PatchSiren

Oracle Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83408

A high-severity vulnerability exists in Oracle GraalVM for JDK and Oracle GraalVM products. The vulnerability is difficult to exploit and allows unauthenticated attackers with network access via HTTP to potentially compromise the products. Successful attacks can result in takeover of the affected products. This vulnerability affects Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12. [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83357

A high-severity vulnerability exists in Oracle GraalVM for JDK and Oracle GraalVM products. This issue, located in the Compiler component, is difficult to exploit and allows unauthenticated attackers with network access via HTTP to potentially compromise the affected systems. Successful attacks could result in a takeover of Oracle GraalVM for JDK and Oracle GraalVM. The CVSS 3.1 Base Score is 8.1, indicat [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87288

A vulnerability in Oracle GraalVM product of Oracle Java SE (component: Compiler) allows unauthenticated attackers with network access via HTTP to compromise Oracle GraalVM, potentially leading to takeover. The supported version affected is Oracle GraalVM: 25.0.4.1. This CVE was published on 2026-09-15T20:19:18.790Z and last modified on 2026-09-22T04:18:02.077Z.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87287

A vulnerability in Oracle GraalVM product of Oracle Java SE (component: Compiler) allows unauthenticated attackers with network access via HTTP to compromise Oracle GraalVM, potentially leading to takeover. The supported version affected is Oracle GraalVM: 25.0.4.1. This CVE was published on 2026-09-15T20:19:18.680Z and was last modified on 2026-09-22T04:18:01.913Z.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87286

A vulnerability in Oracle GraalVM product of Oracle Java SE (component: Compiler) allows unauthenticated attackers with network access via HTTP to compromise Oracle GraalVM, potentially leading to takeover. The supported version affected is Oracle GraalVM: 25.0.4.1. This CVE was published on 2026-09-15T20:19:18.560Z and was last modified on 2026-09-22T04:18:01.753Z.

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-87285

A vulnerability in Oracle VM VirtualBox allows high-privileged attackers to cause a denial of service (complete DOS) of Oracle VM VirtualBox. The supported version that is affected is 7.2.16. This vulnerability can be exploited by attackers with logon to the infrastructure where Oracle VM VirtualBox executes, potentially causing a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox, [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-87283

A vulnerability in Oracle VM VirtualBox allows high-privileged attackers to cause a denial of service (complete DOS) of Oracle VM VirtualBox. The supported version that is affected is 7.2.16. This vulnerability requires verification of exposure and remediation priority, as high-privileged attackers may exploit it to cause a denial of service, potentially impacting additional products due to scope change. [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-87282

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:19:17.023Z and has not been modified since then. The vulnerability in Oracle VM VirtualBox 7.2.16 allows high privileged attackers with logon to the infrastructure to compromise Oracle VM VirtualBox, potentially impacting additional products. Successful attacks can result in unauthorized abili [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-87279

A vulnerability in Oracle VM VirtualBox allows low-privileged attackers with logon access to compromise the system, potentially causing a hang or crash and allowing unauthorized data updates. This medium-severity vulnerability, tracked as CVE-2026-87279, affects Oracle VM VirtualBox version 7.2.16 and has a CVSS 3.1 Base Score of 6.1, indicating integrity and availability impacts. Successful attacks can r [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87276

A high-severity vulnerability exists in Oracle VM VirtualBox 7.2.16, which could allow a low-privileged attacker with logon access to the infrastructure to compromise the VirtualBox. The vulnerability requires human interaction and could impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox and potentially impact additional products (scope chan [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87273

CVE-2026-87273 is a high-severity vulnerability in Oracle VM VirtualBox 7.2.16, allowing unauthenticated attackers with logon to compromise the product. This vulnerability requires human interaction and can lead to a takeover of Oracle VM VirtualBox instances. The vulnerability has a CVSS score of 8.6 and affects Oracle VM VirtualBox 7.2.16. Defenders managing Oracle VM VirtualBox deployments should asses [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87272

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:19:15.917Z and has not been modified since then. The vulnerability in Oracle VM VirtualBox 7.2.16 allows low-privileged attackers with logon access to compromise the system, potentially leading to system takeover and confidentiality, integrity, and availability impacts. Defenders should priori [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87271

The CVE-2026-87271 vulnerability affects Oracle VM VirtualBox 7.2.16 on Windows hosts, allowing low-privileged attackers with logon access to compromise the system. This high-severity vulnerability has a CVSS score of 7.8, indicating potential system compromise, data confidentiality, integrity, and availability impacts. Defenders should prioritize verifying exposure, assessing user access, and applying re [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87270

The CVE-2026-87270 vulnerability affects Oracle VM VirtualBox 7.2.16 on Windows hosts, allowing low-privileged attackers with logon access to potentially take over the system. Defenders should prioritize verifying exposure and assessing the need for updates or mitigations. This vulnerability has a high severity score and requires immediate attention to prevent potential unauthorized access or disruption o [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87269

A vulnerability in Oracle VM VirtualBox allows low-privileged attackers with logon access to the infrastructure to compromise the VirtualBox instance, potentially leading to a takeover. This issue is specific to Windows hosts and has a CVSS score of 7.8, indicating high severity. The vulnerability can result in the takeover of Oracle VM VirtualBox instances. System administrators and security teams should [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87268

The CVE-2026-87268 vulnerability affects Oracle VM VirtualBox 7.2.16 on Windows hosts, allowing low-privileged attackers with logon access to potentially compromise the system. Defenders should prioritize verifying exposure and assessing potential impact. The vulnerability has a CVSS score of 7.8 and is considered high severity. It is crucial for defenders to review Oracle's security advisories for remedi [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-87267

A vulnerability in Oracle VM VirtualBox allows low-privileged attackers with network access via RDP to cause a hang or crash of the VirtualBox service. This issue is difficult to exploit and affects version 7.2.16. Successful attacks can result in a complete denial of service (DOS). The CVSS score is 5.3, indicating a medium severity. The vulnerability is in the Core component and requires low privileges [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87266

A vulnerability exists in Oracle Agile PLM (component: Application Server) version 9.3.6. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to compromise Oracle Agile PLM, potentially leading to unauthorized access to critical data or a partial denial of service (partial DOS). The CVSS 3.1 Base Score is 8.2, indicating high severity.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87265

CVE-2026-87265 is a high-severity vulnerability in Oracle Purchasing, a component of Oracle E-Business Suite. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Purchasing, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Oracle Purchasing accessible data, as well as unauthorized access to critical data [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87244

CVE-2026-87244 is a high-severity vulnerability in Oracle Hyperion Financial Management, a component of Oracle Hyperion. The vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. Defenders should assess exposure, prioritize security measures, and monitor for potential security incidents. [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87243

A high-severity vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000. This difficult-to-exploit vulnerability allows unauthenticated attackers with physical access to the communication segment to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data and unauthorized access [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87242

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:19:12.920Z and has not been modified since then. This high-severity vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers with network access via TLS to compromise the product, potentially leading to data tampering or unauthorized access. Defenders managing thi [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87241

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:19:12.807Z and has not been modified since then. This high-severity vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers to compromise data integrity and confidentiality. Defenders should assess their exposure, particularly for version 11.2.26.0.000, and imple [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87236

CVE-2026-87236 is a high-severity vulnerability in Oracle Hyperion Financial Management 11.2.26.0.000, allowing low-privileged attackers with network access via HTTP to access critical data and cause partial denial of service. The vulnerability has a CVSS 3.1 Base Score of 7.1, indicating high severity. Defenders should prioritize verifying exposure, assessing potential data access and denial of service r [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87235

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:19:12.097Z and has not been modified since then. The vulnerability affects Oracle Hyperion Financial Management version 11.2.26.0.000, and allows unauthenticated attackers with network access via SSH to compromise the system, potentially leading to unauthorized creation, deletion, or modificat [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87234

A vulnerability in Oracle Hyperion Financial Management allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access or modification. This high-severity vulnerability affects the Security component of Oracle Hyperion Financial Management version 11.2.26.0.000. Successful attacks can result in unauthorized creation, deletion, or modi [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87233

A high-severity vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000, allowing high-privileged attackers with network access via HTTP to compromise the system. This could potentially impact additional products, leading to unauthorized data access or partial denial of service. Oracle Hyperion Financial Management administrators and security teams should assess exposure, restrict netwo [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87232

A high-severity vulnerability exists in Oracle Hyperion Financial Management 11.2.26.0.000. An unauthenticated attacker with physical access to the communication segment can compromise the product, leading to unauthorized data access and modification. This vulnerability allows attackers to create, delete, or modify critical data, or access sensitive data without authorization. Defenders should assess expo [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-87230

The CVE-2026-87230 vulnerability affects Oracle Hyperion Financial Management, specifically component: Security, with version 11.2.26.0.000 being supported and vulnerable. This critical vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks can result in unauthorized creation, deletion, or modification access to cr [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87229

A vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers to compromise the system via HTTP, potentially leading to unauthorized data access and modification. The vulnerability affects the Security component of Oracle Hyperion Financial Management, version 11.2.26.0.000. Successful attacks can result in unauthorized creation, deletion or modification access to critical data [truncated]