Oracle Corporation has 387 CVEs on record. Disclosure cadence is accelerating: 387 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 371. The median CVSS is 7.8 (high), with 41 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-284 (203) and CWE-269 (99). Most affected products: Oracle Business Intelligence Enterprise Edition (35), Oracle Commerce Guided Search / Oracle Commerce Experience Manager (27), Oracle BI Publisher (22).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 387 prev 0
Weakness classes
Products
- Oracle Business Intelligence Enterprise Edition 35
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager 27
- Oracle BI Publisher 22
- Siebel CRM Deployment 21
- Oracle Database Server 13
- Helidon 9
Worst active — by depth score
CVE-2026-83282Critical· 9.9Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)55CVE-2026-83058Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83057Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83056Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55CVE-2026-83055Critical· 9.9Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)55
Oracle Corporation vulnerabilities
CVEs affecting Oracle Corporation, newest first. Open any entry for full detail, references, and exploit status.
387 CVEsRSS
CVE-2026-83433Medium· 6.5Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics)
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker…
CVE-2026-83432High· 8.1Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges)
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attack…
CVE-2026-83431Medium· 5.4Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI)
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network a…
CVE-2026-83430High· 8.1Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker …
CVE-2026-83429High· 8.1Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at…
CVE-2026-83428High· 8.1Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at…
CVE-2026-83425High· 8.5Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows …
CVE-2026-83424High· 7.5Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper)
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated atta…
CVE-2026-83423High· 8.8Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework)
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged atta…
CVE-2026-83420High· 7.8Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering)
Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-83419Medium· 5.4Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP)
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerab…
CVE-2026-83418High· 8.2Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP)
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Difficult to exploit vulner…
CVE-2026-83417High· 7.1Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP)
Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerab…
CVE-2026-83356High· 7.7Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security)
Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with netw…
CVE-2026-83355Critical· 9.8Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics)
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthentic…
CVE-2026-83354Medium· 6.3Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access vi…
CVE-2026-83353High· 7.8Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged a…
CVE-2026-83352High· 7.1Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install)
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acces…
CVE-2026-83351High· 8.1Vulnerability in the RDBMS component of Oracle Database Server
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise…
CVE-2026-83350High· 7.5Vulnerability in the Oracle Net Services component of Oracle Database Server
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access …
CVE-2026-83349High· 7.5Vulnerability in the Oracle Net Services component of Oracle Database Server
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with net…
CVE-2026-83348High· 8.8Vulnerability in the RDBMS component of Oracle Database Server
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create DB Link p…
CVE-2026-83347Medium· 6.5Vulnerability in the Oracle Net Services component of Oracle Database Server
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to comp…
CVE-2026-83346Medium· 5.4Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework)
Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privilege…
CVE-2026-83345High· 7.1Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install)
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acces…
CVE-2026-83344High· 7.2Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table)
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability al…
CVE-2026-83343High· 8.2Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide)
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A…
CVE-2026-83342High· 7.8Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide)
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13…
CVE-2026-83341High· 7.5Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone)
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated…
CVE-2026-83340High· 8.8Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security)
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker…