These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A critical vulnerability exists in Oracle Hyperion Data Relationship Management 11.2.26.0.000. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all accessible data.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:59.820Z and has not been modified since then. The vulnerability in Oracle Hyperion Data Relationship Management 11.2.26.0.000 allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized creation, deletion, or modification acce [truncated]
A vulnerability in Oracle Product Hub, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. This issue affects versions 12.2.3 through 12.2.15 and can lead to unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. The vulnerability has a high severity with a CVSS 3.1 Base Score of 7.7, i [truncated]
A vulnerability in Oracle Product Hub of Oracle E-Business Suite (component: Item Catalog) has been identified. The vulnerability affects versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data.
A vulnerability in Oracle Product Hub of Oracle E-Business Suite, specifically in the Internal Operations component, allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in a takeover of Oracle Product Hub. The vulnerability is easily exploitable, and its CVSS 3.1 Base Score is 8.8, indicating high severity due to its impact on confidentiali [truncated]
A high-severity vulnerability exists in Oracle Product Hub within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. This easily exploitable vulnerability allows high-privileged attackers with network access via HTTP to compromise Oracle Product Hub, potentially leading to a takeover of the product. The vulnerability is in the Internal Operations component and has a CVSS 3.1 Base Score of [truncated]
A high-severity vulnerability exists in Oracle Product Hub within Oracle E-Business Suite, specifically in the Internal Operations component. The vulnerability affects versions 12.2.3 through 12.2.15 and allows a high-privileged attacker with network access via HTTP to compromise Oracle Product Hub, potentially leading to a takeover of the product.
A high-severity vulnerability exists in Oracle Coherence, a product of Oracle Fusion Middleware, specifically in the Core component. This vulnerability, which has a CVSS score of 7.5, allows a low-privileged attacker with network access via HTTP to potentially compromise Oracle Coherence, leading to takeover. The affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
A low-privileged attacker with logon to the infrastructure where Oracle Coherence executes could compromise Oracle Coherence to read a subset of accessible data. This is a difficult-to-exploit vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core), affecting version 15.1.1.0.0. The CVSS score is 2.5, indicating low severity. Defenders should prioritize verifying exposu [truncated]
A vulnerability in Oracle Coherence of Oracle Fusion Middleware allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in a takeover of Oracle Coherence. The CVSS 3.1 Base Score is 8.8, indicating high severity. This vulnerability affects versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 of Oracle Coherence. Defenders should assess exposure and [truncated]
The CVE-2026-83410 vulnerability affects Oracle Coherence, a product of Oracle Fusion Middleware, specifically in its Core component. This vulnerability is easily exploitable by low-privileged attackers with network access via multiple protocols, potentially leading to a takeover of Oracle Coherence. The affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The CVSS 3.1 Base Score [truncated]
A vulnerability in Oracle Forms allows unauthenticated attackers to read a subset of Oracle Forms data. Defenders should assess exposure, prioritize remediation, and verify inventory. The vulnerability affects Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0, and allows attackers with network access via HTTP to compromise Oracle Forms. Successful attacks can result in unauthorized read access to a subset [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:21.000Z and has not been modified since then. This critical vulnerability in Oracle Forms allows unauthenticated attackers to compromise the system via HTTP. Affected versions are 12.2.1.19.0 and 14.1.2.0.0, with a CVSS score of 9.8 indicating critical severity. Defenders should prioritize [truncated]
A critical vulnerability exists in Oracle Forms, specifically in the Forms Services, C/S, Charmode component. This vulnerability allows an unauthenticated attacker with network access via TCP to compromise Oracle Forms, potentially leading to unauthorized creation, deletion, or modification of critical data or all Oracle Forms accessible data, as well as unauthorized access to critical data or complete ac [truncated]
A critical vulnerability exists in Oracle Forms, specifically in the Forms Services, C/S, Charmode component. The vulnerability, CVE-2026-83100, has a CVSS score of 9.8 and allows an unauthenticated attacker with network access via HTTP to compromise Oracle Forms, potentially leading to a takeover of the system. This vulnerability is considered high risk due to its ease of exploitation and potential impac [truncated]
A critical vulnerability exists in Oracle Forms, specifically in the Forms Services, C/S, Charmode component. This vulnerability, tracked as CVE-2026-83099, allows an unauthenticated attacker with network access via HTTP to compromise Oracle Forms easily. The vulnerability affects Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0. Successful exploitation can lead to a complete takeover of Oracle Forms, wit [truncated]
A critical vulnerability exists in Oracle Forms, specifically in the Forms Services, C/S, Charmode component. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Forms, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is 9.8, indicating a high impact on Confidentiality, Integrity, and Availability.
A vulnerability in Oracle Forms allows high-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data modifications and service disruptions. The vulnerability, tracked as CVE-2026-83097, affects Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0. Successful attacks can result in unauthorized creation, deletion, or modification access to critical dat [truncated]
The CVE-2026-83095 vulnerability affects Oracle Forms, specifically versions 12.2.1.19.0 and 14.1.2.0.0. This critical vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to a takeover of Oracle Forms. Defenders should prioritize verifying exposure of Oracle Forms instances, especially versions 12.2.1.19.0 and 14.1.2.0.0, and assess the [truncated]
A critical vulnerability exists in Oracle Forms, specifically in the Forms Services, C/S, Charmode component. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Forms, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is 9.8, indicating a high impact on Confidentiality, Integrity, and Availability.
A vulnerability in Oracle Forms allows unauthenticated attackers with network access via HTTP to compromise Oracle Forms, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Forms accessible data. This high-severity vulnerability, with a CVSS 3.1 Base Score of 8.6, requires immediate attention from Oracle Forms a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:15.443Z and has not been modified since then. The vulnerability affects Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0, allowing unauthenticated attackers with network access via T3 or IIOP to compromise the directory, potentially leading to takeover. Defenders should prioriti [truncated]
A critical vulnerability exists in Oracle Internet Directory, a component of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-83062, affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Internet Directory, potentially leading to a takeover of the directory. The CVSS 3.1 Base Score is 9.8, indicating a critical severity level.
A critical vulnerability exists in Oracle Internet Directory, a component of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-83061, affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Internet Directory, potentially leading to a takeover of the directory. Oracle has provided a vendor advisory for this issue.
A critical vulnerability exists in Oracle Internet Directory, a component of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-83060, affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Internet Directory, potentially leading to a takeover of the directory. Oracle has provided a vendor advisory for this issue.
The CVE-2026-83054 vulnerability affects Oracle Internet Directory, a component of Oracle Fusion Middleware. This vulnerability, classified under OID LDAP Server, allows an unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory, potentially leading to its takeover. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating critical severity with high impacts on c [truncated]
A critical vulnerability exists in Oracle Identity Manager, specifically in the OIM Legacy UI component. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager, potentially leading to a complete takeover of the system. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, with a CVSS 3.1 Base Score of 9.8, in [truncated]
A high-severity vulnerability exists in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This difficult-to-exploit vulnerability allows unauthenticated attackers with access to the physical communication segment to potentially compromise the connector, leading to takeover. The CVSS score is 7.5, indicating high confidentiality, integrity, and availability impacts.
A critical vulnerability exists in Oracle Identity Manager Connector, allowing an unauthenticated attacker with physical access to the communication segment to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data.
A high-severity vulnerability exists in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83026, has a CVSS score of 8.3 and can be exploited by an unauthenticated attacker with access to the physical communication segment. Successful exploitation can lead to a takeover of Oracle Identity Manager Connector and potentially impact additional products.