Financial Management | Security | HTTP | No | 6.3 | Network | Low | Low | None | Un- changed |
Low | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70753 | Oracle Hyperion Financial Reporting | Server | HTTP | No | 6.3 | Network | Low | Low | Required | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-62558 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 6.3 | Local | High | None | Required | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70838 | Oracle Hyperion Financial Management | Security | None | No | 6.1 | Local | Low | Low | None | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70765 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70768 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62499 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62568 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70961 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-71013 | Oracle Hyperion Financial Management | Security | None | No | 6.0 | Local | Low | High | None | Un- changed |
High | High | None | 11.2.25.0.000 | |
| CVE-2026-70677 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 5.9 | Network | High | None | Required | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70789 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 5.9 | Network | High | None | Required | Un- changed |
High | Low | None | 11.2.25.0.000 | |
| CVE-2026-70841 | Oracle Hyperion Financial Management | Security | None | No | 5.6 | Local | High | Low | None | Changed | High | None | None | 11.2.25.0.000 | |
| CVE-2026-70836 | Oracle Hyperion Financial Management | Security | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62553 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62564 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62573 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 5.5 | Local | Low | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62441 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 5.4 | Network | Low | Low | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62603 | Oracle Hyperion Calculation Manager | Security | SFTP | Yes | 5.4 | Adjacent Network |
Low | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-71123 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 5.4 | Network | Low | None | Required | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70759 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 5.4 | Network | Low | None | Required | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70766 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 5.4 | Network | Low | None | Required | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-61342 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 5.3 | Network | High | None | Required | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-62446 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70679 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-70911 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70974 | Oracle Hyperion Financial Management | Security | HTTP | No | 5.3 | Network | High | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71108 | Oracle Hyperion Financial Management | Security | HTTP | No | 5.3 | Network | High | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71120 | Oracle Hyperion Financial Management | Security | HTTP | No | 5.3 | Network | High | Low | None | Un- changed |
None | None | High | 11.2.25.0.000 | |
| CVE-2026-71148 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70912 | Oracle Hyperion Financial Management | Security | None | No | 5.3 | Local | High | Low | Required | Changed | None | High | None | 11.2.25.0.000 | |
| CVE-2026-70754 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70758 | Oracle Hyperion Financial Reporting | Server | None | No | 5.3 | Local | High | Low | None | Un- changed |
Low | High | None | 11.2.25.0.000 | |
| CVE-2026-70784 | Oracle Hyperion Financial Reporting | Server | None | No | 5.3 | Local | High | Low | None | Un- changed |
Low | High | None | 11.2.25.0.000 | |
| CVE-2026-62509 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62510 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62566 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62579 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62460 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 5.0 | Network | Low | Low | None | Changed | Low | None | None | 11.2.25.0.000 | |
| CVE-2026-71085 | Oracle Hyperion Financial Management | Security | HTTP | No | 4.9 | Network | Low | High | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71118 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62520 | Oracle Hyperion Infrastructure Technology | Common Events | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2021-31805 | Oracle Hyperion Infrastructure Technology | Common Events (Apache Struts 1) | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-71105 | Oracle Hyperion Financial Management | Security | None | No | 4.7 | Local | High | Low | None | Un- changed |
None | None | High | 11.2.25.0.000 | |
| CVE-2026-70794 | Oracle Hyperion Financial Reporting | Server | None | No | 4.7 | Local | High | Low | None | Un- changed |
None | High | None | 11.2.25.0.000 | |
| CVE-2026-62575 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 4.7 | Local | High | Low | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71060 | Oracle Hyperion Financial Management | Security | HTTP | No | 4.4 | Network | High | High | None | Un- changed |
High | None | None | 11.2.25.0.000 | |
| CVE-2026-71145 | Oracle Hyperion Financial Management | Security | HTTP | No | 4.4 | Network | High | Low | Required | Changed | Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70683 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 4.3 | Network | Low | None | Required | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-71147 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 4.2 | Network | High | None | Required | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-71149 | Oracle Hyperion Financial Management | Security | None | No | 4.2 | Local | High | Low | Required | Un- changed |
Low | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70793 | Oracle Hyperion Financial Reporting | Server | HTTP | No | 4.2 | Network | High | Low | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70963 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | HTTP | No | 4.2 | Network | High | Low | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-70714 | Oracle Hyperion Calculation Manager | Security | None | No | 4.1 | Local | High | High | None | Un- changed |
None | High | None | 11.2.25.0.000 | |
| CVE-2021-4104 | Oracle Hyperion Infrastructure Technology | Common Events (Apache Log4j) | HTTP | No | 4.1 | Network | High | High | None | Un- changed |
Low | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70719 | Oracle Hyperion Calculation Manager | Security | None | No | 4.0 | Local | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70916 | Oracle Hyperion Financial Management | Security | None | No | 4.0 | Local | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70917 | Oracle Hyperion Financial Management | Security | None | No | 4.0 | Local | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62584 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 4.0 | Local | Low | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62532 | Oracle Hyperion Calculation Manager | Security | SQL | No | 3.8 | Network | Low | High | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62533 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70682 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70848 | Oracle Hyperion Financial Management | Security | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70785 | Oracle Hyperion Financial Reporting | Server | HTTP | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70711 | Oracle Hyperion Calculation Manager | Security | None | No | 3.6 | Local | High | None | Required | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62529 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 3.5 | Network | Low | Low | Required | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-62569 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.4 | Local | Low | High | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-70853 | Oracle Hyperion Financial Management | Security | HTTP | No | 3.3 | Network | High | High | None | Un- changed |
Low | None | Low | 11.2.25.0.000 | |
| CVE-2026-62526 | Oracle Hyperion Infrastructure Technology | Common Security | HTTP | No | 3.3 | Network | High | High | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-62577 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.3 | Local | Low | Low | None | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-70962 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.3 | Local | Low | Low | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62461 | Oracle Hyperion Calculation Manager | Security | HTTP | Yes | 3.1 | Network | High | None | Required | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62606 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 3.1 | Network | High | Low | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-62604 | Oracle Hyperion Calculation Manager | Security | HTTPS | Yes | 3.1 | Adjacent Network |
High | None | None | Un- changed |
Low | None | None | 11.2.25.0.000 | |
| CVE-2026-70851 | Oracle Hyperion Financial Management | Security | HTTP | No | 3.1 | Network | High | Low | None | Un- changed |
None | None | Low | 11.2.25.0.000 | |
| CVE-2026-70850 | Oracle Hyperion Financial Management | Security | None | No | 3.0 | Local | High | High | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-71144 | Oracle Hyperion Financial Management | Security | None | No | 3.0 | Local | High | High | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62511 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.0 | Local | High | High | None | Un- changed |
Low | Low | None | 11.2.25.0.000 | |
| CVE-2026-62570 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.0 | Local | High | High | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-62583 | Oracle Hyperion Infrastructure Technology | Installation and Configuration | None | No | 3.0 | Local | High | High | None | Un- changed |
None | Low | Low | 11.2.25.0.000 | |
| CVE-2026-62580 | Oracle Hyperion Calculation Manager | Security | HTTP | No | 2.6 | Adjacent Network |
High | Low | None | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-70776 | Oracle Hyperion Financial Reporting | Server | HTTP | No | 2.6 | Network | High | Low | Required | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-70919 | Oracle Hyperion Financial Management | Security | None | No | 2.5 | Local | High | None | Required | Un- changed |
None | Low | None | 11.2.25.0.000 | |
| CVE-2026-71146 | Oracle Hyperion Financial Management | Security | None | No | 1.9 | Local | High | High | None | Un- changed |
None | None | Low | 11.2.25.0.000 | |
This Critical Security Patch Update contains 5 new security patches for Oracle Java SE. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
The CVSS scores below assume that a user running a Java applet or Java Web Start application has administrator privileges (typical on Windows). When the user does not run with administrator privileges (typical on Solaris and Linux), the corresponding CVSS impact scores for Confidentiality, Integrity, and Availability are "Low" instead of "High", lowering the CVSS Base Score. For example, a Base Score of 9.6 becomes 7.1.
Java Management Service, available to all users, can help you find vulnerable Java versions in your systems. Java SE Subscribers and customers running in Oracle Cloud can use Java Management Service to update Java Runtimes and to do further security reviews like identifying potentially vulnerable third party libraries used by your Java programs. Existing Java Management Service user click here to log in to your dashboard. The Java Management Service Documentation provides a list of features available to everyone and those available only to customers. Learn more about using Java Management Service to monitor and secure your Java Installations.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-62574 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Install | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 | See Note 1 |
| CVE-2026-70906 | Oracle Java SE | 2D | Multiple | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | Oracle Java SE: 25.0.4, 26.0.2 | See Note 1 |
| CVE-2026-61308 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Networking | HTTP | Yes | 6.8 | Network | High | None | None | Changed | High | None | None | Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 | See Note 1 |
| CVE-2026-70907 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | JSSE | TLS | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 | See Note 2 |
| CVE-2026-60589 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Security | Multiple | Yes | 3.7 | Network | High | None | None | Un- changed |
Low | None | None | Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20, 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19 | See Note 2 |
This Critical Security Patch Update contains 6 new security patches for Oracle JD Edwards. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-61272 | JD Edwards EnterpriseOne Tools | Web Runtime SEC | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 9.2.0.0-9.2.26.4 | |
| CVE-2026-61273 | JD Edwards EnterpriseOne Tools | Installation Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 9.2.0.0-9.2.26.4 | |
| CVE-2026-61270 | JD Edwards EnterpriseOne Orchestrator | E1 IOT Orchestrator Security | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 9.2.0.0-9.2.26.4 | |
| CVE-2026-61265 | JD Edwards EnterpriseOne Orchestrator | E1 IOT Orchestrator Security | TLS | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 9.2.0.0-9.2.26.4 | |
| CVE-2026-61268 | JD Edwards EnterpriseOne Tools | Business Logic Infra SEC | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 9.2.0.0-9.2.26.4 | |
| CVE-2026-60956 | JD Edwards EnterpriseOne US Payroll | Payroll | JDENET | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 9.2 | |
This Critical Security Patch Update contains 9 new security patches for Oracle MySQL. 5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-60592 | MySQL Cluster | Cluster: NDB Operator | MySQL Protocol | Yes | 8.2 | Network | Low | None | None | Un- changed |
None | Low | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 | |
| CVE-2025-14821 | MySQL Cluster | Cluster: General (libssh) | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 | |
| CVE-2026-70724 | MySQL Cluster | Cluster: General | HTTP | Yes | 7.5 | Network | High | None | Required | Un- changed |
High | High | High | 8.0.0-8.0.48, 8.4.0-8.4.11, 9.7.0-9.7.2 | |
| CVE-2025-13151 | MySQL Cluster | Cluster: General (Libtasn1) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1 | |
| CVE-2026-65914 | MySQL AI | AI: Console (DOMPurify) | HTTP | Yes | 7.2 | Network | Low | None | None | Changed | Low | Low | None | 9.4.0-9.7.2, 26.7.0 | |
| CVE-2026-71084 | MySQL Connectors | Connector/ODBC | None | No | 6.8 | Local | Low | None | None | Un- changed |
Low | None | High | 26.7.0 | |
| CVE-2026-71079 | MySQL Connectors | Connector/ODBC | MySQL Protocol | No | 6.5 | Network | Low | Low | None | Un- changed |
None | None | High | 26.7.0 | |
| CVE-2026-0968 | MySQL Shell | Shell: Core Client (libssh) | MySQL Protocol | Yes | 5.9 | Network | High | None | None | Un- changed |
None | High | None | 26.7.0 | |
| CVE-2026-71073 | MySQL Connectors | Connector/ODBC | None | No | 5.5 | Local | Low | None | Required | Un- changed |
None | None | High | 26.7.0 | |
This Critical Security Patch Update contains 15 new security patches for Oracle PeopleSoft. 7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-60821 | PeopleSoft Enterprise PeopleTools | Business Interlink | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-60967 | PeopleSoft Enterprise PeopleTools | nVision | HTTP | Yes | 8.8 | Network | Low | None | Required | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-60879 | PeopleSoft Enterprise PeopleTools | Configuration Manager | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-61307 | PeopleSoft Enterprise CC Common Application Objects | Common Application Objects | Oracle Net | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 9.2 | |
| CVE-2026-71112 | PeopleSoft Enterprise FIN Common Objects | Security | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 9.2 | |
| CVE-2026-60831 | PeopleSoft Enterprise PeopleTools | Integration Broker | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-60742 | PeopleSoft Enterprise PeopleTools | PIA Core Technology | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-71092 | PeopleSoft Enterprise FIN Lease Administration | Lease Administration | None | No | 7.5 | Local | High | Low | None | Changed | High | High | None | 9.2 | |
| CVE-2026-60975 | PeopleSoft Enterprise PeopleTools | Security | None | No | 7.5 | Local | High | Low | None | Changed | High | High | None | 8.61, 8.62 | |
| CVE-2026-60856 | PeopleSoft Enterprise PeopleTools | Install and Packaging | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 8.61-8.63 | |
| CVE-2026-70861 | PeopleSoft Enterprise FIN Common Objects Brazil | Common Objects | T3, IIOP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 9.1 | |
| CVE-2026-60883 | PeopleSoft Enterprise PeopleTools | PeopleCode | HTTP | No | 7.2 | Network | Low | High | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-60873 | PeopleSoft Enterprise PeopleTools | Data Mover | None | No | 7.2 | Local | High | High | Required | Changed | High | High | Low | 8.61-8.63 | |
| CVE-2026-60902 | PeopleSoft Enterprise PeopleTools | Tuxedo | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 8.61-8.63 | |
| CVE-2026-60884 | PeopleSoft Enterprise PeopleTools | Panel Processor | HTTP | No | 4.4 | Network | High | Low | Required | Changed | Low | Low | None | 8.61-8.63 | |
This Critical Security Patch Update contains 5 new security patches for Oracle Retail Applications. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-34481 | Oracle Retail Advanced Inventory Planning | Operations & Maintenance (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 15.0, 16.0 | |
| CVE-2026-34481 | Oracle Retail Assortment Planning | Application Core (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 15.0, 16.0 | |
| CVE-2026-34481 | Oracle Retail Fiscal Management | NF Issuing (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 14.2 | |
| CVE-2026-34481 | Oracle Retail Item Planning | Application Core (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 15.0, 16.0 | |
| CVE-2026-34481 | Oracle Retail Regular Price Optimization | Operations & Maintenance (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 15.0, 16.0 | |
This Critical Security Patch Update contains 50 new security patches for Oracle Siebel CRM. 21 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-61317 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 22.3-26.6 | |
| CVE-2026-62452 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | Yes | 9.9 | Network | Low | None | None | Changed | High | Low | Low | 22.3-26.6 | |
| CVE-2026-62512 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 22.3-26.6 | |
| CVE-2026-62588 | Siebel CRM Integration | Open Integration | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 25.12-26.6 | |
| CVE-2026-62585 | Siebel CRM Administration | Data Archival | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 25.12-26.6 | |
| CVE-2026-61318 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 22.3-26.6 | |
| CVE-2026-62592 | Siebel CRM Integration | Open Integration | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 25.12-26.6 | |
| CVE-2026-70855 | Siebel Apps - Self Service | Helpdesk/Training | HTTP | Yes | 9.3 | Network | Low | None | Required | Changed | High | High | None | 17.0-26.6 | |
| CVE-2026-60754 | Siebel Apps - Marketing | Marketing | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | None | High | 17.0-26.6 | |
| CVE-2026-60751 | Siebel Apps - Marketing | Marketing | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-60767 | Siebel Apps - Marketing | Marketing | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-61330 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 22.3-26.6 | |
| CVE-2026-61341 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 22.3-26.6 | |
| CVE-2026-70949 | Siebel CRM Deployment | Server Infrastructure | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-70951 | Siebel CRM End User | Document Management | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-61332 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 22.3-26.6 | |
| CVE-2026-62589 | Siebel CRM Integration | Open Integration | HTTP | Yes | 8.7 | Network | High | None | None | Changed | High | High | None | 25.12-26.6 | |
| CVE-2026-62586 | Siebel CRM Administration | Data Archival | HTTP | Yes | 8.6 | Network | Low | None | None | Changed | High | None | None | 25.12-26.6 | |
| CVE-2026-60758 | Siebel Artificial Intelligence | AI | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 25.12-26.6 | |
| CVE-2026-61326 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 22.3-26.6 | |
| CVE-2026-60798 | Siebel CRM Deployment | Migration | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 17.0-26.6 | |
| CVE-2026-62590 | Siebel CRM Integration | Open Integration | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 25.12-26.6 | |
| CVE-2026-62596 | Siebel CRM Integration | Open Integration | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 25.12-26.6 | |
| CVE-2026-70859 | Siebel CRM Integration | REST | HTTP | No | 8.5 | Network | High | Low | None | Changed | High | High | High | 17.0-26.6 | |
| CVE-2026-62455 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.3 | Network | Low | Low | None | Un- changed |
Low | High | High | 22.3-26.6 | |
| CVE-2026-60796 | Siebel CRM Integration | REST | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | None | Low | 17.0-26.6 | |
| CVE-2026-60779 | Siebel Apps - Marketing | Marketing | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 17.0-26.6 | |
| CVE-2026-61321 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 22.3-26.6 | |
| CVE-2026-62442 | Siebel CRM Cloud Applications | Siebel Cloud Manager | HTTPS | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 22.3-26.6 | |
| CVE-2026-60791 | Siebel CRM Deployment | Application Interface | TCP | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-60757 | Siebel CRM End User | Search | TLS | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-62591 | Siebel CRM Integration | Open Integration | HTTP | Yes | 8.1 | Network | Low | None | Required | Un- changed |
High | High | None | 25.12-26.6 | |
| CVE-2026-62595 | Siebel CRM Integration | Open Integration | TLS | Yes | 8.1 | Adjacent Network |
Low | None | None | Un- changed |
High | High | None | 25.12-26.6 | |
| CVE-2026-62454 | Siebel CRM Cloud Applications | Siebel Cloud Manager | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 22.3-26.6 | |
| CVE-2026-60753 | Siebel CRM Deployment | Installation | None | No | 7.8 | Local | Low | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-70857 | Siebel CRM End User | Open UI | HTTPS | No | 7.7 | Network | High | Low | Required | Changed | High | High | None | 17.0-26.6 | |
| CVE-2026-62593 | Siebel CRM Integration | Open Integration | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 25.12-26.6 | |
| CVE-2026-62594 | Siebel CRM Integration | Open Integration | HTTP | No | 7.7 | Network | High | High | None | Changed | None | High | High | 25.12-26.6 | |
| CVE-2026-60765 | Siebel Apps - Marketing | Marketing | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-60808 | Siebel Apps - Marketing | Email Marketing | None | No | 7.5 | Local | High | Low | None | Changed | High | High | None | 17.0-26.6 | |
| CVE-2026-70856 | Siebel CRM Deployment | Migration | HTTP | Yes | 7.5 | Network | High | None | Required | Un- changed |
High | High | High | 17.0-26.6 | |
| CVE-2026-70910 | Siebel CRM Integration | REST | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 17.0-26.6 | |
| CVE-2026-60803 | Siebel Apps - Marketing | Marketing | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-60792 | Siebel CRM Deployment | Server Infrastructure | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-60820 | Siebel CRM Integration | REST | HTTP | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-60766 | Siebel CRM Integration | REST | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-60797 | Siebel CRM Integration | REST | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 17.0-26.6 | |
| CVE-2026-61339 | Siebel CRM Cloud Applications | Siebel Cloud Manager | None | No | 7.3 | Local | Low | Low | None | Changed | High | Low | None | 22.3-26.6 | |
| CVE-2026-60752 | Siebel Apps - Marketing | Marketing | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | None | Low | 17.0-26.6 | |
| CVE-2026-62587 | Siebel CRM Administration | Data Archival | HTTP | No | 7.1 | Network | Low | Low | None | Un- changed |
High | Low | None | 25.12-26.6 | |
This Critical Security Patch Update contains 46 new security patches for Oracle Supply Chain. 18 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71040 | Oracle Agile PLM | Security | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2024-10095 | Oracle Agile PLM MCAD Connector | CAX Client (Telerik UI for WPF) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 3.6 | |
| CVE-2022-37434 | Oracle Agile PLM MCAD Connector | CAX Client (zlib) | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 3.6 | |
| CVE-2026-70846 | Oracle Demand Planning | Internal Operations | HTTP | No | 9.6 | Network | Low | Low | None | Changed | High | High | None | 12.1, 12.2 | |
| CVE-2026-71052 | Oracle Agile Engineering Data Management | Web Services Security | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71039 | Oracle Agile PLM | Application Server | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2026-71044 | Oracle Agile PLM | Export | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2026-71045 | Oracle Agile PLM | Security | HTTP | Yes | 8.8 | Network | Low | None | Required | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2026-71046 | Oracle Agile PLM | Security | None | No | 8.8 | Local | Low | Low | None | Changed | High | High | High | 9.3.6 | |
| CVE-2026-71067 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 3.6 | |
| CVE-2026-71051 | Oracle Product Lifecycle Analytics | Installation Issues | None | No | 8.8 | Local | Low | Low | None | Changed | High | High | High | 3.6.1 | |
| CVE-2026-71050 | Oracle Product Lifecycle Analytics | Installation Issues | Oracle Net | No | 8.7 | Network | Low | High | None | Changed | High | High | None | 3.6.1 | |
| CVE-2026-71049 | Oracle Product Lifecycle Analytics | Installation Issues | Oracle Net | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 3.6.1 | |
| CVE-2026-70703 | Oracle Agile Engineering Data Management | Engineering Communication Interface | HTTP | No | 8.2 | Network | High | Low | None | Changed | High | High | None | 6.2.1 | |
| CVE-2026-70852 | Oracle Demand Planning | Internal Operations | HTTP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 12.1, 12.2 | |
| CVE-2026-71053 | Oracle Agile Engineering Data Management | Web Services Security | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71042 | Oracle Agile PLM | PGC / Excel Plugin | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
None | High | High | 9.3.6 | |
| CVE-2026-71068 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | Yes | 8.1 | Network | High | None | None | Un- changed |
High | High | High | 3.6 | |
| CVE-2026-71048 | Oracle Product Lifecycle Analytics | Installation Issues | HTTP | No | 7.6 | Network | Low | Low | None | Un- changed |
High | Low | Low | 3.6.1 | |
| CVE-2026-70691 | Oracle Agile Engineering Data Management | Engineering Communication Interface | Multiple | Yes | 7.5 | Adjacent Network |
High | None | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71043 | Oracle Agile PLM | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 9.3.6 | |
| CVE-2026-71069 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | No | 7.5 | Network | High | Low | None | Un- changed |
High | High | High | 3.6 | |
| CVE-2026-34481 | Oracle Agile PLM MCAD Connector | CAX Client (Apache Log4j) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | High | None | 3.6 | |
| CVE-2022-40152 | Oracle Agile PLM MCAD Connector | CAX Client (Jackson dataformat XML) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.6 | |
| CVE-2022-40150 | Oracle Agile PLM MCAD Connector | CAX Client (Jettison) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 3.6 | |
| CVE-2026-70697 | Oracle Agile Engineering Data Management | Engineering Communication Interface | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71041 | Oracle Agile PLM | Gantt Chart | None | No | 7.0 | Local | High | Low | None | Un- changed |
High | High | High | 9.3.6 | |
| CVE-2026-70698 | Oracle Agile Engineering Data Management | Install | None | No | 6.7 | Local | Low | High | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71070 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | No | 6.5 | Network | Low | Low | None | Un- changed |
High | None | None | 3.6 | |
| CVE-2026-70712 | Oracle Agile Engineering Data Management | Install | None | No | 6.4 | Local | High | High | None | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-70693 | Oracle Agile Engineering Data Management | Engineering Communication Interface | None | No | 6.3 | Local | High | High | Required | Un- changed |
High | High | High | 6.2.1 | |
| CVE-2026-71075 | Oracle Agile PLM MCAD Connector | CAX Client | TLS | Yes | 5.9 | Adjacent Network |
High | None | None | Un- changed |
High | Low | None | 3.6 | |
| CVE-2026-71076 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.6 | |
| CVE-2026-71087 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 3.6 | |
| CVE-2026-71077 | Oracle Agile PLM MCAD Connector | CAX Client | HTTPS | Yes | 5.3 | Adjacent Network |
High | None | None | Un- changed |
High | None | None | 3.6 | |
| CVE-2026-70709 | Oracle Agile Engineering Data Management | Engineering Communication Interface | HTTP | Yes | 4.8 | Network | High | None | None | Un- changed |
Low | Low | None | 6.2.1 | |
| CVE-2026-71088 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | No | 4.8 | Network | High | Low | Required | Un- changed |
High | None | None | 3.6 | |
| CVE-2026-71071 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | No | 4.6 | Adjacent Network |
Low | Low | None | Un- changed |
Low | Low | None | 3.6 | |
| CVE-2026-71066 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 4.5 | Local | High | None | Required | Un- changed |
Low | Low | Low | 3.6 | |
| CVE-2026-71078 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 4.2 | Local | High | Low | Required | Un- changed |
Low | Low | Low | 3.6 | |
| CVE-2026-71080 | Oracle Agile PLM MCAD Connector | CAX Client | HTTP | Yes | 3.7 | Adjacent Network |
High | None | Required | Un- changed |
Low | Low | None | 3.6 | |
| CVE-2026-71072 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 3.3 | Local | Low | Low | None | Un- changed |
None | None | Low | 3.6 | |
| CVE-2026-71089 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 3.3 | Local | Low | None | Required | Un- changed |
Low | None | None | 3.6 | |
| CVE-2026-71082 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 2.5 | Local | High | Low | None | Un- changed |
Low | None | None | 3.6 | |
| CVE-2026-71081 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 1.9 | Local | High | High | None | Un- changed |
None | Low | None | 3.6 | |
| CVE-2026-71083 | Oracle Agile PLM MCAD Connector | CAX Client | None | No | 1.8 | Local | High | High | Required | Un- changed |
Low | None | None | 3.6 | |
This Critical Security Patch Update contains 21 new security patches for Oracle Virtualization. 2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req'd |
User Interact |
Scope | Confid- entiality |
Inte- grity |
Avail- ability |
|||||||
| CVE-2026-71131 | Oracle VM VirtualBox | Core | None | No | 8.6 | Local | Low | None | Required | Changed | High | High | High | 7.2.14 | |
| CVE-2026-71129 | Oracle VM VirtualBox | Core | None | No | 8.2 | Local | Low | High | None | Changed | High | High | High | 7.2.14 | |
| CVE-2026-71130 | Oracle VM VirtualBox | Core | RDP | Yes | 8.2 | Network | Low | None | None | Un- changed |
High | Low | None | 7.2.14 | |
| CVE-2026-71126 | Oracle VM VirtualBox | Core | None | No | 7.8 | Local | High | Low | None | Changed | High | High | High | 7.2.14 | |
| CVE-2026-71141 | Oracle VM VirtualBox | Core | None | No | 7.7 | Local | Low | None | Required | Changed | Low | High | Low | 7.2.14 | |
| CVE-2026-71116 | Oracle VM VirtualBox | Core | None | No | 7.5 | Local | High | High | None | Changed | High | High | High | 7.2.14 | |
| CVE-2026-71113 | Oracle VM VirtualBox | Core | RDP | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 7.2.14 | |
| CVE-2026-71136 | Oracle VM VirtualBox | Core | None | No | 7.3 | Local | Low | High | None | Changed | Low | Low | High | 7.2.14 | |
| CVE-2026-71138 | Oracle VM VirtualBox | Core | None | No | 7.3 | Local | Low | High | None | Changed | Low | Low | High | 7.2.14 | |
| CVE-2026-71125 | Oracle VM VirtualBox | Core | None | No | 6.1 | Local | Low | None | Required | Un- changed |
None | Low | High | 7.2.14 | |
| CVE-2026-71114 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | High | None | None | 7.2.14 | |
| CVE-2026-71115 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | High | None | None | 7.2.14 | |
| CVE-2026-71127 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.14 | |
| CVE-2026-71128 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.14 | |
| CVE-2026-71135 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.14 | |
| CVE-2026-71137 | Oracle VM VirtualBox | Core | None | No | 6.0 | Local | Low | High | None | Changed | None | None | High | 7.2.14 | |
| CVE-2026-71134 | Oracle VM VirtualBox | Core | None | No | 5.7 | Local | Low | High | None | Changed | Low | Low | Low | 7.2.14 | |
| CVE-2026-71151 | Oracle VM VirtualBox | Core | None | No | 5.6 | Local | High | Low | None | Changed | High | None | None | 7.2.14 | |
| CVE-2026-71132 | Oracle VM VirtualBox | Core | None | No | 5.3 | Local | High | High | None | Changed | High | None | None | 7.2.14 | |
| CVE-2026-71139 | Oracle VM VirtualBox | Core | None | No | 4.4 | Local | Low | High | None | Un- changed |
None | None | High | 7.2.14 | |
| CVE-2026-71140 | Oracle VM VirtualBox | Core | None | No | 3.4 | Local | Low | High | None | Un- changed |
Low | Low | None | 7.2.14 | |