VulnSea

oracle has 522 CVEs on record between 2012 and 2026. Disclosure cadence is accelerating: 489 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 263. The median CVSS is 7.8 (high), with 119 rated critical. 2% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 1283 days (10 cases). The dominant weakness classes are CWE-284 (302) and CWE-306 (88). Most affected products: hyperion_financial_management (83), webcenter_portal (35), hyperion_data_relationship_management (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.8
Publish → KEV
1283 d median(10)
Last 90 days
489 prev 8

Products

  • hyperion_financial_management 83
  • webcenter_portal 35
  • hyperion_data_relationship_management 21
  • webcenter_enterprise_capture 21
  • e-business_suite 20
  • peoplesoft_enterprise_campus_software_campus_community 20
522
Total CVEs
119
Critical
10
CISA KEV
10
Exploited

oracle vulnerabilities

CVEs affecting oracle, newest first. Open any entry for full detail, references, and exploit status.

522 CVEsRSS

CVE-2026-83028High· 7.5
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · identity_manager_connectorEPSS 0.33%via NVD
CVE-2026-83027Critical· 9.3
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Midnightoracle · identity_manager_connectorEPSS 0.35%via NVD
CVE-2026-83026High· 8.3
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · identity_manager_connectorEPSS 0.31%via NVD
CVE-2026-83025High· 8.7
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated…

▾ Twilightoracle · identity_manager_connectorEPSS 0.34%via NVD
CVE-2026-83024High· 7.8
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged at…

▾ Twilightoracle · identity_manager_connectorEPSS 0.16%via NVD
CVE-2026-83023High· 8.6
1w ago

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated a…

▾ Twilightoracle · identity_manager_connectorEPSS 0.41%via NVD
CVE-2026-83022High· 7.9
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unau…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.28%via NVD
CVE-2026-83019High· 8.1
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network acces…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.42%via NVD
CVE-2026-83018High· 7.8
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the …

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.16%via NVD
CVE-2026-83017High· 8.8
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker wi…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.43%via NVD
CVE-2026-83016High· 7.2
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to t…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.14%via NVD
CVE-2026-83015High· 7.0
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with lo…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.13%via NVD
CVE-2026-83014High· 8.1
1w ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with netw…

▾ Twilightoracle · peoplesoft_enterprise_peopletoolsEPSS 0.38%via NVD
CVE-2026-83013High· 8.8
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.43%via NVD
CVE-2026-83012High· 7.7
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.35%via NVD
CVE-2026-83010High· 8.1
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high p…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.37%via NVD
CVE-2026-83009High· 8.8
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.43%via NVD
CVE-2026-83008High· 8.8
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.43%via NVD
CVE-2026-83007High· 8.5
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.30%via NVD
CVE-2026-83006Critical· 9.1
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high p…

▾ Midnightoracle · webcenter_enterprise_captureEPSS 0.49%via NVD
CVE-2026-83005High· 8.8
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.43%via NVD
CVE-2026-83004High· 7.2
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low …

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.12%via NVD
CVE-2026-83003High· 8.5
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…

▾ Twilightoracle · webcenter_enterprise_captureEPSS 0.30%via NVD
CVE-2026-83002High· 8.5
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privil…

▾ Twilightoracle · access_managerEPSS 0.33%via NVD
CVE-2026-83001Critical· 9.1
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privile…

▾ Midnightoracle · access_managerEPSS 0.49%via NVD
CVE-2026-82992High· 7.8
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the inf…

▾ Twilightoracle · siebel_crmEPSS 0.16%via NVD
CVE-2026-73965Medium· 6.8
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network acces…

▾ Sunlitoracle · siebel_crmEPSS 0.29%via NVD
CVE-2026-73963Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-73962Critical· 9.6
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · access_managerEPSS 0.36%via NVD
CVE-2026-73959High· 8.8
1w ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker…

▾ Twilightoracle · webcenter_portalEPSS 0.43%via NVD
oracle vulnerabilities (CVEs) — page 8 · VulnSea