Vulnerabilities
938 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87272 | Local Privilege Escalation Allows Full Takeover in Oracle VM VirtualBox 7.2.16 CVE-2026-87272 is a high-severity flaw in the Core component of Oracle VM VirtualBox, affecting supported version 7.2.16. It is easily exploitable by a low-privileged attacker who already has logon access to the machine where VirtualBox executes — no user interaction is required. Successful exploitation allows the attacker to completely compromise the Oracle VM VirtualBox installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because the attack vector is local (AV:L), this primarily threatens multi-user hosts, developer workstations, and lab/builder machines where untrusted or low-privileged local accounts exist alongside VirtualBox. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there are no reports of in-the-wild exploitation at this time. Do: Upgrade VirtualBox 7.2.16 to the latest available release (newer than 7.2.16) as soon as Oracle publishes the fix via its Critical Patch Update. In the interim, restrict local account creation and enforce least privilege on hosts running VirtualBox, especially shared or multi-user systems. Check host logs for suspicious activity by low-privileged local accounts around VirtualBox processes and drivers. | 7.8 | — |
| masspotentially millions of desktop/workstation installations (only version 7.2.16 affected) | ||
| CVE-2026-87266 +1 in the same advisory: …87256 | Unauthenticated data exposure and partial DoS in Oracle Agile PLM 9.3.6 Oracle Agile PLM 9.3.6 (Application Server component of Oracle Supply Chain) contains an easily exploitable flaw reachable over HTTP that requires no authentication, no user interaction, and no privileges. A remote attacker who can reach the application server over the network can trigger the flaw to gain unauthorized access to critical data — up to complete access to all Oracle Agile PLM accessible data — and can cause a partial denial of service. The issue is scored CVSS 3.1 8.2 (high), with high confidentiality impact and low availability impact but no integrity impact. Organizations running the affected 9.3.6 release, especially any instance reachable from the internet, are at risk of sensitive product-lifecycle, engineering, and supply-chain data disclosure. No public proof of concept is known and the CVE is not on CISA's KEV list, so exploitation is not currently observed. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87266 to all Agile PLM 9.3.6 Application Server instances, obtainable via My Oracle Support. Verify that no Agile PLM application server is exposed to the public internet — place it behind a VPN or restrict access at the firewall to trusted networks. Review access and HTTP server logs around the application server for anomalous unauthenticated requests or large data retrieval, and rotate credentials for accounts with access to Agile PLM data. | 8.2 group max | — |
| nichelikely a few thousand installations globally, with only hundreds internet-exposed | ||
| CVE-2026-87265 | Privilege Escalation in Oracle Purchasing (E-Business Suite) 12.2.3–12.2.15 CVE-2026-87265 is an improper authorization flaw in the Oracle Purchasing module of Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. A low-privileged attacker with a valid account and network access via HTTP can exploit the flaw easily, without user interaction, to compromise Oracle Purchasing. A successful attack yields unauthorized creation, deletion, or modification of critical Purchasing data — or all Oracle Purchasing-accessible data — as well as unauthorized read access up to complete exposure of that data (high confidentiality and integrity impact, CVSS 8.1). Organizations running affected EBS 12.2.x releases with Purchasing exposed to authenticated users, especially internet-facing self-service deployments, are at risk. The flaw is not in the CISA KEV catalog, no public PoC is known, and no exploitation in the wild has been reported. Do: Apply the Oracle Critical Patch Update that remediates this CVE to all EBS environments on 12.2.3–12.2.15. Restrict HTTP access to EBS via network segmentation or VPN so that only trusted, authenticated users can reach the Purchasing module, and enforce least privilege on responsibilities that grant Purchasing access. Review audit trails for recent purchase orders, requisitions, and supplier records to detect any unauthorized creation, modification, or deletion. | 8.1 | — |
| moderate≈ thousands of organizations; on the order of 5,000–10,000 internet-exposed EBS instances (estimate) | ||
| CVE-2026-87264 | Authenticated Data Tampering Flaw in Oracle PeopleSoft PeopleTools Integration Broker CVE-2026-87264 is a vulnerability in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools affecting versions 8.61 through 8.63. A low-privileged authenticated attacker with network access over HTTP can easily exploit the flaw to compromise PeopleSoft Enterprise PeopleTools, and because the vulnerability has a scope change, successful attacks can significantly impact products beyond PeopleTools itself. Successful exploitation yields unauthorized creation, deletion, or modification of critical data or all PeopleTools-accessible data (CVSS 3.1: 7.7, integrity-focused impacts). Organizations running affected PeopleTools releases with HTTP-reachable Integration Broker endpoints are at risk, particularly where low-privilege application accounts are common. No public proof-of-concept or in-the-wild exploitation is currently known, and the CVE is not on the CISA KEV list. Do: Apply Oracle's latest Critical Patch Update for PeopleTools 8.61-8.63 as soon as it is available for your deployment. Restrict HTTP access to Integration Broker endpoints to trusted networks and VPN users, and enforce least-privilege roles for any accounts that can reach the application over HTTP. Review Integration Broker traffic and data-change audit logs for unauthorized modifications by low-privileged accounts. | 7.7 | — |
| moderate≈1,000-10,000 internet-reachable PeopleSoft installations (subset on PeopleTools 8.61-8.63) | ||
| CVE-2026-87259 | Local Privilege Escalation in Oracle Agile Engineering Data Management 6.2.1 CVE-2026-87259 is a high-severity (CVSS 8.4) flaw in the Engineering Communication Interface component of Oracle Agile Engineering Data Management, part of Oracle Supply Chain, affecting version 6.2.1. It is exploited by a low-privileged attacker who already has a logon on the host or infrastructure where the product executes, making it a local privilege-escalation-style weakness rather than a remotely reachable flaw. Because of a scope change, a successful attack can compromise not only Agile EDM but also significantly impact additional products on the same infrastructure. The attacker gains unauthorized ability to create, delete, or modify critical data, as well as full read access to all data accessible through the product; availability is not affected. The vulnerability is not in the CISA KEV catalog, no public proof of concept is known, and there is no evidence of in-the-wild exploitation. Do: Apply the Oracle Critical Patch Update that remediates this issue as soon as Oracle releases it, and check the Oracle advisory for the fixed build of Agile EDM 6.2.1. In the meantime, restrict and audit local OS accounts with logon access to servers hosting Agile EDM, enforce least privilege on those hosts, and monitor for unauthorized creation, deletion, or modification of engineering data via the Engineering Communication Interface. | 8.4 group max | — |
| nichelikely hundreds to low thousands of enterprise installations worldwide (no public deployment counts) | ||
| CVE-2026-87258 +1 in the same advisory: …87254 | Authenticated Data Exposure in Oracle Agile PLM 9.3.6 Folders, Files & Attachments CVE-2026-87258 is a high-severity (CVSS 3.1 base score 7.6) flaw in the Folders, Files & Attachments component of Oracle Agile PLM 9.3.6, part of Oracle Supply Chain. A remote, low-privileged attacker with HTTP access to the application can exploit it easily, but a successful attack requires interaction from a victim user other than the attacker — meaning victims must be socially engineered into clicking or approving a malicious request. A successful exploit lets the attacker read all Oracle Agile PLM accessible data (including critical data) and gain unauthorized update, insert, or delete access to some of that data; due to a scope change, the impact can extend beyond Agile PLM itself to additional products. Organizations running the supported affected version 9.3.6 are exposed, particularly if the Agile PLM web tier is reachable by broad user populations. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no active exploitation has been reported. Do: Apply the Oracle Critical Patch Update that remediates this vulnerability in Agile PLM 9.3.6 as soon as it is available. If patching is delayed, restrict HTTP access to the Agile PLM web tier via VPN or IP allowlisting, and warn users about social-engineering-driven clicks or approvals since exploitation requires victim interaction. Review low-privileged account activity and audit logs for anomalous data reads or unauthorized insert/update/delete operations against folders, files, and attachments. | 7.6 group max | — |
| nichelikely hundreds to low thousands of enterprise installations worldwide, with only a subset internet-exposed | ||
| CVE-2026-87257 | Authenticated Critical Data Exposure in Oracle Agile PLM 9.3.6 SDK CVE-2026-87257 is a vulnerability in the SDK component of Oracle Agile PLM 9.3.6 (part of Oracle Supply Chain) that allows a low-privileged attacker with network access via HTTP to compromise the Agile PLM instance. Successful exploitation yields unauthorized access to critical data or complete access to all data reachable through Oracle Agile PLM, and because the CVSS vector records a scope change (S:C), the blast radius can extend beyond Agile PLM into additional products that share its data or integrations. The flaw is rated CVSS 3.1 7.7 (high), driven entirely by confidentiality impact — integrity and availability are not affected. Any organization running the supported Agile PLM 9.3.6 release is affected, typically manufacturers and engineering organizations using it for product lifecycle management. The vulnerability is not listed in CISA's KEV catalog and no public proof-of-concept is known, so exploitation status is currently none known. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87257 to Agile PLM 9.3.6, since 9.3.6 is the affected supported version and no later version is listed in the advisory. Restrict HTTP access to the Agile PLM server so only authenticated, trusted users and networks can reach it, and enforce least-privilege roles for accounts that use the SDK. Review server and application logs for evidence of anomalous data access by low-privileged accounts, given the vulnerability's potential to expose all Agile PLM-accessible data. | 7.7 | — |
| nichelikely low-thousands of enterprise installations, with a subset (order of ~1,000+) internet-exposed (estimate) | ||
| CVE-2026-87230 | Unauthenticated Critical Flaw in Oracle Hyperion Financial Management Security Component CVE-2026-87230 is a flaw in the Security component of Oracle Hyperion Financial Management, affecting supported version 11.2.26.0.000. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks allow unauthorized creation, deletion, or modification of critical data — or all data accessible to Oracle Hyperion Financial Management — as well as unauthorized read access to that data, and because of a scope change, the impact can extend beyond Hyperion Financial Management to additional products. The vulnerability carries a maximum CVSS 3.1 base score of 10.0, driven by high confidentiality and integrity impacts. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported to date. Do: Apply the Oracle patch for this issue as soon as it is available via Oracle's Critical Patch Update for Hyperion 11.2.x, since 11.2.26.0.000 is the only listed affected version. Until patched, restrict network access to Hyperion Financial Management HTTP endpoints — remove internet exposure and place the service behind a VPN or allow-listed reverse proxy — and monitor authentication and Security component logs for unauthenticated access attempts. Verify that you are not running the affected 11.2.26.0.000 build on any production or DR instance. | 10.0 group max | — |
| moderatelikely on the order of a few thousand installations (low thousands of internet-reachable instances; unclear how many more exist on internal networks) |