ZeroHour
Product

Oracle Hyperion

2 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Oracle Critical Security Patch Update, September 2026 Review

Oracle's September 2026 Critical Patch Update fixes 673 vulnerabilities, including 104 critical, with many remotely exploitable in E-Business Suite and Fusion Middleware.

Oracle released 673 security patches in its September 2026 Critical Patch Update: 104 rated critical, 503 high, and 59 medium. Oracle E-Business Suite received the most patches (159, 24% of total), with 19 exploitable without credentials including CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 at CVSS 9.8. Fusion Middleware received 153 patches with 78 remotely exploitable without authentication, and 41 patches address third-party open-source component flaws. Qualys published detection QIDs for vulnerable assets.

Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

Oracle's September 2026 Critical Patch Update ships 673 patches across 17 product families, including 100+ critical and 240+ remotely exploitable flaws.

Oracle's September 2026 Critical Security Patch Update ships 673 patches covering 672 unique CVEs, with more than 130 additional CVEs resolved through bundled fixes, pushing the effective total past 800. Over 100 flaws are critical severity and more than 240 are remotely exploitable without authentication. Oracle E-Business Suite received 159 fixes, Fusion Middleware 153 (78 unauthenticated and network-exploitable), and Hyperion 102. No in-the-wild exploitation of these specific flaws is reported, but Oracle cites CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0).

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle's August 2026 Critical Patch Update fixes 943 vulnerabilities; Oracle Fusion Middleware and Hyperion received the most patches at 262.

Oracle released its August 2026 Critical Patch Update, addressing 943 security vulnerabilities across multiple product families, including third-party components bundled in Oracle products. Oracle Fusion Middleware and Oracle Hyperion received the highest number of fixes with 262 patches. Several of the addressed vulnerabilities impact more than one product.

Qualys ThreatPROTECT · 28d agoAdvisory2

Related CVEs

  • Unauthenticated Access Control Bypass in Oracle HTTP Server and WebLogic Proxy Plug-in
    CVE-2026-21962 is an improper access control flaw (CWE-284) in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in (components: the plug-in for Apache HTTP Server and the plug-in for IIS), part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can trivially exploit it, and the scope-change designation means a successful attack can significantly impact additional products beyond the plug-in itself. The attacker gains unauthorized access to critical data (potentially all accessible data) as well as the ability to create, delete, or modify critical data, reflected in the maximum CVSS 10.0 score with high confidentiality and integrity impacts and no availability impact. Organizations running the affected versions - 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0 for Oracle HTTP Server and the Apache plug-in, and 12.2.1.4.0 only for the IIS plug-in - especially those with internet-facing Apache/IIS/OHS front ends proxying WebLogic applications, are exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-24, and EPSS assigns a 42% probability of exploitation within 30 days, though no public proof-of-concept is known.
    · Oracle HTTP Server (Oracle Fusion Middleware) 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 · Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 KEVlarge
  • Low-Privilege Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0
    CVE-2026-83282 is a critical vulnerability (CVSS 3.1 base score 9.9) in the Platform Security component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0, part of Oracle Analytics. A low-privileged, authenticated attacker with network access via HTTP can send crafted requests that compromise the OBIEE installation and, because the scope changes, may also significantly impact additional products beyond OBIEE itself. Successful exploitation results in a complete takeover of OBIEE with high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or destroy business analytics data and pivot to connected systems. Organizations running the affected 12.2.1.4.0 release, especially instances reachable over a network, are at risk. As of now, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no active exploitation has been reported.
    · Oracle Business Intelligence Enterprise Edition (Oracle Analytics, component: Platform Security)moderate
  • Unauthenticated Takeover Flaw in Oracle BI Enterprise Edition 12.2.1.4.0
    CVE-2026-83283 is a critical (CVSS 9.8) flaw in the Platform Security component of Oracle Business Intelligence Enterprise Edition (OBIEE), affecting version 12.2.1.4.0. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, requiring only network reachability to the OBIEE service. A successful exploit allows complete takeover of the OBIEE installation, with high impact on confidentiality, integrity, and availability — including access to sensitive analytics data, reports, and potentially connected backend data sources. Organizations running the affected 12.2.1.4.0 release, especially those with OBIEE consoles reachable from untrusted networks, are at risk. There is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
    · Oracle Business Intelligence Enterprise Edition (Oracle Analytics) 12.2.1.4.0moderate
  • Unauthenticated SOAP Flaw in Oracle E-Business Suite Framework Allows Full Takeover
    CVE-2026-83327 is a critical vulnerability (CVSS 9.8) in the Personalization component of Oracle Applications Framework within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker who has network access to the target via SOAP, requiring no privileges or user interaction. A successful attack allows the attacker to compromise Oracle Applications Framework and take it over, with high impact on the confidentiality, integrity, and availability of the affected system. Any organization running E-Business Suite Release 12.2 in the affected version range is potentially exposed, particularly instances with SOAP endpoints reachable from untrusted networks. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported as of this writing.
    · Oracle E-Business Suite (Oracle Applications Framework, Personalization component) 12.2.3-12.2.15moderate
  • Unauthenticated Takeover Flaw in Oracle EBS Document Management and Collaboration
    CVE-2026-83452 is a critical (CVSS 9.8) flaw in the Internal Operations component of the Oracle Document Management and Collaboration product within Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks allow complete takeover of the Document Management and Collaboration component with high impact to confidentiality, integrity, and availability. Organizations running affected EBS releases that expose these services to a network — especially internet-facing HTTP endpoints — are at risk of full compromise of sensitive documents and collaboration data. The flaw is addressed in Oracle's Critical Patch Update cycle, but the specific flaw type (e.g., injection or deserialization) was not disclosed by Oracle. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
    · Oracle E-Business Suite - Oracle Document Management and Collaboration (Internal Operations component) 12.2.3-12.2.15moderate
  • Unauthenticated Takeover in Oracle EBS Mobile Application Server (MWA Terminal Server)
    CVE-2026-83462 is a critical (CVSS 9.8) vulnerability in the MWA Terminal Server component of the Oracle Mobile Application Server, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. An unauthenticated remote attacker who can reach the MWA Terminal Server's TCP port over the network can exploit the flaw without any user interaction or credentials, and a successful attack results in a complete takeover of the Oracle Mobile Application Server with high impact to confidentiality, integrity, and availability. Because exploitation is described as easy and requires no privileges, any EBS environment running an affected version with the MWA service reachable (especially from the internet) is at serious risk of full server compromise. Organizations running EBS 12.2.3-12.2.15 in warehouse, manufacturing, or mobile data-collection deployments are the primary affected population. There is no known public proof-of-concept and the flaw is not on the CISA KEV list, so exploitation status is currently none known.
    · Oracle E-Business Suite - Oracle Mobile Application Server (MWA Terminal Server component) 12.2.3-12.2.15moderate
  • High-Privilege Takeover Flaw in Oracle BI Publisher (BI Platform Security)
    CVE-2026-83268 is a critical (CVSS 9.1) vulnerability in the BI Platform Security component of Oracle BI Publisher, part of Oracle Analytics, affecting versions 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. It is easily exploitable by an already high-privileged, authenticated attacker who has network access to the BI Publisher HTTP interface, so the practical risk is privilege escalation and full product takeover from an administrative foothold rather than an anonymous internet attack. Successful exploitation results in complete compromise of confidentiality, integrity and availability of Oracle BI Publisher, and because the vulnerability has a scope change (S:C), attacks may also significantly impact additional products beyond BI Publisher itself. Organizations running any of the three listed versions, whether on-premises or in Oracle Cloud, are affected. No public proof-of-concept exists and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
    · Oracle BI Publisher (Oracle Analytics, component: BI Platform Security) 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0moderate
  • Unauthenticated SOAP Data Access Flaw in Oracle Siebel CRM Open UI
    CVE-2026-83154 is a critical (CVSS 9.1) vulnerability in the Open UI component of Oracle Siebel CRM's End User product, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access who can reach the product's SOAP interface, requiring no privileges or user interaction. A successful attack lets the attacker create, delete, or modify critical data — or all data accessible to the Siebel CRM End User application — as well as read that data in full, with high impacts on both confidentiality and integrity (availability is not affected). Any organization running Siebel CRM within the affected version range with a network-reachable SOAP endpoint is exposed, particularly if the service is internet-facing. The flaw is not currently listed in CISA's KEV catalog, no public proof-of-concept is known, and no exploitation in the wild has been reported.
    · Oracle Siebel CRM (End User product, Open UI component) 17.0-26.7moderate
  • Privileged HTTP Takeover Flaw in Oracle Siebel CRM Deployment (Server Infrastructure)
    CVE-2026-83196 is a critical (CVSS 9.1) vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM, specifically in the Server Infrastructure component, affecting supported versions 17.0 through 26.7. It is remotely exploitable over HTTP but requires a high-privileged attacker (such as an administrator with valid credentials), which lowers the realistic attack surface to insider threats, compromised admin accounts, or credential-theft-driven attacks. Because the vulnerability has a scope change (S:C), successful exploitation can significantly impact products beyond Siebel CRM Deployment, and a successful attack results in complete takeover of the Siebel CRM Deployment component with high impact to confidentiality, integrity, and availability. Organizations running affected Siebel CRM versions are exposed, particularly if the deployment/management interfaces are reachable over the network. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no active exploitation is known.
    · Oracle Siebel CRM (Siebel CRM Deployment, Server Infrastructure component) 17.0 - 26.7moderate
  • Unauthenticated Data Exposure & DoS in Oracle Siebel CRM Financial Services
    CVE-2026-83197 is a critical (CVSS 9.1) flaw in the Financial Accounts component of Oracle Siebel Apps - Financial Services, affecting all supported versions from 17.0 through 26.7. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction. A successful attack allows the attacker to read critical data — up to complete access to all data accessible through Siebel Apps - Financial Services — and to cause a hang or frequently repeatable crash, resulting in complete denial of service. Integrity impact is rated as none, so the flaw is primarily a confidentiality and availability risk rather than code execution. No public proof-of-concept exists and the vulnerability is not on the CISA KEV list, so exploitation in the wild is not currently known.
    · Oracle Siebel Apps - Financial Services (Oracle Siebel CRM, component: Financial Accounts) 17.0-26.7moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.