Vulnerabilities
162 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-83099 | Unauthenticated HTTP Takeover of Oracle Forms in Fusion Middleware (CVSS 10.0) CVE-2026-83099 is a critical (CVSS 3.1 base score 10.0) unauthenticated vulnerability in the Forms Services client/server and character-mode components of Oracle Forms, part of Oracle Fusion Middleware. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, and successful exploitation results in a complete takeover of Oracle Forms with full impact to confidentiality, integrity, and availability. The CVSS vector includes a scope change (S:C), meaning attacks against the vulnerable Forms component can also significantly impact additional products on the compromised host. Affected deployments are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83099 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as an emergency change, prioritizing any Forms Services endpoints reachable over the network. Remove internet exposure for Forms servlets and restrict access to trusted networks or VPN, and place the service behind an authenticating reverse proxy where possible. Review HTTP access logs for unauthenticated requests to Forms Services endpoints and watch for anomalous process or file activity on Forms hosts, since the scope change means adjacent products on the same server may be impacted after compromise. | 10.0 group max | — |
| moderate≈ low thousands of internet-exposed Oracle Forms endpoints, plus a larger unknown population of internal enterprise deployments | ||
| CVE-2026-83059 | Unauthenticated LDAP Flaw Allows Full Takeover of Oracle Internet Directory CVE-2026-83059 is a critical (CVSS 10.0) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker with network access to the LDAP service can exploit the flaw with low complexity, requiring no privileges or user interaction. Successful exploitation results in a complete takeover of Oracle Internet Directory with high impact to confidentiality, integrity, and availability, and because the scope changes, successful attacks may also significantly impact additional products beyond OID itself. Organizations running the affected OID versions with LDAP reachable by untrusted networks are the primary at-risk population. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date. Do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all Oracle Internet Directory instances running 12.2.1.4.0 or 14.1.2.1.0, prioritizing any OID LDAP endpoints reachable from untrusted networks. Restrict network access to OID LDAP ports so only trusted directory clients can connect, and verify no unauthenticated anomalous LDAP activity has occurred on affected servers. | 10.0 group max | — |
| moderate≈ a few thousand internet-exposed OID LDAP endpoints, out of a larger base of roughly tens of thousands of internal enterprise deployments (clearly an estimate) | ||
| CVE-2026-83064 | Authenticated Takeover Vulnerability in Oracle WebCenter Portal Runtime Tools CVE-2026-83064 is a critical (CVSS 9.1) flaw in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with network access via HTTP and already-high privileges can exploit it easily to fully compromise the WebCenter Portal deployment, and because the vulnerability changes scope, successful attacks may also significantly impact additional products beyond the portal itself. The impact is total compromise of confidentiality, integrity, and availability, effectively a takeover of the affected installation. Organizations running either affected version in internet-reachable or broadly accessible deployments are at risk, though exploitation requires valid high-privileged credentials. No public proof-of-concept exists and the vulnerability is not on the CISA Known Exploited Vulnerabilities list, so no active exploitation is known. Do: Apply the Oracle Critical Patch Update that resolves CVE-2026-83064 to all WebCenter Portal installations running 12.2.1.4.0 or 14.1.2.0.0. Restrict network access to Runtime Tools and administrative HTTP endpoints so only trusted administrators and networks can reach them, and audit high-privileged accounts for signs of misuse. Review HTTP access logs for anomalous requests from privileged accounts targeting Runtime Tools endpoints. | 9.1 | — |
| moderate≈ a few thousand internet-exposed WebCenter Portal/Fusion Middleware installations, with total enterprise deployments plausibly in the low tens of thousands | ||
| CVE-2026-83039 | Authenticated Full Takeover of Oracle WebCenter Portal via Composer Flaw (CVSS 9.9) Oracle WebCenter Portal (Fusion Middleware), specifically its Composer component, contains an easily exploitable flaw in versions 12.2.1.4.0 and 14.1.2.0.0 that lets a low-privileged authenticated attacker with HTTP network access take over the portal. The CVSS 3.1 base score is 9.9 (critical) with a scope change (S:C), meaning successful attacks on WebCenter Portal can significantly impact additional products beyond the vulnerable component. Successful exploitation yields full compromise of confidentiality, integrity, and availability of the affected installation. Any organization running the two affected WebCenter Portal releases and exposing them to users over the network is at risk, particularly portals reachable from untrusted or broad internal networks. The flaw is not in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported to date. Do: Apply the Oracle Critical Patch Update remediation for WebCenter Portal to both 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable from the internet or large internal user populations. Until patched, restrict network access to the Composer component, review low-privileged portal accounts for compromise or over-broad entitlements, and monitor authentication and Composer activity logs for anomalous behavior. Also assess adjacent Fusion Middleware products for follow-on impact given the documented scope change. | 9.9 group max | — |
| moderateorder of 1,000–10,000 deployments worldwide (likely hundreds to low thousands internet-exposed), clearly an estimate | ||
| CVE-2026-83042 | Unauthenticated Remote Takeover in Oracle Identity Manager Legacy UI CVE-2026-83042 is an easily exploitable vulnerability in the OIM Legacy UI component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access via HTTP can trigger the flaw and achieve a complete takeover of Oracle Identity Manager, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Oracle has not disclosed the precise flaw class, but the pre-authentication attack path makes internet-exposed OIM consoles the primary risk. Because OIM is an identity and access management hub, compromise can expose credentials, provisioning workflows, and connected directory integrations across the enterprise. There is no known public proof-of-concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported as of this analysis. Do: Apply Oracle's latest Critical Patch Update to Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as it becomes available, since Oracle remediates these flaws through quarterly CPUs. Until patched, restrict network access to the OIM Legacy UI so it is not reachable from untrusted networks, enforce TLS, and place the console behind a VPN or reverse proxy with authentication. Review OIM logs for unauthenticated HTTP requests to legacy UI endpoints and watch for anomalous account, connector, or provisioning changes that could indicate compromise. | 9.8 | — |
| moderatelow thousands of internet-exposed OIM consoles; overall installed base likely in the thousands to low tens of thousands of enterprise deployments | ||
| CVE-2026-73963 | Unauthenticated HTTP Takeover Flaw in Oracle WebCenter Portal Portlet Services (CVSS 9.8) CVE-2026-73963 is a critical (CVSS 9.8) vulnerability in the Portlet Services component of Oracle WebCenter Portal, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack allows complete takeover of the Oracle WebCenter Portal instance, with high impact on confidentiality, integrity, and availability. Organizations running the affected on-premises portal deployments exposed to network attackers are at risk of full system compromise. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA Known Exploited Vulnerabilities list. Do: Apply the Oracle Critical Patch Update that addresses CVE-2026-73963 to WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict or block external HTTP access to Portlet Services endpoints via firewall rules or a WAF, and require authentication at a reverse proxy. Review logs and the portal for signs of compromise such as unexpected administrative accounts or configuration changes, since successful exploitation yields full takeover. | 9.8 group max | — |
| moderatelikely on the order of a few thousand internet-reachable installations | ||
| CVE-2026-83038 | Low-Privilege Authenticated RCE in Oracle WebLogic Server TopLink Integration CVE-2026-83038 is a critical (CVSS 9.9) vulnerability in the TopLink Integration component of Oracle WebLogic Server, part of Oracle Fusion Middleware. A remote attacker who already holds low-privileged credentials for the server and has HTTP network access can exploit the flaw easily, and a successful attack results in a complete takeover of Oracle WebLogic Server. The CVSS vector includes a scope change (S:C), meaning compromise of WebLogic can significantly impact additional products beyond the vulnerable component itself, with high impact on confidentiality, integrity, and availability. Affected deployments are those running WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. As of this analysis, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed in-the-wild exploitation. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83038 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0. Because exploitation requires only low-privileged HTTP access, restrict management and application HTTP endpoints to trusted networks/VPNs, enforce strong authentication and least-privilege on all WebLogic accounts, and audit low-privilege accounts for abuse. Review servers for signs of post-exploitation such as unexpected deployments, scheduled jobs, or new OS-level users, since successful attacks lead to full server takeover with scope change to adjacent products. | 9.9 | — |
| largeOn the order of tens of thousands of internet-exposed WebLogic servers (roughly 10,000–100,000), plus a substantial internal enterprise estate | ||
| CVE-2026-83031 | Privilege Escalation to Full Takeover in Oracle WebCenter Sites (CVSS 9.9) Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable flaw that allows a low-privileged authenticated attacker with network access via HTTP to compromise the product and achieve a complete takeover of the WebCenter Sites installation. The vulnerability carries a CVSS 3.1 base score of 9.9 with a scope change, meaning successful attacks on WebCenter Sites can significantly impact additional products beyond the initially affected component. Successful exploitation results in high impact to the confidentiality, integrity, and availability of the compromised system. Affected deployments are Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. There is no known public proof-of-concept and no evidence of in-the-wild exploitation; the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83031 to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as the highest priority. Until patched, restrict HTTP access to WebCenter Sites (especially administrative and content-management interfaces) via VPN or IP allowlisting, enforce least privilege on contributor accounts, and review authentication and audit logs for anomalous activity by low-privileged users. Because the vulnerability has a scope change, also verify patch levels and inspect logs on adjacent Fusion Middleware products that share the same infrastructure. | 9.9 group max | — |
| moderateLikely on the order of a few thousand internet-reachable WebCenter Sites instances worldwide; total enterprise deployments unknown | ||
| CVE-2026-83029 | Critical Broken Access Control in Oracle Managed File Transfer Runtime Server Oracle Managed File Transfer (MFT), a component of Oracle Fusion Middleware, contains an easily exploitable broken access control flaw in the MFT Runtime Server affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker holding only low-privileged (authenticated) credentials and network access via HTTP can trigger the flaw, and because the vulnerability carries a scope change, successful attacks may also significantly impact products beyond MFT itself. Exploitation gives the attacker unauthorized ability to create, delete, or modify critical data and full unauthorized read access to all data accessible through Oracle Managed File Transfer. Organizations running either affected version, particularly with the MFT Runtime Server reachable beyond internal trusted networks, are most at risk. No public proof-of-concept exists, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported to date. Do: Apply the current Oracle Critical Patch Update (CPU) to MFT Runtime Server on both 12.2.1.4.0 and 14.1.2.0.0, as Oracle remediates Fusion Middleware flaws through its quarterly CPU cycle. Until patched, restrict HTTP access to the MFT Runtime Server to trusted networks or VPN, and audit low-privileged MFT accounts for legitimacy and least privilege. Review MFT audit and transfer logs for unexpected data creation, deletion, modification, or reads attributable to low-privilege users, which could indicate attempted or successful exploitation. | 9.6 | — |
| nicheunknown; plausibly on the order of hundreds to low thousands of enterprise MFT deployments worldwide | ||
| CVE-2026-83027 | Unauthenticated Adjacent-Network Data Compromise in Oracle Identity Manager Connector CVE-2026-83027 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle Identity Manager (OIM) Connector, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An attacker only needs a foothold on the same physical network segment where the OIM Connector executes — no privileges or user interaction are required — to trigger the flaw. A successful attack can compromise the connector and, because of a scope change, may significantly impact additional products beyond OIM Connector itself. The attacker gains unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to critical or all OIM Connector-accessible data, with high confidentiality and integrity impact (CVSS 3.1 base score 9.3, availability unaffected). No public proof of concept exists and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not known. Do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83027 to OIM Connector 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as your patch cycle allows. Restrict and monitor access to the network segments where the OIM Connector executes (e.g., VLAN segmentation and allow-listing) since exploitation requires only adjacency, not authentication. Review identity stores and connected target systems for unauthorized data creation, modification, or deletion, keeping in mind the scope change can affect products beyond the connector itself. | 9.3 | — |
| nicheLikely low thousands of enterprise deployments worldwide (order of 1,000–10,000 organizations) | ||
| CVE-2026-83021 | Unauthenticated HTTP Takeover Flaw in Oracle WebLogic Server Web Container CVE-2026-83021 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Web Container component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It is triggered remotely by an unauthenticated attacker sending crafted requests over HTTP to an affected WebLogic instance, requiring no privileges or user interaction. A successful exploit results in a complete takeover of Oracle WebLogic Server, and because the CVSS scope is changed, successful attacks may also significantly impact additional products beyond WebLogic itself. The supported affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. As of this writing, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, though WebLogic's history as a high-value target makes prompt patching essential. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83021 to all WebLogic Server installations running 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 as soon as it is available, prioritizing any instance reachable over HTTP. Until patched, restrict network access to WebLogic HTTP/Admin listen ports (e.g., 7001/7002) to trusted sources via firewall rules, and review logs for unauthenticated anomalous HTTP requests against the Web Container. Also assess connected products and services, since successful attacks can impact systems beyond WebLogic itself. | 10.0 | — |
| large≈ tens of thousands of internet-exposed WebLogic instances, plus a larger unknown population of internal enterprise deployments | ||
| CVE-2026-83020 | Unauthenticated Takeover Flaw in Oracle Platform Security for Java (Fusion Middleware) CVE-2026-83020 is a critical (CVSS 3.1 base score 10.0) vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (OPSS), part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful exploitation results in complete takeover of Oracle Platform Security for Java, and because of a scope change, attacks may significantly impact additional products beyond OPSS itself, with full impact to confidentiality, integrity, and availability. Organizations running WebLogic Server or other Fusion Middleware deployments on the affected OPSS versions are exposed wherever the relevant HTTP endpoints are reachable. As of now, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Apply the Oracle Critical Patch Update (CPU) that remediates CVE-2026-83020 to all OPSS installations on 12.2.1.4.0 and 14.1.2.0.0, prioritizing any systems with HTTP endpoints exposed to untrusted networks. Restrict network access to administrative and OPSS-related HTTP endpoints so only trusted hosts can reach them, and monitor logs for unauthenticated HTTP requests targeting Fusion Middleware/OPSS paths until patching is complete. | 10.0 group max | — |
| large≈ tens of thousands of internet-exposed Oracle Fusion Middleware/WebLogic hosts, plus a larger unknown number of internal enterprise deployments | ||
| CVE-2026-83006 | High-Privilege Takeover Flaw in Oracle WebCenter Enterprise Capture Client Bundle CVE-2026-83006 is a critical (CVSS 9.1) vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a high-privileged attacker who has network access to the product via HTTP, requiring no user interaction. Successful exploitation results in a complete takeover of Oracle WebCenter Enterprise Capture with high impact to confidentiality, integrity, and availability, and due to a scope change the attack may also significantly impact additional products beyond the vulnerable component. Organizations running either affected version in their capture workflows are exposed, though the high-privilege prerequisite limits the attacker pool to compromised or malicious privileged accounts. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation to date. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83006 to both 12.2.1.4.0 and 14.1.2.0.0 deployments, prioritizing any instance reachable over HTTP. Until patched, restrict network access to Enterprise Capture client endpoints and audit privileged accounts for anomalous activity, since exploitation requires high privileges and could cascade to other products via the scope change. | 9.1 | — |
| nichelikely low thousands of deployments worldwide, with only a small fraction (est. hundreds) internet-reachable | ||
| CVE-2026-73962 +1 in the same advisory: …83001 | Authenticated Access Bypass in Oracle Access Manager Enables Full Compromise Oracle Access Manager (OAM), the SSO/authentication tier of Oracle Fusion Middleware, contains a critical flaw (CVSS 3.1 base 9.6) in its Authentication Engine affecting versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker who already holds any valid account can exploit it over HTTPS with no user interaction, needing only network access and a low-complexity attack. Successful exploitation allows unauthorized creation, deletion, or modification of critical OAM data and complete read access to all data OAM can reach; because the scope changes, attacks can also significantly impact additional products that trust OAM for authentication. Any organization running the affected OAM versions as its web single sign-on layer is exposed, particularly where OAM endpoints are internet-facing. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported, though OAM flaws have historically attracted attackers after disclosure. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73962 to OAM 12.2.1.4.0 and 14.1.2.1.0 (typically the April 2026 or later CPU bundle patch for each affected release). Restrict OAM administration and server endpoints to trusted networks or VPNs, and enforce MFA for accounts that can authenticate to OAM to blunt the low-privileged-attacker prerequisite. Review authentication policies, user stores, and audit logs on OAM instances for unauthorized changes or anomalous authenticated sessions. | 9.6 group max | — |
| moderate≈5,000–15,000 internet-exposed OAM deployments, with downstream user populations potentially far larger | ||
| CVE-2026-82999 | Authenticated Takeover Flaw in Oracle Service Delivery Platform Messaging Enabler (CVSS 9.9) Oracle Service Delivery Platform, a component of Oracle Fusion Middleware (specifically its Messaging Enabler component), contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker with only low-privileged credentials and HTTP network access to the platform can exploit the flaw, which successful exploitation results in a complete takeover of the Service Delivery Platform. Because the vulnerability has a scope change (CVSS S:C), successful attacks may also significantly impact additional products beyond Service Delivery Platform itself, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.9). Affected organizations are typically communications and digital service providers running Oracle SDP on the listed Fusion Middleware versions. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known. Do: Apply the latest Oracle Critical Patch Update to Service Delivery Platform installations running 12.2.1.4.0 or 14.1.2.0.0 as soon as patches are available. Restrict HTTP access to SDP and Messaging Enabler interfaces to trusted administrative networks, and enforce least privilege and strong credential controls for all SDP accounts since valid low-privileged access is required. Given the scope-change impact on additional products, review logs for anomalous activity by low-privileged accounts and assess adjacent systems for compromise. | 9.9 group max | — |
| nichelikely hundreds to low thousands of deployments worldwide at telecom/service providers (exact count unknown) | ||
| CVE-2026-76675 | Authenticated Command Injection in HPE Aruba EdgeConnect SD-WAN Gateways A command injection vulnerability exists in the command line interface (CLI) of HPE Aruba Networking EdgeConnect SD-WAN Gateways, rated critical at CVSS 9.1. It is triggered when a remote attacker who already holds high-privilege (administrative) credentials submits crafted input to the gateway's CLI, allowing arbitrary commands to be executed on the underlying operating system. Successful exploitation gives the attacker full control of the appliance, compromising its confidentiality, integrity, and availability, and potentially the wider SD-WAN fabric it anchors. The flaw affects EdgeConnect SD-WAN Gateway deployments wherever the vulnerable CLI is reachable. No public proof of concept is known, the CVE is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported, though the high privilege requirement and lack of user interaction make insider-threat and credential-reuse scenarios the primary risk paths. Do: Apply HPE's patched firmware as soon as the vendor advisory specifies fixed versions. Restrict CLI/SSH and management access to trusted administrative networks via ACLs or a dedicated management plane, rotate high-privilege admin credentials, and enforce role-based access so fewer accounts hold the high privileges this flaw requires. Review gateway logs for unexpected CLI command execution or configuration anomalies indicative of post-exploitation activity. | 9.1 | — |
| large≈ tens of thousands of appliances deployed worldwide (order of 10^4 systems), with a subset of thousands likely internet-reachable | ||
| CVE-2026-76674 | Unauthenticated Buffer Overflow RCE in HPE EdgeConnect SD-WAN Gateways CVE-2026-76674 is a critical (CVSS 9.8) buffer overflow vulnerability in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways (EdgeConnect OS/ECOS appliances). It is triggered remotely over the network with no authentication, no privileges, and no user interaction required, and successful exploitation allows an attacker to execute arbitrary commands on the gateway's OS, leading to complete system compromise of the appliance. Affected parties are enterprises and service providers operating HPE EdgeConnect SD-WAN branch or data-center gateways, especially any with management or data-plane services reachable from untrusted networks. Because gateways sit at the network edge, compromise can enable traffic interception or pivoting into internal corporate networks. No public proof of concept is known and the flaw is not in CISA's KEV catalog, so no active exploitation has been reported to date. Do: Apply the patched EdgeConnect OS release specified in HPE's security bulletin to all affected gateways as soon as it is available (the exact fixed version must be taken from the HPE advisory, as it is not stated here). In the interim, restrict gateway management and service ports to trusted orchestrator/admin networks using firewall rules or ACLs, and run external scans to confirm none of your gateways are internet-reachable. Monitor gateway logs, the HPE advisory, and the CISA KEV catalog for signs of exploitation. | 9.8 | — |
| moderate≈ low-thousands to ~10,000 internet-exposed EdgeConnect gateway/orchestrator endpoints, within a larger installed base of enterprise gateways | ||
| CVE-2026-76673 | Unauthenticated Auth Bypass in HPE Aruba EdgeConnect SD-WAN Orchestrator API CVE-2026-76673 is an authentication-bypass flaw in the API of HPE Aruba Networking's EdgeConnect SD-WAN Orchestrator that lets an unauthenticated remote attacker circumvent existing authentication controls over the network, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation grants the attacker administrative privileges on the Orchestrator, which amounts to complete compromise of the Orchestrator host and, by extension, potential control over the managed SD-WAN fabric. Any organization operating an EdgeConnect SD-WAN Orchestrator (on-premises or provider/cloud-hosted) is affected, particularly instances whose API interface is reachable from untrusted networks. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and there are no reports of in-the-wild exploitation as of this analysis. The high severity and network-exploitable nature still make patching urgent for exposed deployments. Do: Apply HPE's patch immediately per the Aruba Networking security advisory and confirm your Orchestrator version against the affected/fixed list. Until patched, restrict Orchestrator API and management access to trusted networks or VPN and enforce allow-listing at edge firewalls. Review Orchestrator and host logs for unexplained unauthenticated API activity or new admin accounts, and rotate credentials and API keys if compromise is suspected. | 9.8 | — |
| moderatethousands of enterprise SD-WAN deployments; likely hundreds to low thousands of internet-reachable Orchestrator instances | ||
| CVE-2026-76672 | Authenticated Secret Disclosure in HPE SD-WAN Orchestrator Cache Sync Endpoint CVE-2026-76672 is a critical (CVSS 9.9) information disclosure flaw in HPE's SD-WAN Orchestrator affecting the cache synchronization endpoint. An authenticated remote attacker holding only read-only privileges can send a specially crafted request to that endpoint, which returns sensitive configuration data without further authorization checks. Successful exploitation discloses third-party API tokens and credentials, which could enable lateral movement into external security platforms integrated with the orchestrator. The vulnerability affects HPE SD-WAN Orchestrator deployments exposed to authenticated users; no specific version ranges were provided in the advisory data. There is no known public proof of concept and the flaw is not on CISA's KEV list, so exploitation status is currently none known. Do: Apply the patched release identified in HPE's security bulletin for the SD-WAN Orchestrator as soon as it is available. Restrict orchestrator management access to trusted admin networks or VPN, and audit logs for unusual requests to the cache synchronization endpoint from read-only accounts. Rotate any third-party API tokens and credentials configured on the orchestrator, since exposed secrets could enable lateral movement to connected security platforms. | 9.9 | — |
| moderate≈1,000–5,000 orchestrator deployments worldwide (one management instance per enterprise SD-WAN estate) | ||
| CVE-2026-76670 +1 in the same advisory: …76669 | Authenticated Privilege Escalation in HPE EdgeConnect SD-WAN Orchestrator API HPE Networking EdgeConnect SD-WAN Orchestrator contains privilege escalation flaws in its API that let a remote, low-privileged authenticated user escalate to administrative privileges. Exploitation is triggered by sending crafted requests to the orchestrator's API as any valid low-privilege account, with no user interaction required. A successful attacker gains full administrative control of the orchestrator, which HPE describes as leading to complete system compromise — and because the orchestrator centrally manages an organization's SD-WAN fabric, this also puts the wider network edge at risk. The issue affects customers running HPE Networking EdgeConnect SD-WAN Orchestrator (formerly Aruba EdgeConnect / Silver Peak Unity Orchestrator), in both on-premises and HPE-managed cloud deployments; specific affected versions were not stated in the advisory data. The flaw is rated critical (CVSS 9.9), but no public proof of concept exists, it is not in the CISA KEV catalog, and no in-the-wild exploitation is known. Do: Apply the patched release specified in HPE's security bulletin for EdgeConnect SD-WAN Orchestrator as soon as it is available, prioritizing any orchestrator whose management interface or API is reachable from untrusted networks. Restrict API and management-plane access to trusted admin networks or VPN, enforce least-privilege API roles, and rotate credentials for all low-privileged API accounts. Review orchestrator audit logs for anomalous privilege changes or unfamiliar API activity by low-privilege users. | 9.9 | — |
| moderate≈1,000–10,000 orchestrator deployments worldwide, each managing an enterprise SD-WAN with many sites and users | ||
| CVE-2026-73961 | Unauthenticated Takeover Flaw in Oracle JDeveloper ADF Faces (Fusion Middleware) CVE-2026-73961 is a critical vulnerability (CVSS 3.1 base score 9.8) in the ADF Faces component of Oracle JDeveloper, part of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated attacker who has network access via HTTP, requiring no privileges and no user interaction. A successful attack can result in complete takeover of the Oracle JDeveloper installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported. Do: Apply the Oracle Critical Patch Update that remediates CVE-2026-73961 to all JDeveloper 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is available. Restrict HTTP network access to JDeveloper and associated development servers so they are reachable only from trusted internal networks. Audit those systems for signs of unauthenticated HTTP access or unexpected configuration changes until patched. | 9.8 | — |
| nicheunknown; likely low thousands to tens of thousands of developer installations, with very few internet-exposed instances |