Release roundup
Oracle Critical Security Patch Update Advisory, September 2026: unauthenticated Fusion Middleware flaws lead 330 fixes
Oracle's September 2026 Critical Patch Update covers 330 CVEs: 69 critical, 234 high, 24 medium and 3 low. No CVEs are recorded as exploited or in CISA KEV. Unauthenticated Fusion Middleware flaws, several scored 10.0, warrant priority.
The release at a glance
The Oracle Critical Security Patch Update Advisory - September 2026 spans 330 CVEs across Oracle's products. The severity mix is 69 critical, 234 high, 24 medium and 3 low. Oracle E-Business Suite accounts for 159 of the CVEs, Oracle Fusion Middleware for 152, Oracle Database Server for 11, Oracle Java SE for 6, Oracle Enterprise Manager for 1 and Oracle Analytics for 1. No CVE in this release is recorded as exploited in the wild or listed in CISA KEV.
Among the highest-scoring issues, Oracle Access Manager, Oracle Platform Security for Java, Oracle WebLogic Server, Oracle Internet Directory and Oracle Forms each carry a CVSS 3.1 score of 10.0 and are reachable over the network without credentials. Several further items in Oracle Access Manager, WebCenter Portal, WebCenter Sites and Service Delivery Platform score 9.9 and require only low privileges.
What matters most
Oracle Access Manager has the sharpest items. CVE-2026-71133 is an unauthenticated HTTP issue in the Authentication Engine; Oracle rates it 10.0, with scope change and takeover of the product. CVE-2026-73945 is a lower-privilege issue, also in the Authentication Engine, scoring 9.9 and allowing takeover. Oracle Platform Security for Java CVE-2026-83020 is an unauthenticated HTTP issue in Centralized Thirdparty Jars, scored 10.0. Oracle WebLogic Server CVE-2026-83021 affects the Web Container, is unauthenticated over HTTP, scores 10.0 and allows takeover. Oracle Internet Directory CVE-2026-83059 is an unauthenticated LDAP issue in the OID LDAP Server, also scored 10.0. Oracle Forms CVE-2026-83099 is an unauthenticated HTTP issue in Forms Services, C/S, Charmode, also scored 10.0. Oracle WebCenter Portal CVE-2026-73948 is a low-privilege HTTP issue in Composer, scoring 9.9. Service Delivery Platform CVE-2026-82997 is a low-privilege T3/IIOP issue in Messaging Enabler, scoring 9.9. These matter first because they combine network access, low or no privileges, and Oracle's 'easily exploitable' assessment.
Patch in this order
- Patch the unauthenticated network-facing Fusion Middleware components first: Oracle Access Manager CVE-2026-71133, Oracle Platform Security for Java CVE-2026-83020, Oracle WebLogic Server CVE-2026-83021, Oracle Internet Directory CVE-2026-83059 and Oracle Forms CVE-2026-83099. They score 10.0, require no credentials, and Oracle describes them as easily exploitable.
- Patch the low-privileged Fusion Middleware items next: Oracle Access Manager CVE-2026-71163 and CVE-2026-73945, Oracle WebCenter Portal CVE-2026-73948, Service Delivery Platform CVE-2026-82997, CVE-2026-82998 and CVE-2026-82999, and Oracle WebCenter Sites CVE-2026-83031. These score 9.9 and require only low privileges.
- Continue with the remaining Oracle Fusion Middleware and Oracle E-Business Suite updates, prioritising internet-facing E-Business Suite modules and any Fusion Middleware components reachable from untrusted networks.
- Move to Oracle Database Server, Oracle Java SE, Oracle Enterprise Manager and Oracle Analytics according to your normal patch cycle.
Because no CVE in this release is in CISA KEV, there is no CISA due date to schedule around; the priority is exposure and Oracle's rating.
Beyond the patch
This release is defined by network-reachable, low-or-no-privilege Fusion Middleware flaws, which makes it a strong case for continuous exposure management rather than a quarterly scramble. Virtual CISO Services can help you keep internet-facing Oracle services visible and prioritised, and Implementation & Assessment Services can test the authentication and access-control boundaries in Access Manager, WebLogic Server and related components before the next CPU lands.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-71133 | Oracle Access Manager | Critical 10.0 | |
| CVE-2026-83020 | Oracle Platform Security for Java | Critical 10.0 | |
| CVE-2026-83021 | Oracle WebLogic Server | Critical 10.0 | |
| CVE-2026-83059 | Oracle Internet Directory | Critical 10.0 | |
| CVE-2026-83099 | Oracle Forms | Critical 10.0 | |
| CVE-2026-71163 | Oracle Access Manager | Critical 9.9 | |
| CVE-2026-73945 | Oracle Access Manager | Critical 9.9 | |
| CVE-2026-73948 | Oracle WebCenter Portal | Critical 9.9 | |
| CVE-2026-82997 | Service Delivery Platform | Critical 9.9 | |
| CVE-2026-82998 | Service Delivery Platform | Critical 9.9 | |
| CVE-2026-82999 | Service Delivery Platform | Critical 9.9 | |
| CVE-2026-83031 | Oracle WebCenter Sites | Critical 9.9 | |
| CVE-2026-83038 | Oracle WebLogic Server | Critical 9.9 | |
| CVE-2026-83039 | Oracle WebCenter Portal | Critical 9.9 | |
| CVE-2026-83055 | Oracle Internet Directory | Critical 9.9 | |
| CVE-2026-83056 | Oracle Internet Directory | Critical 9.9 | |
| CVE-2026-83057 | Oracle Internet Directory | Critical 9.9 | |
| CVE-2026-83058 | Oracle Internet Directory | Critical 9.9 | |
| CVE-2026-70748 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-70756 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-70757 | Oracle WebLogic Server | Critical 9.8 | |
| CVE-2026-70913 | Oracle Identity Manager | Critical 9.8 | |
| CVE-2026-73940 | Oracle Access Manager | Critical 9.8 | |
| CVE-2026-73947 | Oracle Access Manager | Critical 9.8 | |
| CVE-2026-73950 | Oracle Access Manager | Critical 9.8 | |
| CVE-2026-73953 | Oracle WebCenter Portal | Critical 9.8 | |
| CVE-2026-73956 | Oracle WebCenter Portal | Critical 9.8 | |
| CVE-2026-73961 | Oracle JDeveloper | Critical 9.8 | |
| CVE-2026-73963 | Oracle WebCenter Portal | Critical 9.8 | |
| CVE-2026-82994 | Oracle Platform Security for Java | Critical 9.8 | |
| CVE-2026-82995 | Oracle Platform Security for Java | Critical 9.8 | |
| CVE-2026-83000 | Service Delivery Platform | Critical 9.8 | |
| CVE-2026-83035 | Oracle WebCenter Sites | Critical 9.8 | |
| CVE-2026-83036 | Oracle WebCenter Sites | Critical 9.8 | |
| CVE-2026-83037 | Oracle WebCenter Sites | Critical 9.8 | |
| CVE-2026-83042 | Oracle Identity Manager | Critical 9.8 | |
| CVE-2026-83054 | Oracle Internet Directory | Critical 9.8 | |
| CVE-2026-83060 | Oracle Internet Directory | Critical 9.8 | |
| CVE-2026-83061 | Oracle Internet Directory | Critical 9.8 | |
| CVE-2026-83062 | Oracle Internet Directory | Critical 9.8 |
Show all 330
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-83066 | Oracle Internet Directory | Critical 9.8 | |
| CVE-2026-83094 | Oracle Forms | Critical 9.8 | |
| CVE-2026-83095 | Oracle Forms | Critical 9.8 | |
| CVE-2026-83098 | Oracle Forms | Critical 9.8 | |
| CVE-2026-83100 | Oracle Forms | Critical 9.8 | |
| CVE-2026-83108 | Oracle Forms | Critical 9.8 | |
| CVE-2026-83151 | Service Delivery Platform | Critical 9.8 | |
| CVE-2026-83232 | Oracle Data Integrator | Critical 9.8 | |
| CVE-2026-83327 | Oracle Applications Framework | Critical 9.8 | |
| CVE-2026-83339 | Oracle WebCenter Enterprise Capture | Critical 9.8 | |
| CVE-2026-83355 | Oracle Enterprise Manager for Fusion Middleware | Critical 9.8 | |
| CVE-2026-83452 | Oracle Document Management and Collaboration | Critical 9.8 | |
| CVE-2026-83462 | Oracle Mobile Application Server | Critical 9.8 | |
| CVE-2026-73962 | Oracle Access Manager | Critical 9.6 | |
| CVE-2026-83029 | Oracle Managed File Transfer | Critical 9.6 | |
| CVE-2026-83040 | Oracle WebCenter Portal | Critical 9.6 | |
| CVE-2026-83043 | Oracle WebCenter Portal | Critical 9.6 | |
| CVE-2026-73957 | Oracle WebCenter Portal | Critical 9.3 | |
| CVE-2026-83027 | Oracle Identity Manager Connector | Critical 9.3 | |
| CVE-2026-73944 | Oracle Access Manager | Critical 9.1 | |
| CVE-2026-73946 | Oracle Access Manager | Critical 9.1 | |
| CVE-2026-73952 | Oracle WebCenter Portal | Critical 9.1 | |
| CVE-2026-83001 | Oracle Access Manager | Critical 9.1 | |
| CVE-2026-83006 | Oracle WebCenter Enterprise Capture | Critical 9.1 | |
| CVE-2026-83064 | Oracle WebCenter Portal | Critical 9.1 | |
| CVE-2026-83103 | Oracle Forms | Critical 9.1 | |
| CVE-2026-83104 | Oracle Forms | Critical 9.1 | |
| CVE-2026-83107 | Oracle Forms | Critical 9.1 | |
| CVE-2026-83105 | Oracle Forms | Critical 9.0 | |
| CVE-2026-70915 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-71047 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-73942 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-73949 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-73959 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-83005 | Oracle WebCenter Enterprise Capture | High 8.8 | |
| CVE-2026-83008 | Oracle WebCenter Enterprise Capture | High 8.8 | |
| CVE-2026-83009 | Oracle WebCenter Enterprise Capture | High 8.8 | |
| CVE-2026-83013 | Oracle WebCenter Enterprise Capture | High 8.8 | |
| CVE-2026-83032 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-83033 | Oracle WebCenter Sites | High 8.8 | |
| CVE-2026-83053 | Oracle WebCenter Portal | High 8.8 | |
| CVE-2026-83069 | Oracle Fusion Middleware Control | High 8.8 | |
| CVE-2026-83090 | Oracle Spares Management | High 8.8 | |
| CVE-2026-83119 | Oracle User Management | High 8.8 | |
| CVE-2026-83120 | Oracle Alert | High 8.8 | |
| CVE-2026-83121 | Oracle Marketing | High 8.8 | |
| CVE-2026-83122 | Oracle Report Manager | High 8.8 | |
| CVE-2026-83124 | Oracle Sales Online | High 8.8 | |
| CVE-2026-83125 | Oracle Report Manager | High 8.8 | |
| CVE-2026-83136 | Oracle Spares Management | High 8.8 | |
| CVE-2026-83137 | Oracle Spares Management | High 8.8 | |
| CVE-2026-83160 | Oracle Database Server | High 8.8 | |
| CVE-2026-83163 | Oracle Application Object Library | High 8.8 | |
| CVE-2026-83164 | Oracle Customer Interaction History | High 8.8 | |
| CVE-2026-83165 | Oracle Customer Interaction History | High 8.8 | |
| CVE-2026-83168 | Oracle Applications Manager | High 8.8 | |
| CVE-2026-83189 | Oracle User Management | High 8.8 | |
| CVE-2026-83194 | Oracle Depot Repair | High 8.8 | |
| CVE-2026-83205 | Oracle Applications Framework | High 8.8 | |
| CVE-2026-83271 | Oracle Database Server | High 8.8 | |
| CVE-2026-83306 | Oracle JDeveloper | High 8.8 | |
| CVE-2026-83329 | Oracle Applications Framework | High 8.8 | |
| CVE-2026-83331 | Oracle Applications Framework | High 8.8 | |
| CVE-2026-83338 | Oracle Applications Manager | High 8.8 | |
| CVE-2026-83340 | Oracle Identity Manager | High 8.8 | |
| CVE-2026-83348 | Oracle Database Server | High 8.8 | |
| CVE-2026-83410 | Oracle Coherence | High 8.8 | |
| CVE-2026-83411 | Oracle Coherence | High 8.8 | |
| CVE-2026-83423 | Oracle JDeveloper | High 8.8 | |
| CVE-2026-83444 | Oracle Product Hub | High 8.8 | |
| CVE-2026-83445 | Oracle Complex Maintenance, Repair and Overhaul | High 8.8 | |
| CVE-2026-83454 | Oracle Document Management and Collaboration | High 8.8 | |
| CVE-2026-83456 | Oracle Demand Signal Repository | High 8.8 | |
| CVE-2026-83479 | Oracle Contracts | High 8.8 | |
| CVE-2026-87150 | Oracle Bills of Material | High 8.8 | |
| CVE-2026-87155 | Oracle Product Hub | High 8.8 | |
| CVE-2026-87162 | Oracle Contract Lifecycle Management for Public Sector | High 8.8 | |
| CVE-2026-87163 | Oracle Purchasing | High 8.8 | |
| CVE-2026-87165 | Oracle Contract Lifecycle Management for Public Sector | High 8.8 | |
| CVE-2026-73926 | Oracle Access Manager | High 8.7 | |
| CVE-2026-83025 | Oracle Identity Manager Connector | High 8.7 | |
| CVE-2026-83135 | Oracle iStore | High 8.7 | |
| CVE-2026-73941 | Oracle Access Manager | High 8.6 | |
| CVE-2026-83023 | Oracle Identity Manager Connector | High 8.6 | |
| CVE-2026-83093 | Oracle Forms | High 8.6 | |
| CVE-2026-83002 | Oracle Access Manager | High 8.5 | |
| CVE-2026-83003 | Oracle WebCenter Enterprise Capture | High 8.5 | |
| CVE-2026-83007 | Oracle WebCenter Enterprise Capture | High 8.5 | |
| CVE-2026-83045 | Oracle WebCenter Portal | High 8.5 | |
| CVE-2026-83049 | Oracle WebCenter Portal | High 8.5 | |
| CVE-2026-83083 | Oracle Marketing | High 8.5 | |
| CVE-2026-83172 | Oracle Sales Online | High 8.5 | |
| CVE-2026-83272 | Oracle Database Server | High 8.5 | |
| CVE-2026-83425 | Oracle Complex Maintenance, Repair and Overhaul | High 8.5 | |
| CVE-2026-83449 | Oracle Bills of Material | High 8.5 | |
| CVE-2026-83451 | Oracle Product Workbench | High 8.5 | |
| CVE-2026-83490 | Oracle iRecruitment | High 8.5 | |
| CVE-2026-87161 | Oracle HRMS (India) | High 8.5 | |
| CVE-2026-83026 | Oracle Identity Manager Connector | High 8.3 | |
| CVE-2026-83030 | Oracle Managed File Transfer | High 8.3 | |
| CVE-2026-87125 | Oracle Financials for Asia/Pacific | High 8.3 | |
| CVE-2026-83047 | Oracle WebCenter Portal | High 8.2 | |
| CVE-2026-83265 | Oracle Web Services Manager | High 8.2 | |
| CVE-2026-83266 | Oracle JDeveloper | High 8.2 | |
| CVE-2026-83435 | Oracle Bills of Material | High 8.2 | |
| CVE-2026-83438 | Oracle Engineering | High 8.2 | |
| CVE-2026-83461 | Oracle Mobile Application Server | High 8.2 | |
| CVE-2026-83465 | Oracle Mobile Application Server | High 8.2 | |
| CVE-2026-83357 | Oracle GraalVM for JDK, Oracle GraalVM | High 8.1 | |
| CVE-2026-83408 | Oracle GraalVM for JDK, Oracle GraalVM | High 8.1 | |
| CVE-2026-73951 | Oracle WebCenter Portal | High 8.1 | |
| CVE-2026-73958 | Oracle Access Manager | High 8.1 | |
| CVE-2026-83010 | Oracle WebCenter Enterprise Capture | High 8.1 | |
| CVE-2026-83011 | Oracle Platform Security for Java | High 8.1 | |
| CVE-2026-83067 | Oracle JDeveloper | High 8.1 | |
| CVE-2026-83072 | Oracle Applications Framework | High 8.1 | |
| CVE-2026-83089 | Oracle Alert | High 8.1 | |
| CVE-2026-83101 | Oracle Forms | High 8.1 | |
| CVE-2026-83132 | Oracle iStore | High 8.1 | |
| CVE-2026-83152 | Oracle Project Intelligence | High 8.1 | |
| CVE-2026-83169 | Oracle One-to-One Fulfillment | High 8.1 | |
| CVE-2026-83174 | Oracle CRM Technical Foundation | High 8.1 | |
| CVE-2026-83177 | Oracle One-to-One Fulfillment | High 8.1 | |
| CVE-2026-83351 | Oracle Database Server | High 8.1 | |
| CVE-2026-83412 | Oracle Coherence | High 8.1 | |
| CVE-2026-83422 | Oracle Identity Manager | High 8.1 | |
| CVE-2026-83428 | Oracle Demand Signal Repository | High 8.1 | |
| CVE-2026-83429 | Oracle Demand Signal Repository | High 8.1 | |
| CVE-2026-83430 | Oracle Product Workbench | High 8.1 | |
| CVE-2026-83432 | Oracle Depot Repair | High 8.1 | |
| CVE-2026-83434 | Oracle Product Workbench | High 8.1 | |
| CVE-2026-83439 | Helidon | High 8.1 | |
| CVE-2026-83446 | Oracle Financials Common Modules | High 8.1 | |
| CVE-2026-83447 | Oracle Bills of Material | High 8.1 | |
| CVE-2026-83448 | Oracle Bills of Material | High 8.1 | |
| CVE-2026-83455 | Oracle Demand Signal Repository | High 8.1 | |
| CVE-2026-83457 | Oracle Demand Signal Repository | High 8.1 | |
| CVE-2026-83464 | Oracle Mobile Application Server | High 8.1 | |
| CVE-2026-87152 | Oracle Installed Base | High 8.1 | |
| CVE-2026-87153 | Oracle Product Hub | High 8.1 | |
| CVE-2026-87154 | Oracle Product Hub | High 8.1 | |
| CVE-2026-87157 | Oracle Order Management | High 8.1 | |
| CVE-2026-87159 | Oracle HRMS (India) | High 8.1 | |
| CVE-2026-87166 | Oracle Purchasing | High 8.1 | |
| CVE-2026-87167 | Oracle Purchasing | High 8.1 | |
| CVE-2026-87168 | Oracle Purchasing | High 8.1 | |
| CVE-2026-87265 | Oracle Purchasing | High 8.1 | |
| CVE-2026-87286 | Oracle GraalVM | High 8.1 | |
| CVE-2026-87287 | Oracle GraalVM | High 8.1 | |
| CVE-2026-87288 | Oracle GraalVM | High 8.1 | |
| CVE-2026-83477 | Oracle Work in Process | High 8.1 | |
| CVE-2026-83138 | Oracle Spares Management | High 8.0 | |
| CVE-2026-83157 | Oracle Applications Manager | High 8.0 | |
| CVE-2026-83178 | Oracle Application Object Library | High 8.0 | |
| CVE-2026-83450 | Oracle Bills of Material | High 8.0 | |
| CVE-2026-83483 | Oracle Advanced Benefits | High 8.0 | |
| CVE-2026-83170 | Oracle One-to-One Fulfillment | High 8.0 | |
| CVE-2026-83022 | Oracle WebCenter Enterprise Capture | High 7.9 | |
| CVE-2026-83096 | Oracle Forms | High 7.9 | |
| CVE-2026-82996 | Oracle Platform Security for Java | High 7.8 | |
| CVE-2026-83024 | Oracle Identity Manager Connector | High 7.8 | |
| CVE-2026-83118 | Applications DBA | High 7.8 | |
| CVE-2026-83159 | Applications DBA | High 7.8 | |
| CVE-2026-83337 | Oracle Middleware Common Libraries and Tools | High 7.8 | |
| CVE-2026-83353 | Oracle WebCenter Content | High 7.8 | |
| CVE-2026-83012 | Oracle WebCenter Enterprise Capture | High 7.7 | |
| CVE-2026-83041 | Oracle WebCenter Portal | High 7.7 | |
| CVE-2026-83048 | Oracle WebCenter Portal | High 7.7 | |
| CVE-2026-83084 | Oracle Marketing | High 7.7 | |
| CVE-2026-83088 | Oracle Database Server | High 7.7 | |
| CVE-2026-83116 | Oracle Order Management | High 7.7 | |
| CVE-2026-83127 | Oracle Sales Offline | High 7.7 | |
| CVE-2026-83129 | Oracle Sales | High 7.7 | |
| CVE-2026-83131 | Oracle Web Applications Desktop Integrator | High 7.7 | |
| CVE-2026-83134 | Oracle iStore | High 7.7 | |
| CVE-2026-83141 | Oracle Field Service | High 7.7 | |
| CVE-2026-83142 | Oracle Proposals | High 7.7 | |
| CVE-2026-83166 | Oracle Customer Interaction History | High 7.7 | |
| CVE-2026-83312 | Oracle BI Publisher | High 7.7 | |
| CVE-2026-83356 | Enterprise Command Center Framework | High 7.7 | |
| CVE-2026-83437 | Oracle Engineering | High 7.7 | |
| CVE-2026-83485 | Oracle Product Hub | High 7.7 | |
| CVE-2026-83486 | Oracle Product Hub | High 7.7 | |
| CVE-2026-83487 | Oracle Product Hub | High 7.7 | |
| CVE-2026-87124 | Oracle iRecruitment | High 7.7 | |
| CVE-2026-87127 | Oracle Purchasing | High 7.7 | |
| CVE-2026-87151 | Oracle Bills of Material | High 7.7 | |
| CVE-2026-73943 | Oracle Identity Manager | High 7.6 | |
| CVE-2026-83052 | Oracle WebCenter Portal | High 7.6 | |
| CVE-2026-83091 | Oracle Field Service | High 7.6 | |
| CVE-2026-83126 | Oracle Sales Online | High 7.6 | |
| CVE-2026-83028 | Oracle Identity Manager Connector | High 7.5 | |
| CVE-2026-83034 | Oracle WebCenter Sites | High 7.5 | |
| CVE-2026-83051 | Oracle WebCenter Portal | High 7.5 | |
| CVE-2026-83106 | Oracle Forms | High 7.5 | |
| CVE-2026-83110 | Oracle Marketing | High 7.5 | |
| CVE-2026-83114 | Oracle Quality | High 7.5 | |
| CVE-2026-83115 | Oracle Applications Manager | High 7.5 | |
| CVE-2026-83128 | Oracle Sales Offline | High 7.5 | |
| CVE-2026-83133 | Oracle iStore | High 7.5 | |
| CVE-2026-83156 | Oracle Database Server | High 7.5 | |
| CVE-2026-83167 | Oracle Application Object Library | High 7.5 | |
| CVE-2026-83204 | Oracle Sourcing | High 7.5 | |
| CVE-2026-83276 | Helidon | High 7.5 | |
| CVE-2026-83280 | Helidon | High 7.5 | |
| CVE-2026-83281 | Helidon | High 7.5 | |
| CVE-2026-83330 | Helidon | High 7.5 | |
| CVE-2026-83333 | Oracle Database Server | High 7.5 | |
| CVE-2026-83341 | Oracle Applications Manager | High 7.5 | |
| CVE-2026-83349 | Oracle Database Server | High 7.5 | |
| CVE-2026-83350 | Oracle Database Server | High 7.5 | |
| CVE-2026-83415 | Oracle Coherence | High 7.5 | |
| CVE-2026-83424 | Oracle JDeveloper | High 7.5 | |
| CVE-2026-87289 | Helidon | High 7.5 | |
| CVE-2026-83065 | Oracle WebCenter Portal | High 7.5 | |
| CVE-2026-83463 | Oracle Mobile Application Server | High 7.5 | |
| CVE-2026-83102 | Oracle Forms | High 7.4 | |
| CVE-2026-83162 | Oracle Application Object Library | High 7.4 | |
| CVE-2026-83184 | Oracle Application Object Library | High 7.4 | |
| CVE-2026-83334 | Oracle Web Services Manager | High 7.4 | |
| CVE-2026-83185 | Oracle Common Applications | High 7.3 | |
| CVE-2026-83063 | Oracle Internet Directory | High 7.2 | |
| CVE-2026-83082 | Oracle Marketing | High 7.2 | |
| CVE-2026-83112 | Oracle Lease and Finance Management | High 7.2 | |
| CVE-2026-83117 | Applications DBA | High 7.2 | |
| CVE-2026-83176 | Oracle Common Applications | High 7.2 | |
| CVE-2026-83188 | Oracle Depot Repair | High 7.2 | |
| CVE-2026-83328 | Oracle Applications Framework | High 7.2 | |
| CVE-2026-83344 | Oracle Identity Manager Connector | High 7.2 | |
| CVE-2026-83440 | Oracle Product Hub | High 7.2 | |
| CVE-2026-83442 | Oracle Product Hub | High 7.2 | |
| CVE-2026-83453 | Oracle Document Management and Collaboration | High 7.2 | |
| CVE-2026-83481 | Oracle Contracts | High 7.2 | |
| CVE-2026-83482 | Oracle Contracts | High 7.2 | |
| CVE-2026-83004 | Oracle WebCenter Enterprise Capture | High 7.2 | |
| CVE-2026-83044 | Oracle XML Gateway | High 7.1 | |
| CVE-2026-83046 | Oracle WebCenter Portal | High 7.1 | |
| CVE-2026-83050 | Oracle WebCenter Portal | High 7.1 | |
| CVE-2026-83092 | Oracle Field Service | High 7.1 | |
| CVE-2026-83113 | Oracle Quality | High 7.1 | |
| CVE-2026-83123 | Oracle Report Manager | High 7.1 | |
| CVE-2026-83171 | Oracle One-to-One Fulfillment | High 7.1 | |
| CVE-2026-83173 | Oracle One-to-One Fulfillment | High 7.1 | |
| CVE-2026-83179 | Oracle Common Applications Calendar | High 7.1 | |
| CVE-2026-83186 | Oracle Common Applications Calendar | High 7.1 | |
| CVE-2026-83300 | Oracle XML Gateway | High 7.1 | |
| CVE-2026-83332 | Oracle Applications Framework | High 7.1 | |
| CVE-2026-83345 | Oracle XML Gateway | High 7.1 | |
| CVE-2026-83352 | Oracle XML Gateway | High 7.1 | |
| CVE-2026-83436 | Oracle Depot Repair | High 7.1 | |
| CVE-2026-83484 | Oracle US Federal Human Resources | High 7.1 | |
| CVE-2026-87126 | Oracle Report Manager | High 7.1 | |
| CVE-2026-87149 | Oracle Contract Lifecycle Management for Public Sector | High 7.1 | |
| CVE-2026-87156 | Oracle Product Hub | High 7.1 | |
| CVE-2026-87158 | Oracle Order Management | High 7.1 | |
| CVE-2026-87160 | Oracle HRMS (India) | High 7.1 | |
| CVE-2026-83111 | Oracle Partner Management | High 7.1 | |
| CVE-2026-83130 | Oracle Site Hub | High 7.1 | |
| CVE-2026-83158 | Oracle Applications Manager | High 7.1 | |
| CVE-2026-83161 | Oracle Project Intelligence | High 7.1 | |
| CVE-2026-83187 | Oracle Common Applications Calendar | High 7.1 | |
| CVE-2026-83368 | Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM | High 7.0 | |
| CVE-2026-83231 | Helidon | High 7.0 | |
| CVE-2026-83076 | Oracle HR Intelligence | Medium 6.8 | |
| CVE-2026-83441 | Oracle Product Hub | Medium 6.8 | |
| CVE-2026-83491 | Oracle iRecruitment | Medium 6.8 | |
| CVE-2026-83278 | Helidon | Medium 6.8 | |
| CVE-2026-70755 | Oracle Web Applications Desktop Integrator | Medium 6.5 | |
| CVE-2026-83097 | Oracle Forms | Medium 6.5 | |
| CVE-2026-83140 | Oracle Field Service | Medium 6.5 | |
| CVE-2026-83175 | Oracle Application Object Library | Medium 6.5 | |
| CVE-2026-83200 | Oracle Process Manufacturing Intelligence | Medium 6.5 | |
| CVE-2026-83347 | Oracle Database Server | Medium 6.5 | |
| CVE-2026-83433 | Oracle Depot Repair | Medium 6.5 | |
| CVE-2026-83443 | Oracle Assets | Medium 6.5 | |
| CVE-2026-83460 | Helidon | Medium 6.5 | |
| CVE-2026-83354 | Oracle Coherence | Medium 6.3 | |
| CVE-2026-87169 | Oracle Contract Lifecycle Management for Public Sector | Medium 6.1 | |
| CVE-2026-83198 | Oracle Field Service | Medium 5.4 | |
| CVE-2026-83346 | Oracle Fusion Middleware Control | Medium 5.4 | |
| CVE-2026-83431 | Oracle Product Workbench | Medium 5.4 | |
| CVE-2026-83488 | Helidon | Medium 5.4 | |
| CVE-2026-83109 | Oracle Forms | Medium 5.3 | |
| CVE-2026-83458 | Helidon | Medium 5.3 | |
| CVE-2026-83459 | Helidon | Medium 5.3 | |
| CVE-2026-83480 | Helidon | Medium 5.3 | |
| CVE-2026-83416 | Oracle Coherence | Medium 4.3 | |
| CVE-2026-83369 | Oracle Access Manager | Low 3.1 | |
| CVE-2026-83414 | Oracle Coherence | Low 2.5 | |
| CVE-2026-83413 | Oracle Coherence | Low 1.9 |
References
Vendor advisory
CVE
- CVE-2026-71133 — cve.org
- CVE-2026-71133 — NVD
- CVE-2026-83020 — cve.org
- CVE-2026-83020 — NVD
- CVE-2026-83021 — cve.org
- CVE-2026-83021 — NVD
- CVE-2026-83059 — cve.org
- CVE-2026-83059 — NVD
- CVE-2026-83099 — cve.org
- CVE-2026-83099 — NVD
- CVE-2026-71163 — cve.org
- CVE-2026-71163 — NVD
- CVE-2026-73945 — cve.org
- CVE-2026-73945 — NVD
- CVE-2026-73948 — cve.org
- CVE-2026-73948 — NVD
- CVE-2026-82997 — cve.org
- CVE-2026-82997 — NVD
- CVE-2026-82998 — cve.org
- CVE-2026-82998 — NVD
- CVE-2026-82999 — cve.org
- CVE-2026-82999 — NVD
- CVE-2026-83031 — cve.org
- CVE-2026-83031 — NVD