Release roundup
Oracle Critical Patch Update, August 2026: one exploited Identity Manager flaw in 390 fixes
Oracle's August 2026 Critical Patch Update covers 390 CVEs: 84 critical and 247 high. CVE-2025-61757 in Oracle Identity Manager is actively exploited and in CISA KEV. Apply that first, then unauthenticated OID and WebCenter flaws, then the wider update.
The release at a glance
Oracle released the Critical Security Patch Update Advisory for August 2026, covering 390 CVEs in scope. The severity mix is 84 critical, 247 high, 56 medium and 3 low. Oracle Fusion Middleware accounts for 261 of the listed CVEs, followed by Oracle E-Business Suite with 120, Oracle Database Server with 5, and Oracle Java SE with 4.
One CVE is already in CISA KEV and assessed as active by CISA SSVC: CVE-2025-61757 in the Oracle Identity Manager REST WebServices component, published on 2025-10-21. The KEV due date is 2025-12-12. No other CVE in the release is listed as exploited.
What matters most
Oracle Identity Manager. CVE-2025-61757 is the priority. It is an unauthenticated HTTP flaw in REST WebServices affecting 12.2.1.4.0 and 14.1.2.1.0, with CVSS 9.8 and takeover of Identity Manager. CISA KEV and CISA SSVC both assess it as active, and its EPSS is 88.6. The KEV due date is 2025-12-12.
Two further Identity Manager flaws belong on the first pass: CVE-2026-60720 and CVE-2026-61066, both CVSS 9.9, affect OIM Legacy UI through HTTP and RMI respectively, require low privilege, and allow takeover of Identity Manager.
Oracle Internet Directory. CVE-2026-61241 is a CVSS 10.0 flaw. An unauthenticated attacker with network access via LDAP can take over Oracle Internet Directory; affected versions are 12.2.1.4.0 and 14.1.2.1.0. CVE-2026-61248 is an additional OID LDAP flaw requiring low privilege and rated CVSS 9.9.
Oracle WebLogic Server. CVE-2026-60702 is a CVSS 9.9 flaw reachable over T3 or IIOP by a low-privileged attacker, allowing takeover across affected versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Oracle WebCenter Enterprise Capture. CVE-2026-60916 is unauthenticated over HTTP and allows unauthorised data changes, partial read and partial denial of service.
Oracle Managed File Transfer. CVE-2026-61003 is a CVSS 9.9 low-privilege takeover flaw reachable over T3 or IIOP.
Patch in this order
- CVE-2025-61757 — Oracle Identity Manager (REST WebServices). Apply the vendor fix or mitigations first. CISA KEV and CISA SSVC rate it active; the KEV due date is 2025-12-12. Affected versions: 12.2.1.4.0, 14.1.2.1.0.
- CVE-2026-61241 — Oracle Internet Directory. Unauthenticated LDAP takeover with CVSS 10.0. Prioritise for any internet-facing OID LDAP server. Affected versions: 12.2.1.4.0, 14.1.2.1.0.
- CVE-2026-60916 — Oracle WebCenter Enterprise Capture. Unauthenticated HTTP with scope change. Prioritise if exposed. Affected versions: 12.2.1.4.0, 14.1.2.0.0.
- CVE-2026-60702 — Oracle WebLogic Server. Low-privilege T3/IIOP takeover; prioritise especially if T3/IIOP is exposed. Affected versions: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0.
- CVE-2026-61248 — Oracle Internet Directory; CVE-2026-60720 and CVE-2026-61066 — Oracle Identity Manager; CVE-2026-61003 — Oracle Managed File Transfer. Low-privilege takeover flaws rated CVSS 9.9. Apply after the unauthenticated items.
- Remaining Critical Patch Update. Complete the wider release: 84 critical and 247 high ratings among the 390 CVEs. Prioritise Fusion Middleware and E-Business Suite, then Database Server and Java SE.
Beyond the patch
A release this size is easier to handle next month if Oracle's exposure is already mapped. Virtual CISO Services (vCISO) helps identify internet-facing Oracle services, open T3/IIOP or LDAP ports, and middleware that does not need to be reachable. Where those products are already deployed, Implementation & Assessment Services provides penetration testing and hardening verification so a patch is confirmed to close the path rather than just being applied.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2025-61757 | Identity Manager | Critical 9.8 KEV | |
| CVE-2026-61241 | Oracle Internet Directory | Critical 10.0 | |
| CVE-2026-60702 | Oracle WebLogic Server | Critical 9.9 | |
| CVE-2026-60720 | Oracle Identity Manager | Critical 9.9 | |
| CVE-2026-60730 | Oracle WebCenter Portal | Critical 9.9 | |
| CVE-2026-60916 | Oracle WebCenter Enterprise Capture | Critical 9.9 | |
| CVE-2026-60990 | Oracle Identity Manager Connector | Critical 9.9 | |
| CVE-2026-60995 | Oracle Identity Manager Connector | Critical 9.9 | |
| CVE-2026-61003 | Oracle Managed File Transfer | Critical 9.9 | |
| CVE-2026-61021 | Oracle WebCenter Sites | Critical 9.9 | |
| CVE-2026-61066 | Oracle Identity Manager | Critical 9.9 | |
| CVE-2026-61248 | Oracle Internet Directory | Critical 9.9 | |
| CVE-2026-62608 | Oracle Reports Developer | Critical 9.9 | |
| CVE-2026-73930 | Helidon | Critical 9.9 | |
| CVE-2026-60672 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-60696 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-60698 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-60721 | Oracle Identity Manager | Critical 9.8 | |
| CVE-2026-60727 | Oracle Identity Manager | Critical 9.8 | |
| CVE-2026-60782 | Oracle Payments | Critical 9.8 | |
| CVE-2026-60921 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60946 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60947 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60958 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60970 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60971 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-60977 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-61018 | Oracle WebCenter Sites | Critical 9.8 | |
| CVE-2026-61258 | Oracle Internet Directory | Critical 9.8 | |
| CVE-2026-62609 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62611 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62614 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62617 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62621 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62622 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62624 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62626 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62630 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62632 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62633 | Oracle Reports Developer | Critical 9.8 |
Show all 390
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-62634 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62635 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62639 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-62640 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-70669 | Oracle Reports Developer | Critical 9.8 | |
| CVE-2026-70905 | Oracle Access Manager | Critical 9.8 | |
| CVE-2026-70926 | Oracle Workflow | Critical 9.8 | |
| CVE-2026-70970 | Oracle WebCenter Portal | Critical 9.8 | |
| CVE-2026-71074 | Helidon | Critical 9.8 | |
| CVE-2026-71152 | Helidon | Critical 9.8 | |
| CVE-2026-71164 | Helidon | Critical 9.8 | |
| CVE-2026-73905 | Helidon | Critical 9.8 | |
| CVE-2026-73912 | Helidon | Critical 9.8 | |
| CVE-2026-73921 | Helidon | Critical 9.8 | |
| CVE-2026-60861 | Service Delivery Platform | Critical 9.6 | |
| CVE-2026-60905 | Oracle WebCenter Content | Critical 9.6 | |
| CVE-2026-61001 | Oracle Web Services Manager | Critical 9.6 | |
| CVE-2026-70670 | Oracle Reports Developer | Critical 9.6 | |
| CVE-2026-71063 | Oracle Database Server | Critical 9.6 | |
| CVE-2026-71064 | Oracle Database Server | Critical 9.6 | |
| CVE-2026-62629 | Oracle Reports Developer | Critical 9.4 | |
| CVE-2026-71166 | Helidon | Critical 9.4 | |
| CVE-2026-71167 | Helidon | Critical 9.4 | |
| CVE-2026-73920 | Helidon | Critical 9.4 | |
| CVE-2026-62613 | Oracle Reports Developer | Critical 9.3 | |
| CVE-2026-62618 | Oracle Reports Developer | Critical 9.3 | |
| CVE-2026-62637 | Oracle Reports Developer | Critical 9.3 | |
| CVE-2026-70673 | Oracle Reports Developer | Critical 9.3 | |
| CVE-2026-71065 | Helidon | Critical 9.3 | |
| CVE-2026-60728 | Oracle WebCenter Portal | Critical 9.1 | |
| CVE-2026-60737 | Oracle Web Services Manager | Critical 9.1 | |
| CVE-2026-61008 | Oracle WebCenter Sites | Critical 9.1 | |
| CVE-2026-61034 | Oracle WebCenter Sites | Critical 9.1 | |
| CVE-2026-62610 | Oracle Reports Developer | Critical 9.1 | |
| CVE-2026-62638 | Oracle Reports Developer | Critical 9.1 | |
| CVE-2026-70668 | Oracle Reports Developer | Critical 9.1 | |
| CVE-2026-71102 | Oracle Database Server | Critical 9.1 | |
| CVE-2026-73865 | Helidon | Critical 9.1 | |
| CVE-2026-73866 | Helidon | Critical 9.1 | |
| CVE-2026-73916 | Helidon | Critical 9.1 | |
| CVE-2026-73917 | Helidon | Critical 9.1 | |
| CVE-2026-73922 | Helidon | Critical 9.1 | |
| CVE-2026-73924 | Helidon | Critical 9.1 | |
| CVE-2026-61029 | Oracle WebCenter Sites | Critical 9.0 | |
| CVE-2026-60715 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-60716 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-60722 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-60726 | Oracle Access Manager | High 8.8 | |
| CVE-2026-60729 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-60731 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-60976 | Oracle Scripting | High 8.8 | |
| CVE-2026-61002 | Oracle SOA Suite | High 8.8 | |
| CVE-2026-61017 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61022 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61032 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61040 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61042 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61058 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-61118 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-61213 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-61231 | Oracle Virtual Directory | High 8.8 | |
| CVE-2026-61319 | Oracle U.S. Federal Financials | High 8.8 | |
| CVE-2026-62450 | Oracle Flow Manufacturing | High 8.8 | |
| CVE-2026-62462 | Oracle Work in Process | High 8.8 | |
| CVE-2026-62612 | Oracle Reports Developer | High 8.8 | |
| CVE-2026-62619 | Oracle Reports Developer | High 8.8 | |
| CVE-2026-62623 | Oracle Reports Developer | High 8.8 | |
| CVE-2026-62631 | Oracle Reports Developer | High 8.8 | |
| CVE-2026-70674 | Oracle Reports Developer | High 8.8 | |
| CVE-2026-70686 | Oracle General Ledger | High 8.8 | |
| CVE-2026-70707 | Oracle Sales for Handhelds | High 8.8 | |
| CVE-2026-70710 | Oracle Sales Foundation | High 8.8 | |
| CVE-2026-70729 | Oracle Teleservice | High 8.8 | |
| CVE-2026-70747 | Oracle Customers Online | High 8.8 | |
| CVE-2026-70761 | Oracle Risk Management | High 8.8 | |
| CVE-2026-70792 | Oracle Yard Management | High 8.8 | |
| CVE-2026-70812 | Oracle Call Center Technology | High 8.8 | |
| CVE-2026-70813 | Oracle Call Center Technology | High 8.8 | |
| CVE-2026-70918 | Oracle Product Hub | High 8.8 | |
| CVE-2026-70948 | Oracle Purchasing | High 8.8 | |
| CVE-2026-70941 | Oracle Payroll | High 8.8 | |
| CVE-2026-60707 | Oracle Identity Manager | High 8.7 | |
| CVE-2026-60860 | Service Delivery Platform | High 8.7 | |
| CVE-2026-60903 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60934 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60935 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60954 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60980 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60981 | Oracle WebCenter Content | High 8.7 | |
| CVE-2026-60996 | Oracle Identity Manager Connector | High 8.7 | |
| CVE-2026-61193 | Oracle WebCenter Portal | High 8.7 | |
| CVE-2026-61215 | Oracle WebCenter Portal | High 8.7 | |
| CVE-2026-61219 | Oracle WebCenter Portal | High 8.7 | |
| CVE-2026-62607 | Oracle Customer Care | High 8.7 | |
| CVE-2026-70778 | Oracle Customer Care | High 8.7 | |
| CVE-2026-60699 | Oracle WebLogic Server | High 8.6 | |
| CVE-2026-61033 | Oracle WebCenter Sites | High 8.6 | |
| CVE-2026-61045 | Oracle WebCenter Sites | High 8.6 | |
| CVE-2026-61228 | Oracle WebCenter Portal | High 8.6 | |
| CVE-2026-61230 | Oracle WebCenter Portal | High 8.6 | |
| CVE-2026-62599 | Oracle Trading Community | High 8.6 | |
| CVE-2026-62620 | Oracle Reports Developer | High 8.6 | |
| CVE-2026-62625 | Oracle Reports Developer | High 8.6 | |
| CVE-2026-62628 | Oracle Reports Developer | High 8.6 | |
| CVE-2026-62636 | Oracle Reports Developer | High 8.6 | |
| CVE-2026-73939 | Helidon | High 8.6 | |
| CVE-2026-60841 | Oracle Unified Directory | High 8.5 | |
| CVE-2026-60849 | Oracle Unified Directory | High 8.5 | |
| CVE-2026-61212 | Oracle WebCenter Portal | High 8.5 | |
| CVE-2026-62615 | Oracle Reports Developer | High 8.5 | |
| CVE-2026-70718 | Oracle Bills of Material | High 8.5 | |
| CVE-2026-70807 | Oracle Call Center Technology | High 8.5 | |
| CVE-2026-71062 | Oracle Database Server | High 8.5 | |
| CVE-2026-71155 | Helidon | High 8.5 | |
| CVE-2026-60928 | Oracle WebCenter Content | High 8.4 | |
| CVE-2026-70770 | Oracle Warehouse Management | High 8.3 | |
| CVE-2026-73929 | Helidon | High 8.3 | |
| CVE-2026-73931 | Helidon | High 8.3 | |
| CVE-2026-60944 | Oracle WebCenter Content | High 8.2 | |
| CVE-2026-60955 | Oracle WebCenter Content | High 8.2 | |
| CVE-2026-61011 | Oracle WebCenter Sites | High 8.2 | |
| CVE-2026-61016 | Oracle WebCenter Sites | High 8.2 | |
| CVE-2026-61038 | Oracle WebCenter Sites | High 8.2 | |
| CVE-2026-61054 | Oracle WebCenter Sites | High 8.2 | |
| CVE-2026-61222 | Oracle WebCenter Portal | High 8.2 | |
| CVE-2026-61340 | Oracle MES for Process Manufacturing | High 8.2 | |
| CVE-2026-62448 | Oracle Email Center | High 8.2 | |
| CVE-2026-62605 | Oracle Partner Management | High 8.2 | |
| CVE-2026-70702 | Oracle Payments | High 8.2 | |
| CVE-2026-70722 | Oracle Advanced Inbound Telephony | High 8.2 | |
| CVE-2026-70773 | Oracle HCM Common Architecture | High 8.2 | |
| CVE-2026-71159 | Helidon | High 8.2 | |
| CVE-2026-73925 | Helidon | High 8.2 | |
| CVE-2026-73937 | Helidon | High 8.2 | |
| CVE-2026-60415 | Oracle WebLogic Server | High 8.1 | |
| CVE-2026-60680 | Oracle WebLogic Server | High 8.1 | |
| CVE-2026-60992 | Oracle Identity Manager Connector | High 8.1 | |
| CVE-2026-61177 | Oracle WebCenter Portal | High 8.1 | |
| CVE-2026-61229 | Oracle WebCenter Portal | High 8.1 | |
| CVE-2026-62491 | Oracle Purchasing | High 8.1 | |
| CVE-2026-62600 | Oracle Sales | High 8.1 | |
| CVE-2026-70671 | Oracle Reports Developer | High 8.1 | |
| CVE-2026-70675 | Oracle Reports Developer | High 8.1 | |
| CVE-2026-70701 | Oracle Payables | High 8.1 | |
| CVE-2026-70704 | Oracle Trading Community | High 8.1 | |
| CVE-2026-70708 | Oracle Sales Foundation | High 8.1 | |
| CVE-2026-70762 | Oracle Risk Management | High 8.1 | |
| CVE-2026-70782 | Oracle Labor Distribution | High 8.1 | |
| CVE-2026-70795 | Oracle Applications Platform Engineering | High 8.1 | |
| CVE-2026-70805 | Oracle Project Planning and Control | High 8.1 | |
| CVE-2026-70811 | Oracle Purchasing | High 8.1 | |
| CVE-2026-70814 | Oracle Call Center Technology | High 8.1 | |
| CVE-2026-70815 | Oracle Internet Procurement Connector | High 8.1 | |
| CVE-2026-70830 | Oracle Process Manufacturing Systems | High 8.1 | |
| CVE-2026-70835 | Oracle iRecruitment | High 8.1 | |
| CVE-2026-70924 | Oracle Web Services Manager | High 8.1 | |
| CVE-2026-70931 | Oracle Workflow | High 8.1 | |
| CVE-2026-71110 | Helidon | High 8.1 | |
| CVE-2026-60961 | Oracle WebCenter Content | High 8.0 | |
| CVE-2026-60998 | Oracle Identity Manager Connector | High 8.0 | |
| CVE-2026-70690 | Oracle HRMS (US) | High 8.0 | |
| CVE-2026-70802 | Oracle Public Sector Human Resources | High 8.0 | |
| CVE-2026-60392 | Oracle Outside In Technology | High 7.8 | |
| CVE-2026-60412 | Oracle Outside In Technology | High 7.8 | |
| CVE-2026-60413 | Oracle Outside In Technology | High 7.8 | |
| CVE-2026-60414 | Oracle Outside In Technology | High 7.8 | |
| CVE-2026-60991 | Oracle Identity Manager Connector | High 7.8 | |
| CVE-2026-61291 | Oracle WebCenter Content | High 7.8 | |
| CVE-2026-70798 | Oracle Purchasing | High 7.8 | |
| CVE-2026-71101 | Oracle HRMS (US) | High 7.8 | |
| CVE-2026-71111 | Oracle Identity Manager | High 7.8 | |
| CVE-2026-60733 | Oracle WebCenter Portal | High 7.7 | |
| CVE-2026-60969 | Oracle Unified Directory | High 7.7 | |
| CVE-2026-60983 | Oracle WebCenter Content | High 7.7 | |
| CVE-2026-61199 | Oracle WebCenter Portal | High 7.7 | |
| CVE-2026-61331 | Oracle Financials Common Modules | High 7.7 | |
| CVE-2026-70687 | Oracle Marketing | High 7.7 | |
| CVE-2026-70692 | Oracle Marketing Encyclopedia System | High 7.7 | |
| CVE-2026-70694 | Oracle Payments | High 7.7 | |
| CVE-2026-70695 | Oracle Payments | High 7.7 | |
| CVE-2026-70771 | Oracle Warehouse Management | High 7.7 | |
| CVE-2026-70804 | Oracle Public Sector Human Resources | High 7.7 | |
| CVE-2026-70827 | Oracle MES for Process Manufacturing | High 7.7 | |
| CVE-2026-70945 | Oracle Payroll | High 7.7 | |
| CVE-2026-60748 | Oracle General Ledger | High 7.6 | |
| CVE-2026-60909 | Oracle WebCenter Content | High 7.6 | |
| CVE-2026-61208 | Oracle WebCenter Portal | High 7.6 | |
| CVE-2026-61227 | Oracle WebCenter Portal | High 7.6 | |
| CVE-2026-61296 | Oracle Enterprise Asset Management | High 7.6 | |
| CVE-2026-70725 | Oracle Advanced Inbound Telephony | High 7.6 | |
| CVE-2026-70764 | Oracle General Ledger | High 7.6 | |
| CVE-2026-70786 | Oracle Service Fulfillment Manager | High 7.6 | |
| CVE-2026-70791 | Oracle Transportation Execution | High 7.6 | |
| CVE-2026-70803 | Oracle General Ledger | High 7.6 | |
| CVE-2026-60679 | Oracle WebLogic Server | High 7.5 | |
| CVE-2026-60769 | Oracle General Ledger | High 7.5 | |
| CVE-2026-60850 | Oracle Unified Directory | High 7.5 | |
| CVE-2026-60889 | Oracle Unified Directory | High 7.5 | |
| CVE-2026-60906 | Oracle WebCenter Content | High 7.5 | |
| CVE-2026-60914 | Oracle Unified Directory | High 7.5 | |
| CVE-2026-60993 | Oracle Identity Manager Connector | High 7.5 | |
| CVE-2026-61007 | Oracle WebCenter Sites | High 7.5 | |
| CVE-2026-70681 | Oracle Applications DBA | High 7.5 | |
| CVE-2026-70696 | Oracle Payments | High 7.5 | |
| CVE-2026-70700 | Oracle Payables | High 7.5 | |
| CVE-2026-70706 | Oracle Sales | High 7.5 | |
| CVE-2026-70713 | Oracle iSetup | High 7.5 | |
| CVE-2026-70763 | Oracle Operations Intelligence | High 7.5 | |
| CVE-2026-70772 | Oracle Warehouse Management | High 7.5 | |
| CVE-2026-70777 | Oracle iSupplier Portal | High 7.5 | |
| CVE-2026-70799 | Oracle SDP Number Portability | High 7.5 | |
| CVE-2026-70810 | Oracle Scripting | High 7.5 | |
| CVE-2026-70829 | Oracle Process Manufacturing Systems | High 7.5 | |
| CVE-2026-70906 | Oracle Java SE | High 7.5 | |
| CVE-2026-70908 | Helidon | High 7.5 | |
| CVE-2026-70927 | Oracle Workflow | High 7.5 | |
| CVE-2026-70930 | Oracle Order Management | High 7.5 | |
| CVE-2026-70947 | Oracle Purchasing | High 7.5 | |
| CVE-2026-71153 | Helidon | High 7.5 | |
| CVE-2026-71158 | Helidon | High 7.5 | |
| CVE-2026-71160 | Helidon | High 7.5 | |
| CVE-2026-73878 | Helidon | High 7.5 | |
| CVE-2026-73879 | Helidon | High 7.5 | |
| CVE-2026-73882 | Helidon | High 7.5 | |
| CVE-2026-73883 | Helidon | High 7.5 | |
| CVE-2026-73884 | Helidon | High 7.5 | |
| CVE-2026-73887 | Helidon | High 7.5 | |
| CVE-2026-73890 | Helidon | High 7.5 | |
| CVE-2026-73902 | Helidon | High 7.5 | |
| CVE-2026-73903 | Helidon | High 7.5 | |
| CVE-2026-73907 | Helidon | High 7.5 | |
| CVE-2026-73908 | Helidon | High 7.5 | |
| CVE-2026-73915 | Helidon | High 7.5 | |
| CVE-2026-73927 | Helidon | High 7.5 | |
| CVE-2026-73934 | Helidon | High 7.5 | |
| CVE-2026-73935 | Helidon | High 7.5 | |
| CVE-2026-73936 | Helidon | High 7.5 | |
| CVE-2026-73938 | Helidon | High 7.5 | |
| CVE-2026-60759 | Oracle Internet Procurement Connector | High 7.4 | |
| CVE-2026-60915 | Helidon | High 7.4 | |
| CVE-2026-60933 | Oracle WebCenter Content | High 7.4 | |
| CVE-2026-70672 | Oracle Reports Developer | High 7.4 | |
| CVE-2026-70699 | Oracle Payments | High 7.4 | |
| CVE-2026-70779 | Oracle iSupplier Portal | High 7.4 | |
| CVE-2026-70783 | Oracle Service Contracts | High 7.4 | |
| CVE-2026-70790 | Oracle Telecommunications Billing Integrator | High 7.4 | |
| CVE-2026-73891 | Helidon | High 7.3 | |
| CVE-2026-73894 | Helidon | High 7.3 | |
| CVE-2026-73918 | Helidon | High 7.3 | |
| CVE-2026-73933 | Helidon | High 7.3 | |
| CVE-2026-70800 | Oracle SDP Number Portability | High 7.3 | |
| CVE-2026-62540 | Oracle Cost Management | High 7.2 | |
| CVE-2026-62616 | Oracle Reports Developer | High 7.2 | |
| CVE-2026-70781 | Oracle Proposals | High 7.2 | |
| CVE-2026-70797 | Oracle Purchasing | High 7.2 | |
| CVE-2026-70820 | Oracle Call Center Technology | High 7.2 | |
| CVE-2026-71104 | Oracle HRMS (Netherlands) | High 7.2 | |
| CVE-2026-73875 | Helidon | High 7.2 | |
| CVE-2026-73876 | Helidon | High 7.2 | |
| CVE-2026-73885 | Helidon | High 7.2 | |
| CVE-2026-73886 | Helidon | High 7.2 | |
| CVE-2026-73928 | Helidon | High 7.2 | |
| CVE-2026-60994 | Oracle Identity Manager Connector | High 7.2 | |
| CVE-2026-70796 | Oracle General Ledger | High 7.2 | |
| CVE-2026-70932 | Oracle Order Management | High 7.2 | |
| CVE-2026-60693 | Oracle General Ledger | High 7.1 | |
| CVE-2026-60781 | Oracle Payments | High 7.1 | |
| CVE-2026-60949 | Oracle WebCenter Content | High 7.1 | |
| CVE-2026-61124 | Oracle WebCenter Portal | High 7.1 | |
| CVE-2026-61288 | Oracle WebCenter Content | High 7.1 | |
| CVE-2026-61290 | Oracle WebCenter Content | High 7.1 | |
| CVE-2026-61295 | Oracle WebCenter Content | High 7.1 | |
| CVE-2026-61306 | Oracle Complex Maintenance, Repair and Overhaul | High 7.1 | |
| CVE-2026-62458 | Oracle Work in Process | High 7.1 | |
| CVE-2026-62601 | Oracle Sales | High 7.1 | |
| CVE-2026-62627 | Oracle Reports Developer | High 7.1 | |
| CVE-2026-70680 | Oracle Applications DBA | High 7.1 | |
| CVE-2026-70760 | Oracle Order Management | High 7.1 | |
| CVE-2026-70774 | Oracle Warehouse Management | High 7.1 | |
| CVE-2026-70801 | Oracle Flow Manufacturing | High 7.1 | |
| CVE-2026-70808 | Oracle Scripting | High 7.1 | |
| CVE-2026-70809 | Oracle Scripting | High 7.1 | |
| CVE-2026-70816 | Oracle Financials for EMEA | High 7.1 | |
| CVE-2026-70833 | Oracle Landed Cost Management | High 7.1 | |
| CVE-2026-70837 | Oracle Financials for Asia/Pacific | High 7.1 | |
| CVE-2026-70839 | Oracle Financials for EMEA | High 7.1 | |
| CVE-2026-70844 | Oracle Loans | High 7.1 | |
| CVE-2026-70845 | Oracle Loans | High 7.1 | |
| CVE-2026-70858 | Oracle WebCenter Content | High 7.1 | |
| CVE-2026-70806 | Oracle E-Business Tax | High 7.1 | |
| CVE-2026-62449 | Oracle Work in Process | High 7.0 | |
| CVE-2026-60865 | Service Delivery Platform | Medium 6.8 | |
| CVE-2026-60895 | Oracle Unified Directory | Medium 6.8 | |
| CVE-2026-61308 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Medium 6.8 | |
| CVE-2026-71029 | Helidon | Medium 6.8 | |
| CVE-2026-62475 | Oracle Shipping Execution | Medium 6.6 | |
| CVE-2026-60830 | Oracle Workflow | Medium 6.5 | |
| CVE-2026-60866 | Service Delivery Platform | Medium 6.5 | |
| CVE-2026-61198 | Oracle Learning Management | Medium 6.5 | |
| CVE-2026-70720 | Oracle Production Scheduling | Medium 6.5 | |
| CVE-2026-70732 | Oracle Mobile Application Server | Medium 6.5 | |
| CVE-2026-71162 | Helidon | Medium 6.5 | |
| CVE-2026-73867 | Helidon | Medium 6.5 | |
| CVE-2026-73868 | Helidon | Medium 6.5 | |
| CVE-2026-73892 | Helidon | Medium 6.5 | |
| CVE-2026-73893 | Helidon | Medium 6.5 | |
| CVE-2026-73896 | Helidon | Medium 6.5 | |
| CVE-2026-73897 | Helidon | Medium 6.5 | |
| CVE-2026-73904 | Helidon | Medium 6.5 | |
| CVE-2026-73914 | Helidon | Medium 6.5 | |
| CVE-2026-61139 | Oracle Public Sector Financials (International) | Medium 6.3 | |
| CVE-2026-70775 | Oracle Installed Base | Medium 6.3 | |
| CVE-2026-70923 | Helidon | Medium 6.1 | |
| CVE-2026-73869 | Helidon | Medium 6.1 | |
| CVE-2026-73870 | Helidon | Medium 6.1 | |
| CVE-2026-73898 | Helidon | Medium 6.1 | |
| CVE-2026-71154 | Helidon | Medium 6.1 | |
| CVE-2026-70726 | Oracle Cash Management | Medium 6.0 | |
| CVE-2026-70716 | Helidon | Medium 5.9 | |
| CVE-2026-73909 | Helidon | Medium 5.9 | |
| CVE-2026-71165 | Helidon | Medium 5.4 | |
| CVE-2026-73874 | Helidon | Medium 5.4 | |
| CVE-2026-73881 | Helidon | Medium 5.4 | |
| CVE-2026-73911 | Helidon | Medium 5.4 | |
| CVE-2026-73913 | Helidon | Medium 5.4 | |
| CVE-2026-73919 | Helidon | Medium 5.4 | |
| CVE-2026-70727 | Helidon | Medium 5.3 | |
| CVE-2026-70907 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Medium 5.3 | |
| CVE-2026-71100 | Oracle Database Server | Medium 5.3 | |
| CVE-2026-71156 | Helidon | Medium 5.3 | |
| CVE-2026-71157 | Helidon | Medium 5.3 | |
| CVE-2026-71161 | Helidon | Medium 5.3 | |
| CVE-2026-73871 | Helidon | Medium 5.3 | |
| CVE-2026-73872 | Helidon | Medium 5.3 | |
| CVE-2026-73877 | Helidon | Medium 5.3 | |
| CVE-2026-73888 | Helidon | Medium 5.3 | |
| CVE-2026-73889 | Helidon | Medium 5.3 | |
| CVE-2026-73895 | Helidon | Medium 5.3 | |
| CVE-2026-73899 | Helidon | Medium 5.3 | |
| CVE-2026-73900 | Helidon | Medium 5.3 | |
| CVE-2026-73906 | Helidon | Medium 5.3 | |
| CVE-2026-73910 | Helidon | Medium 5.3 | |
| CVE-2026-73932 | Helidon | Medium 5.3 | |
| CVE-2026-73901 | Helidon | Medium 4.8 | |
| CVE-2026-73880 | Helidon | Medium 4.4 | |
| CVE-2026-71124 | Oracle Access Manager | Medium 4.3 | |
| CVE-2026-73873 | Helidon | Medium 4.2 | |
| CVE-2026-60589 | Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition | Low 3.7 | |
| CVE-2026-60853 | Helidon | Low 3.7 | |
| CVE-2026-73923 | Helidon | Low 3.7 |
References
Other
CVE
- CVE-2025-61757 — cve.org
- CVE-2025-61757 — NVD
- CVE-2026-61241 — cve.org
- CVE-2026-61241 — NVD
- CVE-2026-60702 — cve.org
- CVE-2026-60702 — NVD
- CVE-2026-60720 — cve.org
- CVE-2026-60720 — NVD
- CVE-2026-60730 — cve.org
- CVE-2026-60730 — NVD
- CVE-2026-60916 — cve.org
- CVE-2026-60916 — NVD
- CVE-2026-60990 — cve.org
- CVE-2026-60990 — NVD
- CVE-2026-60995 — cve.org
- CVE-2026-60995 — NVD
- CVE-2026-61003 — cve.org
- CVE-2026-61003 — NVD
- CVE-2026-61021 — cve.org
- CVE-2026-61021 — NVD
- CVE-2026-61066 — cve.org
- CVE-2026-61066 — NVD
- CVE-2026-61248 — cve.org
- CVE-2026-61248 — NVD