Vulnfeed

Archives
Log in
Subscribe
September 15, 2026

[vulnfeed] 122 critical CVEs — 2026-09-15 20:00 UTC

vulnfeed Critical alert — 2026-09-15 23:05 UTC
122 new critical CVEs in the last 5 hours — 122 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-71133CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engi
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita
CVSS 10.0
CVE-2026-83020CRITICAL
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Central
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.
CVSS 10.0
CVE-2026-83021CRITICAL
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). S
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exp
CVSS 10.0
CVE-2026-83059CRITICAL
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitabl
CVSS 10.0
CVE-2026-83099CRITICAL
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmod
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploita
CVSS 10.0
CVE-2026-87230CRITICAL
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability
CVSS 10.0
CVE-2026-45579CRITICAL
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestC
CVSS 9.9
CVE-2026-61667CRITICAL
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an
CVSS 9.9
CVE-2026-71163CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engi
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita
CVSS 9.9
CVE-2026-73945CRITICAL
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engi
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita
CVSS 9.9
CVE-2026-73948CRITICAL
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppo
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnera
CVSS 9.9
CVE-2026-76669CRITICAL
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Succe
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate thei
CVSS 9.9
CVE-2026-76670CRITICAL
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Succe
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate thei
CVSS 9.9
CVE-2026-76672CRITICAL
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration inf
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vu
CVSS 9.9
CVE-2026-82997CRITICAL
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabl
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita
CVSS 9.9

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-16 04:00 UTC Older → [vulnfeed] 16 critical CVEs — 2026-09-15 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.