Oracle Corporation has 387 CVEs on record. Disclosure cadence is accelerating: 387 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 371. The median CVSS is 7.8 (high), with 41 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-284 (203) and CWE-269 (99). Most affected products: Oracle Business Intelligence Enterprise Edition (35), Oracle Commerce Guided Search / Oracle Commerce Experience Manager (27), Oracle BI Publisher (22).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 387 prev 0
Weakness classes
Products
- Oracle Business Intelligence Enterprise Edition 35
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager 27
- Oracle BI Publisher 22
- Siebel CRM Deployment 21
- Oracle Database Server 13
- Helidon 9
Worst active — by depth score
CVE-2026-83282Critical· 9.9Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)55CVE-2026-83058Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83057Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83056Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83055Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55
Oracle Corporation vulnerabilities
CVEs affecting Oracle Corporation, newest first. Open any entry for full detail, references, and exploit status.
387 CVEsRSS
CVE-2026-82993High· 8.5Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-73966High· 7.2Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing)
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access v…
CVE-2026-73961Critical· 9.8Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces)
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker wit…
CVE-2026-73960High· 7.5Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
CVE-2026-73955High· 7.3Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network …
CVE-2026-73954High· 8.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker …
CVE-2026-70757Critical· 9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…
CVE-2026-70756Critical· 9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…
CVE-2026-70755Medium· 6.5Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download)
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg…
CVE-2026-70748Critical· 9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unau…
CVE-2026-62597Medium· 6.5Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management)
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privil…
CVE-2026-60702Critical· 9.9Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low …
CVE-2026-60726High· 8.8Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…
CVE-2026-71100Medium· 5.3Vulnerability in the RDBMS component of Oracle Database Server
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…
CVE-2026-71061High· 7.5Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability al…
CVE-2026-71059Critical· 9.9Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API)
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0 and 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with …
CVE-2026-71056High· 7.7Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability a…
CVE-2026-71098High· 7.0Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privi…
CVE-2026-71097High· 7.8Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows low privile…
CVE-2026-71063Critical· 9.6Vulnerability in the Portable Clusterware component of Oracle Database Server
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with ac…
CVE-2026-71099High· 7.2Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Answers). The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high pr…
CVE-2026-71094High· 7.3Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low priv…
CVE-2026-61308Medium· 6.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12,…
CVE-2026-61298Medium· 5.6Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install)
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allow…
CVE-2026-60182Medium· 4.4Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin)
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and …
CVE-2026-60718Medium· 6.5Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON)
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows …
CVE-2026-60165Medium· 6.5Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center)
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center). The supported version that is affected is V16. Easily exploitable vulnerability allows high privileged attacker with…