Skip to content

Release roundup

Oracle Critical Security Patch Update Advisory, September 2026: unauthenticated Fusion Middleware flaws lead 330 fixes

Critical 10.0 Vendor: Oracle 330 CVEs in scope Published

Oracle's September 2026 Critical Patch Update covers 330 CVEs: 69 critical, 234 high, 24 medium and 3 low. No CVEs are recorded as exploited or in CISA KEV. Unauthenticated Fusion Middleware flaws, several scored 10.0, warrant priority.

The release at a glance

The Oracle Critical Security Patch Update Advisory - September 2026 spans 330 CVEs across Oracle's products. The severity mix is 69 critical, 234 high, 24 medium and 3 low. Oracle E-Business Suite accounts for 159 of the CVEs, Oracle Fusion Middleware for 152, Oracle Database Server for 11, Oracle Java SE for 6, Oracle Enterprise Manager for 1 and Oracle Analytics for 1. No CVE in this release is recorded as exploited in the wild or listed in CISA KEV.

Among the highest-scoring issues, Oracle Access Manager, Oracle Platform Security for Java, Oracle WebLogic Server, Oracle Internet Directory and Oracle Forms each carry a CVSS 3.1 score of 10.0 and are reachable over the network without credentials. Several further items in Oracle Access Manager, WebCenter Portal, WebCenter Sites and Service Delivery Platform score 9.9 and require only low privileges.

What matters most

Oracle Access Manager has the sharpest items. CVE-2026-71133 is an unauthenticated HTTP issue in the Authentication Engine; Oracle rates it 10.0, with scope change and takeover of the product. CVE-2026-73945 is a lower-privilege issue, also in the Authentication Engine, scoring 9.9 and allowing takeover. Oracle Platform Security for Java CVE-2026-83020 is an unauthenticated HTTP issue in Centralized Thirdparty Jars, scored 10.0. Oracle WebLogic Server CVE-2026-83021 affects the Web Container, is unauthenticated over HTTP, scores 10.0 and allows takeover. Oracle Internet Directory CVE-2026-83059 is an unauthenticated LDAP issue in the OID LDAP Server, also scored 10.0. Oracle Forms CVE-2026-83099 is an unauthenticated HTTP issue in Forms Services, C/S, Charmode, also scored 10.0. Oracle WebCenter Portal CVE-2026-73948 is a low-privilege HTTP issue in Composer, scoring 9.9. Service Delivery Platform CVE-2026-82997 is a low-privilege T3/IIOP issue in Messaging Enabler, scoring 9.9. These matter first because they combine network access, low or no privileges, and Oracle's 'easily exploitable' assessment.

Patch in this order

  1. Patch the unauthenticated network-facing Fusion Middleware components first: Oracle Access Manager CVE-2026-71133, Oracle Platform Security for Java CVE-2026-83020, Oracle WebLogic Server CVE-2026-83021, Oracle Internet Directory CVE-2026-83059 and Oracle Forms CVE-2026-83099. They score 10.0, require no credentials, and Oracle describes them as easily exploitable.
  2. Patch the low-privileged Fusion Middleware items next: Oracle Access Manager CVE-2026-71163 and CVE-2026-73945, Oracle WebCenter Portal CVE-2026-73948, Service Delivery Platform CVE-2026-82997, CVE-2026-82998 and CVE-2026-82999, and Oracle WebCenter Sites CVE-2026-83031. These score 9.9 and require only low privileges.
  3. Continue with the remaining Oracle Fusion Middleware and Oracle E-Business Suite updates, prioritising internet-facing E-Business Suite modules and any Fusion Middleware components reachable from untrusted networks.
  4. Move to Oracle Database Server, Oracle Java SE, Oracle Enterprise Manager and Oracle Analytics according to your normal patch cycle.

Because no CVE in this release is in CISA KEV, there is no CISA due date to schedule around; the priority is exposure and Oracle's rating.

Beyond the patch

This release is defined by network-reachable, low-or-no-privilege Fusion Middleware flaws, which makes it a strong case for continuous exposure management rather than a quarterly scramble. Virtual CISO Services can help you keep internet-facing Oracle services visible and prioritised, and Implementation & Assessment Services can test the authentication and access-control boundaries in Access Manager, WebLogic Server and related components before the next CPU lands.

Every CVE in this release

CVEProductSeverity
CVE-2026-71133Oracle Access ManagerCritical 10.0
CVE-2026-83020Oracle Platform Security for JavaCritical 10.0
CVE-2026-83021Oracle WebLogic ServerCritical 10.0
CVE-2026-83059Oracle Internet DirectoryCritical 10.0
CVE-2026-83099Oracle FormsCritical 10.0
CVE-2026-71163Oracle Access ManagerCritical 9.9
CVE-2026-73945Oracle Access ManagerCritical 9.9
CVE-2026-73948Oracle WebCenter PortalCritical 9.9
CVE-2026-82997Service Delivery PlatformCritical 9.9
CVE-2026-82998Service Delivery PlatformCritical 9.9
CVE-2026-82999Service Delivery PlatformCritical 9.9
CVE-2026-83031Oracle WebCenter SitesCritical 9.9
CVE-2026-83038Oracle WebLogic ServerCritical 9.9
CVE-2026-83039Oracle WebCenter PortalCritical 9.9
CVE-2026-83055Oracle Internet DirectoryCritical 9.9
CVE-2026-83056Oracle Internet DirectoryCritical 9.9
CVE-2026-83057Oracle Internet DirectoryCritical 9.9
CVE-2026-83058Oracle Internet DirectoryCritical 9.9
CVE-2026-70748Oracle WebLogic ServerCritical 9.8
CVE-2026-70756Oracle WebLogic ServerCritical 9.8
CVE-2026-70757Oracle WebLogic ServerCritical 9.8
CVE-2026-70913Oracle Identity ManagerCritical 9.8
CVE-2026-73940Oracle Access ManagerCritical 9.8
CVE-2026-73947Oracle Access ManagerCritical 9.8
CVE-2026-73950Oracle Access ManagerCritical 9.8
CVE-2026-73953Oracle WebCenter PortalCritical 9.8
CVE-2026-73956Oracle WebCenter PortalCritical 9.8
CVE-2026-73961Oracle JDeveloperCritical 9.8
CVE-2026-73963Oracle WebCenter PortalCritical 9.8
CVE-2026-82994Oracle Platform Security for JavaCritical 9.8
CVE-2026-82995Oracle Platform Security for JavaCritical 9.8
CVE-2026-83000Service Delivery PlatformCritical 9.8
CVE-2026-83035Oracle WebCenter SitesCritical 9.8
CVE-2026-83036Oracle WebCenter SitesCritical 9.8
CVE-2026-83037Oracle WebCenter SitesCritical 9.8
CVE-2026-83042Oracle Identity ManagerCritical 9.8
CVE-2026-83054Oracle Internet DirectoryCritical 9.8
CVE-2026-83060Oracle Internet DirectoryCritical 9.8
CVE-2026-83061Oracle Internet DirectoryCritical 9.8
CVE-2026-83062Oracle Internet DirectoryCritical 9.8
Show all 330
CVEProductSeverity
CVE-2026-83066Oracle Internet DirectoryCritical 9.8
CVE-2026-83094Oracle FormsCritical 9.8
CVE-2026-83095Oracle FormsCritical 9.8
CVE-2026-83098Oracle FormsCritical 9.8
CVE-2026-83100Oracle FormsCritical 9.8
CVE-2026-83108Oracle FormsCritical 9.8
CVE-2026-83151Service Delivery PlatformCritical 9.8
CVE-2026-83232Oracle Data IntegratorCritical 9.8
CVE-2026-83327Oracle Applications FrameworkCritical 9.8
CVE-2026-83339Oracle WebCenter Enterprise CaptureCritical 9.8
CVE-2026-83355Oracle Enterprise Manager for Fusion MiddlewareCritical 9.8
CVE-2026-83452Oracle Document Management and CollaborationCritical 9.8
CVE-2026-83462Oracle Mobile Application ServerCritical 9.8
CVE-2026-73962Oracle Access ManagerCritical 9.6
CVE-2026-83029Oracle Managed File TransferCritical 9.6
CVE-2026-83040Oracle WebCenter PortalCritical 9.6
CVE-2026-83043Oracle WebCenter PortalCritical 9.6
CVE-2026-73957Oracle WebCenter PortalCritical 9.3
CVE-2026-83027Oracle Identity Manager ConnectorCritical 9.3
CVE-2026-73944Oracle Access ManagerCritical 9.1
CVE-2026-73946Oracle Access ManagerCritical 9.1
CVE-2026-73952Oracle WebCenter PortalCritical 9.1
CVE-2026-83001Oracle Access ManagerCritical 9.1
CVE-2026-83006Oracle WebCenter Enterprise CaptureCritical 9.1
CVE-2026-83064Oracle WebCenter PortalCritical 9.1
CVE-2026-83103Oracle FormsCritical 9.1
CVE-2026-83104Oracle FormsCritical 9.1
CVE-2026-83107Oracle FormsCritical 9.1
CVE-2026-83105Oracle FormsCritical 9.0
CVE-2026-70915Oracle Identity ManagerHigh 8.8
CVE-2026-71047Oracle Identity ManagerHigh 8.8
CVE-2026-73942Oracle Identity ManagerHigh 8.8
CVE-2026-73949Oracle WebCenter PortalHigh 8.8
CVE-2026-73959Oracle WebCenter PortalHigh 8.8
CVE-2026-83005Oracle WebCenter Enterprise CaptureHigh 8.8
CVE-2026-83008Oracle WebCenter Enterprise CaptureHigh 8.8
CVE-2026-83009Oracle WebCenter Enterprise CaptureHigh 8.8
CVE-2026-83013Oracle WebCenter Enterprise CaptureHigh 8.8
CVE-2026-83032Oracle WebCenter SitesHigh 8.8
CVE-2026-83033Oracle WebCenter SitesHigh 8.8
CVE-2026-83053Oracle WebCenter PortalHigh 8.8
CVE-2026-83069Oracle Fusion Middleware ControlHigh 8.8
CVE-2026-83090Oracle Spares ManagementHigh 8.8
CVE-2026-83119Oracle User ManagementHigh 8.8
CVE-2026-83120Oracle AlertHigh 8.8
CVE-2026-83121Oracle MarketingHigh 8.8
CVE-2026-83122Oracle Report ManagerHigh 8.8
CVE-2026-83124Oracle Sales OnlineHigh 8.8
CVE-2026-83125Oracle Report ManagerHigh 8.8
CVE-2026-83136Oracle Spares ManagementHigh 8.8
CVE-2026-83137Oracle Spares ManagementHigh 8.8
CVE-2026-83160Oracle Database ServerHigh 8.8
CVE-2026-83163Oracle Application Object LibraryHigh 8.8
CVE-2026-83164Oracle Customer Interaction HistoryHigh 8.8
CVE-2026-83165Oracle Customer Interaction HistoryHigh 8.8
CVE-2026-83168Oracle Applications ManagerHigh 8.8
CVE-2026-83189Oracle User ManagementHigh 8.8
CVE-2026-83194Oracle Depot RepairHigh 8.8
CVE-2026-83205Oracle Applications FrameworkHigh 8.8
CVE-2026-83271Oracle Database ServerHigh 8.8
CVE-2026-83306Oracle JDeveloperHigh 8.8
CVE-2026-83329Oracle Applications FrameworkHigh 8.8
CVE-2026-83331Oracle Applications FrameworkHigh 8.8
CVE-2026-83338Oracle Applications ManagerHigh 8.8
CVE-2026-83340Oracle Identity ManagerHigh 8.8
CVE-2026-83348Oracle Database ServerHigh 8.8
CVE-2026-83410Oracle CoherenceHigh 8.8
CVE-2026-83411Oracle CoherenceHigh 8.8
CVE-2026-83423Oracle JDeveloperHigh 8.8
CVE-2026-83444Oracle Product HubHigh 8.8
CVE-2026-83445Oracle Complex Maintenance, Repair and OverhaulHigh 8.8
CVE-2026-83454Oracle Document Management and CollaborationHigh 8.8
CVE-2026-83456Oracle Demand Signal RepositoryHigh 8.8
CVE-2026-83479Oracle ContractsHigh 8.8
CVE-2026-87150Oracle Bills of MaterialHigh 8.8
CVE-2026-87155Oracle Product HubHigh 8.8
CVE-2026-87162Oracle Contract Lifecycle Management for Public SectorHigh 8.8
CVE-2026-87163Oracle PurchasingHigh 8.8
CVE-2026-87165Oracle Contract Lifecycle Management for Public SectorHigh 8.8
CVE-2026-73926Oracle Access ManagerHigh 8.7
CVE-2026-83025Oracle Identity Manager ConnectorHigh 8.7
CVE-2026-83135Oracle iStoreHigh 8.7
CVE-2026-73941Oracle Access ManagerHigh 8.6
CVE-2026-83023Oracle Identity Manager ConnectorHigh 8.6
CVE-2026-83093Oracle FormsHigh 8.6
CVE-2026-83002Oracle Access ManagerHigh 8.5
CVE-2026-83003Oracle WebCenter Enterprise CaptureHigh 8.5
CVE-2026-83007Oracle WebCenter Enterprise CaptureHigh 8.5
CVE-2026-83045Oracle WebCenter PortalHigh 8.5
CVE-2026-83049Oracle WebCenter PortalHigh 8.5
CVE-2026-83083Oracle MarketingHigh 8.5
CVE-2026-83172Oracle Sales OnlineHigh 8.5
CVE-2026-83272Oracle Database ServerHigh 8.5
CVE-2026-83425Oracle Complex Maintenance, Repair and OverhaulHigh 8.5
CVE-2026-83449Oracle Bills of MaterialHigh 8.5
CVE-2026-83451Oracle Product WorkbenchHigh 8.5
CVE-2026-83490Oracle iRecruitmentHigh 8.5
CVE-2026-87161Oracle HRMS (India)High 8.5
CVE-2026-83026Oracle Identity Manager ConnectorHigh 8.3
CVE-2026-83030Oracle Managed File TransferHigh 8.3
CVE-2026-87125Oracle Financials for Asia/PacificHigh 8.3
CVE-2026-83047Oracle WebCenter PortalHigh 8.2
CVE-2026-83265Oracle Web Services ManagerHigh 8.2
CVE-2026-83266Oracle JDeveloperHigh 8.2
CVE-2026-83435Oracle Bills of MaterialHigh 8.2
CVE-2026-83438Oracle EngineeringHigh 8.2
CVE-2026-83461Oracle Mobile Application ServerHigh 8.2
CVE-2026-83465Oracle Mobile Application ServerHigh 8.2
CVE-2026-83357Oracle GraalVM for JDK, Oracle GraalVMHigh 8.1
CVE-2026-83408Oracle GraalVM for JDK, Oracle GraalVMHigh 8.1
CVE-2026-73951Oracle WebCenter PortalHigh 8.1
CVE-2026-73958Oracle Access ManagerHigh 8.1
CVE-2026-83010Oracle WebCenter Enterprise CaptureHigh 8.1
CVE-2026-83011Oracle Platform Security for JavaHigh 8.1
CVE-2026-83067Oracle JDeveloperHigh 8.1
CVE-2026-83072Oracle Applications FrameworkHigh 8.1
CVE-2026-83089Oracle AlertHigh 8.1
CVE-2026-83101Oracle FormsHigh 8.1
CVE-2026-83132Oracle iStoreHigh 8.1
CVE-2026-83152Oracle Project IntelligenceHigh 8.1
CVE-2026-83169Oracle One-to-One FulfillmentHigh 8.1
CVE-2026-83174Oracle CRM Technical FoundationHigh 8.1
CVE-2026-83177Oracle One-to-One FulfillmentHigh 8.1
CVE-2026-83351Oracle Database ServerHigh 8.1
CVE-2026-83412Oracle CoherenceHigh 8.1
CVE-2026-83422Oracle Identity ManagerHigh 8.1
CVE-2026-83428Oracle Demand Signal RepositoryHigh 8.1
CVE-2026-83429Oracle Demand Signal RepositoryHigh 8.1
CVE-2026-83430Oracle Product WorkbenchHigh 8.1
CVE-2026-83432Oracle Depot RepairHigh 8.1
CVE-2026-83434Oracle Product WorkbenchHigh 8.1
CVE-2026-83439HelidonHigh 8.1
CVE-2026-83446Oracle Financials Common ModulesHigh 8.1
CVE-2026-83447Oracle Bills of MaterialHigh 8.1
CVE-2026-83448Oracle Bills of MaterialHigh 8.1
CVE-2026-83455Oracle Demand Signal RepositoryHigh 8.1
CVE-2026-83457Oracle Demand Signal RepositoryHigh 8.1
CVE-2026-83464Oracle Mobile Application ServerHigh 8.1
CVE-2026-87152Oracle Installed BaseHigh 8.1
CVE-2026-87153Oracle Product HubHigh 8.1
CVE-2026-87154Oracle Product HubHigh 8.1
CVE-2026-87157Oracle Order ManagementHigh 8.1
CVE-2026-87159Oracle HRMS (India)High 8.1
CVE-2026-87166Oracle PurchasingHigh 8.1
CVE-2026-87167Oracle PurchasingHigh 8.1
CVE-2026-87168Oracle PurchasingHigh 8.1
CVE-2026-87265Oracle PurchasingHigh 8.1
CVE-2026-87286Oracle GraalVMHigh 8.1
CVE-2026-87287Oracle GraalVMHigh 8.1
CVE-2026-87288Oracle GraalVMHigh 8.1
CVE-2026-83477Oracle Work in ProcessHigh 8.1
CVE-2026-83138Oracle Spares ManagementHigh 8.0
CVE-2026-83157Oracle Applications ManagerHigh 8.0
CVE-2026-83178Oracle Application Object LibraryHigh 8.0
CVE-2026-83450Oracle Bills of MaterialHigh 8.0
CVE-2026-83483Oracle Advanced BenefitsHigh 8.0
CVE-2026-83170Oracle One-to-One FulfillmentHigh 8.0
CVE-2026-83022Oracle WebCenter Enterprise CaptureHigh 7.9
CVE-2026-83096Oracle FormsHigh 7.9
CVE-2026-82996Oracle Platform Security for JavaHigh 7.8
CVE-2026-83024Oracle Identity Manager ConnectorHigh 7.8
CVE-2026-83118Applications DBAHigh 7.8
CVE-2026-83159Applications DBAHigh 7.8
CVE-2026-83337Oracle Middleware Common Libraries and ToolsHigh 7.8
CVE-2026-83353Oracle WebCenter ContentHigh 7.8
CVE-2026-83012Oracle WebCenter Enterprise CaptureHigh 7.7
CVE-2026-83041Oracle WebCenter PortalHigh 7.7
CVE-2026-83048Oracle WebCenter PortalHigh 7.7
CVE-2026-83084Oracle MarketingHigh 7.7
CVE-2026-83088Oracle Database ServerHigh 7.7
CVE-2026-83116Oracle Order ManagementHigh 7.7
CVE-2026-83127Oracle Sales OfflineHigh 7.7
CVE-2026-83129Oracle SalesHigh 7.7
CVE-2026-83131Oracle Web Applications Desktop IntegratorHigh 7.7
CVE-2026-83134Oracle iStoreHigh 7.7
CVE-2026-83141Oracle Field ServiceHigh 7.7
CVE-2026-83142Oracle ProposalsHigh 7.7
CVE-2026-83166Oracle Customer Interaction HistoryHigh 7.7
CVE-2026-83312Oracle BI PublisherHigh 7.7
CVE-2026-83356Enterprise Command Center FrameworkHigh 7.7
CVE-2026-83437Oracle EngineeringHigh 7.7
CVE-2026-83485Oracle Product HubHigh 7.7
CVE-2026-83486Oracle Product HubHigh 7.7
CVE-2026-83487Oracle Product HubHigh 7.7
CVE-2026-87124Oracle iRecruitmentHigh 7.7
CVE-2026-87127Oracle PurchasingHigh 7.7
CVE-2026-87151Oracle Bills of MaterialHigh 7.7
CVE-2026-73943Oracle Identity ManagerHigh 7.6
CVE-2026-83052Oracle WebCenter PortalHigh 7.6
CVE-2026-83091Oracle Field ServiceHigh 7.6
CVE-2026-83126Oracle Sales OnlineHigh 7.6
CVE-2026-83028Oracle Identity Manager ConnectorHigh 7.5
CVE-2026-83034Oracle WebCenter SitesHigh 7.5
CVE-2026-83051Oracle WebCenter PortalHigh 7.5
CVE-2026-83106Oracle FormsHigh 7.5
CVE-2026-83110Oracle MarketingHigh 7.5
CVE-2026-83114Oracle QualityHigh 7.5
CVE-2026-83115Oracle Applications ManagerHigh 7.5
CVE-2026-83128Oracle Sales OfflineHigh 7.5
CVE-2026-83133Oracle iStoreHigh 7.5
CVE-2026-83156Oracle Database ServerHigh 7.5
CVE-2026-83167Oracle Application Object LibraryHigh 7.5
CVE-2026-83204Oracle SourcingHigh 7.5
CVE-2026-83276HelidonHigh 7.5
CVE-2026-83280HelidonHigh 7.5
CVE-2026-83281HelidonHigh 7.5
CVE-2026-83330HelidonHigh 7.5
CVE-2026-83333Oracle Database ServerHigh 7.5
CVE-2026-83341Oracle Applications ManagerHigh 7.5
CVE-2026-83349Oracle Database ServerHigh 7.5
CVE-2026-83350Oracle Database ServerHigh 7.5
CVE-2026-83415Oracle CoherenceHigh 7.5
CVE-2026-83424Oracle JDeveloperHigh 7.5
CVE-2026-87289HelidonHigh 7.5
CVE-2026-83065Oracle WebCenter PortalHigh 7.5
CVE-2026-83463Oracle Mobile Application ServerHigh 7.5
CVE-2026-83102Oracle FormsHigh 7.4
CVE-2026-83162Oracle Application Object LibraryHigh 7.4
CVE-2026-83184Oracle Application Object LibraryHigh 7.4
CVE-2026-83334Oracle Web Services ManagerHigh 7.4
CVE-2026-83185Oracle Common ApplicationsHigh 7.3
CVE-2026-83063Oracle Internet DirectoryHigh 7.2
CVE-2026-83082Oracle MarketingHigh 7.2
CVE-2026-83112Oracle Lease and Finance ManagementHigh 7.2
CVE-2026-83117Applications DBAHigh 7.2
CVE-2026-83176Oracle Common ApplicationsHigh 7.2
CVE-2026-83188Oracle Depot RepairHigh 7.2
CVE-2026-83328Oracle Applications FrameworkHigh 7.2
CVE-2026-83344Oracle Identity Manager ConnectorHigh 7.2
CVE-2026-83440Oracle Product HubHigh 7.2
CVE-2026-83442Oracle Product HubHigh 7.2
CVE-2026-83453Oracle Document Management and CollaborationHigh 7.2
CVE-2026-83481Oracle ContractsHigh 7.2
CVE-2026-83482Oracle ContractsHigh 7.2
CVE-2026-83004Oracle WebCenter Enterprise CaptureHigh 7.2
CVE-2026-83044Oracle XML GatewayHigh 7.1
CVE-2026-83046Oracle WebCenter PortalHigh 7.1
CVE-2026-83050Oracle WebCenter PortalHigh 7.1
CVE-2026-83092Oracle Field ServiceHigh 7.1
CVE-2026-83113Oracle QualityHigh 7.1
CVE-2026-83123Oracle Report ManagerHigh 7.1
CVE-2026-83171Oracle One-to-One FulfillmentHigh 7.1
CVE-2026-83173Oracle One-to-One FulfillmentHigh 7.1
CVE-2026-83179Oracle Common Applications CalendarHigh 7.1
CVE-2026-83186Oracle Common Applications CalendarHigh 7.1
CVE-2026-83300Oracle XML GatewayHigh 7.1
CVE-2026-83332Oracle Applications FrameworkHigh 7.1
CVE-2026-83345Oracle XML GatewayHigh 7.1
CVE-2026-83352Oracle XML GatewayHigh 7.1
CVE-2026-83436Oracle Depot RepairHigh 7.1
CVE-2026-83484Oracle US Federal Human ResourcesHigh 7.1
CVE-2026-87126Oracle Report ManagerHigh 7.1
CVE-2026-87149Oracle Contract Lifecycle Management for Public SectorHigh 7.1
CVE-2026-87156Oracle Product HubHigh 7.1
CVE-2026-87158Oracle Order ManagementHigh 7.1
CVE-2026-87160Oracle HRMS (India)High 7.1
CVE-2026-83111Oracle Partner ManagementHigh 7.1
CVE-2026-83130Oracle Site HubHigh 7.1
CVE-2026-83158Oracle Applications ManagerHigh 7.1
CVE-2026-83161Oracle Project IntelligenceHigh 7.1
CVE-2026-83187Oracle Common Applications CalendarHigh 7.1
CVE-2026-83368Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVMHigh 7.0
CVE-2026-83231HelidonHigh 7.0
CVE-2026-83076Oracle HR IntelligenceMedium 6.8
CVE-2026-83441Oracle Product HubMedium 6.8
CVE-2026-83491Oracle iRecruitmentMedium 6.8
CVE-2026-83278HelidonMedium 6.8
CVE-2026-70755Oracle Web Applications Desktop IntegratorMedium 6.5
CVE-2026-83097Oracle FormsMedium 6.5
CVE-2026-83140Oracle Field ServiceMedium 6.5
CVE-2026-83175Oracle Application Object LibraryMedium 6.5
CVE-2026-83200Oracle Process Manufacturing IntelligenceMedium 6.5
CVE-2026-83347Oracle Database ServerMedium 6.5
CVE-2026-83433Oracle Depot RepairMedium 6.5
CVE-2026-83443Oracle AssetsMedium 6.5
CVE-2026-83460HelidonMedium 6.5
CVE-2026-83354Oracle CoherenceMedium 6.3
CVE-2026-87169Oracle Contract Lifecycle Management for Public SectorMedium 6.1
CVE-2026-83198Oracle Field ServiceMedium 5.4
CVE-2026-83346Oracle Fusion Middleware ControlMedium 5.4
CVE-2026-83431Oracle Product WorkbenchMedium 5.4
CVE-2026-83488HelidonMedium 5.4
CVE-2026-83109Oracle FormsMedium 5.3
CVE-2026-83458HelidonMedium 5.3
CVE-2026-83459HelidonMedium 5.3
CVE-2026-83480HelidonMedium 5.3
CVE-2026-83416Oracle CoherenceMedium 4.3
CVE-2026-83369Oracle Access ManagerLow 3.1
CVE-2026-83414Oracle CoherenceLow 2.5
CVE-2026-83413Oracle CoherenceLow 1.9

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.