VulnSea

oracle has 522 CVEs on record between 2012 and 2026. Disclosure cadence is accelerating: 489 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 263. The median CVSS is 7.8 (high), with 119 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1283 days (10 cases). The dominant weakness classes are CWE-284 (302) and CWE-306 (88). Most affected products: hyperion_financial_management (83), webcenter_portal (35), hyperion_data_relationship_management (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.8
Publish → KEV
1283 d median(10)
Last 90 days
489 prev 8

Products

  • hyperion_financial_management 83
  • webcenter_portal 35
  • hyperion_data_relationship_management 21
  • webcenter_enterprise_capture 21
  • e-business_suite 20
  • peoplesoft_enterprise_campus_software_campus_community 20
522
Total CVEs
119
Critical
10
CISA KEV
10
Exploited

oracle vulnerabilities

CVEs affecting oracle, newest first. Open any entry for full detail, references, and exploit status.

522 CVEsRSS

CVE-2026-71092High· 7.5
1mo ago

Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration)

Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged…

▾ Twilightoracle · peoplesoft_lease_administrationEPSS 0.13%via NVD
CVE-2026-71048High· 7.6
1mo ago

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues)

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker w…

▾ Twilightoracle · product_lifecycle_analyticsEPSS 0.32%via NVD
CVE-2026-71035High· 8.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthen…

▾ Twilightoracle · commerce_experience_managerEPSS 0.39%via NVD
CVE-2026-71034High· 7.5
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenti…

▾ Twilightoracle · commerce_experience_managerEPSS 0.41%via NVD
CVE-2026-71033Medium· 5.5
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Sunlitoracle · commerce_experience_managerEPSS 0.15%via NVD
CVE-2026-71032High· 7.2
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Twilightoracle · commerce_experience_managerEPSS 0.27%via NVD
CVE-2026-71031Medium· 6.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Sunlitoracle · commerce_experience_managerEPSS 0.24%via NVD
CVE-2026-71030High· 7.2
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Twilightoracle · commerce_experience_managerEPSS 0.27%via NVD
CVE-2026-71029Medium· 6.8
1mo ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network …

▾ Sunlitoracle · helidonEPSS 0.33%via NVD
CVE-2026-71028High· 7.8
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Twilightoracle · commerce_experience_managerEPSS 0.16%via NVD
CVE-2026-71027High· 7.6
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Twilightoracle · commerce_experience_managerEPSS 0.27%via NVD
CVE-2026-71026Critical· 9.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Midnightoracle · commerce_experience_managerEPSS 0.43%via NVD
CVE-2026-71025Medium· 6.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Sunlitoracle · commerce_experience_managerEPSS 0.24%via NVD
CVE-2026-71064Critical· 9.6
1mo ago

Vulnerability in the Portable Clusterware component of Oracle Database Server

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with ac…

▾ Midnightoracle · database_serverEPSS 0.40%via NVD
CVE-2026-71036Critical· 9.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allo…

▾ Midnightoracle · commerce_guided_searchEPSS 0.43%via NVD
CVE-2026-71013Medium· 6.0
1mo ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with …

▾ Sunlitoracle · hyperion_financial_managementEPSS 0.18%via NVD
CVE-2026-70924High· 8.1
1mo ago

Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security)

Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unau…

▾ Twilightoracle · web_services_managerEPSS 0.39%via NVD
CVE-2026-70922High· 8.8
1mo ago

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI)

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerab…

▾ Twilightoracle · financial_services_enterprise_case_managementEPSS 0.43%via NVD
CVE-2026-70910High· 7.5
1mo ago

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST)

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTT…

▾ Twilightoracle · siebel_crmEPSS 0.41%via NVD
CVE-2026-70905Critical· 9.8
1mo ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticat…

▾ Midnightoracle · access_managerEPSS 0.51%via NVD
CVE-2026-61058High· 8.8
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-61054High· 8.2
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Twilightoracle · webcenter_sitesEPSS 0.35%via NVD
CVE-2026-61042High· 8.8
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-61040High· 8.8
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-61038High· 8.2
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Twilightoracle · webcenter_sitesEPSS 0.35%via NVD
CVE-2026-61034Critical· 9.1
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged a…

▾ Midnightoracle · webcenter_sitesEPSS 0.49%via NVD
CVE-2026-61032High· 8.8
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-61029Critical· 9.0
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_sitesEPSS 0.39%via NVD
CVE-2026-61022High· 8.8
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · webcenter_sitesEPSS 0.43%via NVD
CVE-2026-61021Critical· 9.9
1mo ago

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at…

▾ Midnightoracle · webcenter_sitesEPSS 0.43%via NVD
oracle vulnerabilities (CVEs) — page 10 · VulnSea