2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70954 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70954

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70953 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70953

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70952 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70952

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70951 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70951

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Management). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV: CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70949 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70949

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70948 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70948

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70944 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70944

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availab CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70943 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70943

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthor CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70941 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70941

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability ca CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70940 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70940

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availa CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70931 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70931

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Workflow accessible data and unauthorize CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70929 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70929

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Manage CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70928 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70928

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availab CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70926 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70926

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70925 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70925

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Managem CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70924 — Vulnerability: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70924

Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70922 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70922

Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70921 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70921

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vu CVSSv3.1 10.0 (CRITICAL)

VNDVulnerabilityTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70920 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70920

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vul CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70918 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70918

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/A CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70909 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70909

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
CRIT

CVE-2026-70905 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70905

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impac CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70904 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70904

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Data Relationship Management executes to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vu CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70903 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70903

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data R CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:17Z
HIGH

CVE-2026-70901 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70901

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in CVSSv3.1 8.1 (HIGH)

VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score