PatchSiren

Oracle CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle CVE published 2026-09-15

CVE-2026-83025

A high-severity vulnerability exists in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. This difficult-to-exploit vulnerability allows an unauthenticated attacker with network access via TCP to compromise the product. It affects versions 12.2.1.4.0 and 14.1.2.1.0, with a CVSS score of 8.7, indicating high confidentiality and integrity impacts. Successful attacks can lead to una [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-83024

A vulnerability in Oracle Identity Manager Connector allows low-privileged attackers with logon access to compromise the system, potentially leading to takeover. Oracle has released a security advisory addressing this issue. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, with a CVSS score of 7.8, indicating high severity. Defenders should assess exposure and apply the advisory to prevent po [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-83023

The CVE-2026-83023 vulnerability affects Oracle Identity Manager Connector, specifically versions 12.2.1.4.0 and 14.1.2.1.0. This vulnerability, with a CVSS score of 8.6, allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-83002

A vulnerability in Oracle Access Manager's Authentication Engine component allows low-privileged attackers with network access via HTTP to potentially compromise the product, with a scope change impacting additional products. Successful attacks can result in takeover of Oracle Access Manager. The vulnerability has a CVSS 3.1 Base Score of 8.5, indicating high severity. Defenders should assess exposure and [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-83001

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with high privileges and network access via HTTP can easily exploit this vulnerability, potentially compromising Oracle Access Manager and impacting additional products due to the scope change. S [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73962

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows a low-privileged attacker with network access via HTTPS to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can lead to unauthorized creation, deletio [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-73958

A vulnerability in Oracle Access Manager's Authentication Engine component allows unauthenticated attackers with network access via HTTP to potentially compromise the product. Successful attacks can result in a takeover of Oracle Access Manager. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 8.1 indicating high severity. The vulnerability is difficult to exploit but ca [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73950

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:17:46.133Z and has not been modified since then. This critical vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to takeover. The affected versions are 12.2.1.4.0 and 14.1.2 [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73947

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can easily exploit this vulnerability to compromise Oracle Access Manager, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73946

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. An attacker with high privileges and network access via HTTP can easily exploit this vulnerability, potentially leading to a takeover of Oracle Access Manager. The scope of the vulnerability is not limited t [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73945

A critical vulnerability exists in Oracle Access Manager, specifically in the Authentication Engine component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows a low-privileged attacker with network access via HTTP to compromise Oracle Access Manager easily. Successful attacks can lead to a takeover of Oracle Access Manager, with a CVSS 3.1 Base Score of [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73944

The CVE-2026-73944 vulnerability affects Oracle Access Manager, specifically its Authentication Engine component, in versions 12.2.1.4.0 and 14.1.2.1.0. This critical vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critica [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-73943

CVE-2026-73943 is a high-severity vulnerability in the Oracle Identity Manager product, specifically in the OIM Legacy UI component. This vulnerability allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and unauthorized updates to some accessible data. Oracle Identity Manager administrators and security teams [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-73942

A vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Identity Manager, potentially leading to a takeover of the product. The vulnerability has a CVSS score of 8.8, indicating high severity. Identity Manager administrators and securi [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-73941

The CVE-2026-73941 vulnerability affects the Oracle Access Manager product of Oracle Fusion Middleware, specifically the Authentication Engine component. This high-severity vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or comple [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-73940

CVE-2026-73940 is a critical vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. This vulnerability allows unauthenticated attackers with network access via T3, IIOP to compromise the system, potentially leading to a takeover of Oracle Access Manager. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. Oracle Access Manager [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-73926

A high-severity vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows high-privileged attackers with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthor [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-71163

A critical vulnerability exists in Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Access Manager, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized access to c [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-71133

The CVE-2026-71133 vulnerability affects Oracle Access Manager's Authentication Engine component, allowing unauthenticated attackers with network access via HTTP to compromise the product. This critical vulnerability has a CVSS score of 10.0 and can lead to a complete takeover of Oracle Access Manager. Defenders should prioritize verifying exposure, assessing network access controls, and applying vendor r [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-71047

A vulnerability in Oracle Identity Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to takeover. Oracle has released an advisory and NVD has analyzed the vulnerability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. Defenders should assess their exposure and apply patches or mitigations as necessar [truncated]

HIGH Oracle CVE published 2026-09-15

CVE-2026-70915

A vulnerability in Oracle Identity Manager allows low-privileged attackers with network access to compromise the product, potentially leading to takeover. Oracle has released an advisory and NVD has analyzed the vulnerability. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. It allows low-privileged attackers with network access via T3 or IIOP to compromise the product [truncated]

CRITICAL Oracle CVE published 2026-09-15

CVE-2026-70913

A critical vulnerability exists in Oracle Identity Manager, allowing unauthenticated attackers to compromise the system via HTTP. This vulnerability, with a CVSS score of 9.8, poses a significant risk as it can lead to system takeover. Defenders should assess exposure and prioritize remediation, especially for versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability's high impact on confidentiality, integrit [truncated]

Known exploited Oracle CVE published 2026-08-24

CVE-2026-21962

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T00:00:00.000Z and has not been modified since then. The Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability (CVE-2026-21962) is a known exploited vulnerability affecting Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in installations, potent [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73939

CVE-2026-73939 is a high-severity vulnerability in the Helidon component of Oracle Fusion Middleware's Imperative Web Server. The vulnerability, which has a CVSS 3.1 Base Score of 8.6, allows unauthenticated attackers with network access via HTTP to compromise Helidon, potentially leading to unauthorized creation, deletion, or modification of critical data or all Helidon accessible data. This vulnerabilit [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73938

The CVE-2026-73938 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. This vulnerability has a CVSS 3.1 Base Score of 7.5, indicating high severity, and allows unauthenticated attackers with network access via HTTP to compromise Helidon, potentially leading to unauthorized access to critical data. The supported version that is affect [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73937

CVE-2026-73937 is a vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. This vulnerability allows unauthenticated attackers with network access via HTTP/2 to compromise Helidon, potentially leading to Denial of Service (DOS) and unauthorized read access to a subset of Helidon accessible data. The CVSS 3.1 Bas [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73936

The CVE-2026-73936 vulnerability affects the Imperative Web Server component of Helidon version 4.5.1. This vulnerability is classified as easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise Helidon. Successful attacks can result in a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5, indicating a high severity with [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73935

The CVE-2026-73935 vulnerability in Helidon 4.5.1 is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP/2 to compromise Helidon, resulting in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5 (Availability impacts). This vulnerability affects Helidon 4.5.1 and may impact system a [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73934

The CVE-2026-73934 vulnerability affects the Imperative Web Server component of Helidon 3.2.19, allowing unauthenticated attackers with network access via HTTP/2 to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5 (Availability impacts). Evidence is limited to public sources and may not reflect the full scope of affected systems. Defenders should verify [truncated]

HIGH Oracle CVE published 2026-08-18

CVE-2026-73933

CVE-2026-73933 is a vulnerability in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The vulnerability has a CVSS score of 7.3 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized data access and partial denial of service. Helidon version 4.5.3 is affected, and users should prioritize patch [truncated]