Oracle Corporation has 387 CVEs on record. Disclosure cadence is accelerating: 387 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 371. The median CVSS is 7.8 (high), with 41 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-284 (203) and CWE-269 (99). Most affected products: Oracle Business Intelligence Enterprise Edition (35), Oracle Commerce Guided Search / Oracle Commerce Experience Manager (27), Oracle BI Publisher (22).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 387 prev 0
Weakness classes
Products
- Oracle Business Intelligence Enterprise Edition 35
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager 27
- Oracle BI Publisher 22
- Siebel CRM Deployment 21
- Oracle Database Server 13
- Helidon 9
Worst active — by depth score
CVE-2026-83282Critical· 9.9Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)55CVE-2026-83058Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83057Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83056Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83055Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55
Oracle Corporation vulnerabilities
CVEs affecting Oracle Corporation, newest first. Open any entry for full detail, references, and exploit status.
387 CVEsRSS
CVE-2026-83150High· 7.0Vulnerability in Oracle Application Testing Suite
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing…
CVE-2026-83149Critical· 9.1Vulnerability in Oracle Application Testing Suite
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via H…
CVE-2026-83148High· 8.8Vulnerability in Oracle Application Testing Suite
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via H…
CVE-2026-83147High· 7.8Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory)
Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with lo…
CVE-2026-83146High· 7.7Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI)
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HT…
CVE-2026-83145High· 8.7Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management)
Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker…
CVE-2026-83144High· 8.7Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management)
Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker…
CVE-2026-83143High· 8.1Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing)
Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network acc…
CVE-2026-83142High· 7.7Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with net…
CVE-2026-83141High· 7.7Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
CVE-2026-83140Medium· 6.5Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
CVE-2026-83138High· 8.0Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attack…
CVE-2026-83137High· 8.8Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker …
CVE-2026-83136High· 8.8Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker …
CVE-2026-83135High· 8.7Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart)
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acce…
CVE-2026-83134High· 7.7Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart)
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acce…
CVE-2026-83133High· 7.5Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart)
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network acc…
CVE-2026-83132High· 8.1Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart)
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acce…
CVE-2026-83131High· 7.7Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download)
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg…
CVE-2026-83130High· 7.1Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with netw…
CVE-2026-83129High· 7.7Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…
CVE-2026-83128High· 7.5Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker wit…
CVE-2026-83127High· 7.7Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
CVE-2026-83126High· 7.6Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with …
CVE-2026-83125High· 8.8Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-83124High· 8.8Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with …
CVE-2026-83123High· 7.1Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-83122High· 8.8Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-83121High· 8.8Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience)
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access…
CVE-2026-83120High· 8.8Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network…