Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83074 – Unauthorized Data Access – Oracle Siebel CRM Cloud Applications 22.3–26.7

CVE-2026-83074 is a high-severity vulnerability (CVSS 8.6) in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It allows an unauthenticated attacker with network access to compromise the affected system, resulting in unauthorized access to critical data. Oracle disclosed the issue as part of its September 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83261 – Unauthenticated Remote Takeover – Oracle Product Lifecycle Analytics 3.6.1

CVE-2026-83261 is a critical, unauthenticated remote compromise vulnerability affecting Oracle Product Lifecycle Analytics (part of the Oracle Supply Chain product family), specifically the Core component. The flaw allows a network-based attacker to fully compromise the application over HTTP without any credentials or user interaction, and Oracle rates it 9.8 (Critical) on the CVSS v3.1 scale.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83462 – Unauthenticated Remote Takeover (RCE) – Oracle Mobile Application Server (MWA Termi

CVE-2026-83462 is a critical vulnerability in the MWA Terminal Server component of Oracle Mobile Application Server (part of Oracle E-Business Suite). The flaw allows an unauthenticated, remote attacker with network access via TCP to fully compromise the affected server. Oracle rates this issue CRITICAL with a CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83181 – Unauthenticated Data Exposure & Partial DoS – Oracle Siebel CRM Development (Worksp

CVE-2026-83181 is a high-severity vulnerability in the Workspaces component of Oracle Siebel CRM Development that allows an unauthenticated, network-based attacker to gain unauthorized access to Siebel CRM Development data and cause a partial denial of service. Oracle rates the flaw as "easily exploitable" via HTTP, requiring no privileges and no user interaction. It was disclosed as part of Oracle's September 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83452 – Unauthenticated Remote Compromise – Oracle Document Management and Collaboration 12

CVE-2026-83452 is a critical vulnerability in the Internal Operations component of Oracle Document Management and Collaboration, a module of Oracle E-Business Suite. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application, with the potential for complete system takeover. Oracle rates this vulnerability CRITICAL with a CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83105 – Unauthenticated Remote Takeover – Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

CVE-2026-83105 is a critical vulnerability in the Oracle Forms product of Oracle Fusion Middleware, affecting the Forms Services, C/S, and Charmode components. It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Forms, and Oracle notes that successful attacks may significantly impact additional products beyond Oracle Forms itself due to a scope change. Oracle rates the flaw 9.0 (Critical) and describes it as "difficult to exploit."

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83104 – Unauthenticated Data Manipulation (RCE-class) – Oracle Forms 12.2.1.19.0 / 14.1.2.0

CVE-2026-83104 is a critical missing-authentication vulnerability affecting the Forms Services, C/S, and Charmode components of Oracle Forms (part of Oracle Fusion Middleware). The flaw allows an unauthenticated, remote attacker with network access via TCP to compromise Oracle Forms without any user interaction. Oracle rates the vulnerability CRITICAL with a CVSS 3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73958 – Authentication Bypass Leading to Full Compromise – Oracle Access Manager 12.2.1.4.0

CVE-2026-73958 is a vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager, with Oracle's advisory describing the impact as a potential complete takeover of the product. The flaw carries a CVSS v3.1 base score of 8.1 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83101 – Unauthenticated Remote Compromise – Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

CVE-2026-83101 is a vulnerability in the Forms Services (C/S, Charmode) component of Oracle Forms, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Forms, resulting in a complete takeover of the affected system. Oracle rates the issue HIGH severity with a CVSS v3.1 base score of 8.1, though it is described by Oracle as difficult to exploit.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83021 – Unauthenticated RCE / Full Takeover – Oracle WebLogic Server 12.2.1.4.0, 14.1.1.0.0

CVE-2026-83021 is a critical, unauthenticated remote code execution vulnerability in the Web Container component of Oracle WebLogic Server, part of Oracle Fusion Middleware. The flaw is remotely exploitable over HTTP without any authentication or user interaction, and a successful attack results in complete takeover of the WebLogic Server. It carries the maximum CVSS v3.1 base score of 10.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83025 – Unauthenticated Data Tampering & Disclosure – Oracle Identity Manager Connector 12.

CVE-2026-83025 is a high-severity vulnerability (CVSS 3.1 base score 8.7) in the Oracle Identity Manager Connector component of Oracle Fusion Middleware. It allows an unauthenticated, remote attacker with network access via TCP to compromise the Connector and, due to a scope change, to affect additional Oracle products, resulting in unauthorized creation, deletion, or modification of critical data as well as unauthorized disclosure of that data. Oracle rates it a difficult-to-exploit vulnerability, but no authentication or user interaction is required.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83100 – Unauthenticated RCE / Full Takeover – Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

CVE-2026-83100 is a critical vulnerability in the Oracle Forms product of Oracle Fusion Middleware, stemming from missing/improper authentication for a critical function (CWE-306, CWE-287). It allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Forms. Oracle rates this as CVSS 9.8 (Critical), and it is described as "easily exploitable."

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83095 – Unauthenticated Remote Takeover – Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

CVE-2026-83095 is a critical vulnerability in Oracle Forms caused by missing authentication for a critical function. It allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Forms, resulting in complete takeover of the affected system. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73944 – Unauthenticated Data Compromise – Oracle Access Manager 12.2.1.4.0 / 14.1.2.1.0

CVE-2026-73944 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager, with high impact to confidentiality and integrity. It carries a CVSS v3.1 base score of 9.1 (Critical) and was disclosed via an Oracle Critical Security Patch Update advisory on September 15, 2026.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83304 – Unauthenticated Data Compromise (Scope Change) – Oracle Business Intelligence Enter

CVE-2026-83304 is a high-severity vulnerability in the Analytics Web General component of Oracle Business Intelligence Enterprise Edition that allows an unauthenticated, network-based attacker to compromise the product via HTTP. Successful exploitation can result in unauthorized creation, deletion, and modification of data, full disclosure of data accessible to the application, and a partial denial of service. Oracle notes that the vulnerability involves a scope change, meaning successful attacks can also significantly impact additional Oracle products beyond Business Intelligence Enterprise Edition itself.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73940 – Unauthenticated Full Compromise – Oracle Access Manager 12.2.1.4.0 & 14.1.2.1.0

CVE-2026-73940 is a critical, easily exploitable vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). It allows an unauthenticated, network-based attacker with access via the T3 or IIOP protocols to compromise Oracle Access Manager and potentially achieve complete takeover of the product. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73963 – Unauthenticated RCE / Full System Takeover – Oracle WebCenter Portal 12.2.1.4.0 and

CVE-2026-73963 is a critical, remotely exploitable vulnerability in the Portlet Services component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to fully compromise the application, with successful exploitation resulting in complete takeover of the affected WebCenter Portal instance. Oracle rates this vulnerability as easily exploitable and disclosed it in the September 2026 Critical Security Patch Update (CSPU).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83234 – Unauthenticated Data Access/Modification – Oracle Commerce Guided Search / Experien

CVE-2026-83234 is a high-severity vulnerability in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Oracle describes it as an easily exploitable flaw that lets an unauthenticated attacker with network access via HTTP compromise the product, resulting in unauthorized access to and modification of application data. The issue carries a CVSS v3.1 base score of 8.2 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83202 – Unauthenticated Data Compromise (RCE-class) – Oracle Siebel CRM 17.0 through 26.7

CVE-2026-83202 is a critical vulnerability in the Server Infrastructure component of Oracle Siebel CRM Deployment. It allows an unauthenticated attacker with network access via HTTP to compromise the system, resulting in unauthorized creation, deletion, or modification of critical data. Oracle rates the flaw 9.1 (Critical) and describes it as easily exploitable.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73952 – Unauthenticated Data Compromise (Confidentiality & Integrity) – Oracle WebCente

CVE-2026-73952 is a critical vulnerability in the Portlet Services component of Oracle WebCenter Portal (part of Oracle Fusion Middleware). It allows an unauthenticated, network-based attacker to compromise the application over HTTP, resulting in unauthorized creation, deletion, or modification of critical data as well as full read access to all data accessible to WebCenter Portal. Oracle rates the flaw as "easily exploitable" with a CVSS 3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73954 – Unauthenticated RCE via Business Interlink – Oracle PeopleSoft Enterprise PeopleToo

CVE-2026-73954 is a vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools that allows a network-based attacker to compromise the system without any authentication or user interaction. Oracle rates the flaw "difficult to exploit," but a successful attack results in complete compromise of confidentiality, integrity, and availability. The issue carries a CVSS v3.1 base score of 8.1 (High) and affects PeopleTools versions 8.61 through 8.63.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83192 – Unauthenticated Takeover via Open UI – Oracle Siebel CRM End User 17.0–26.7

CVE-2026-83192 is a high-severity vulnerability in the Open UI component of Oracle Siebel CRM End User. It allows an unauthenticated, remote attacker with network access via HTTP to compromise the affected system, with successful exploitation resulting in a complete takeover of Siebel CRM End User. The flaw carries a CVSS 3.1 base score of 8.1 (High) and was disclosed by Oracle on September 15, 2026.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-87129 – Unauthenticated Data Tampering – Oracle Hyperion Data Relationship Management 11.2.

CVE-2026-87129 is a critical vulnerability in the Access and Security component of Oracle Hyperion Data Relationship Management (DRM), affecting version 11.2.26.0.000. The flaw allows an unauthenticated, remote attacker with network access via HTTP to create, delete, or modify critical data and to view confidential information without any prior authentication. Oracle rates this as easily exploitable, and it carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83094 – Unauthenticated Remote Takeover – Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

CVE-2026-83094 is a critical missing/improper authentication vulnerability (CWE-306, CWE-287) in the Forms Services, C/S, Charmode component of Oracle Forms (part of Oracle Fusion Middleware). It allows an unauthenticated attacker with network access via HTTP to compromise and fully take over Oracle Forms. Oracle rates it CRITICAL with a CVSS 3.1 base score of 9.8, and it was disclosed in the September 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83265 – Unauthenticated Data Exposure / Integrity Compromise – Oracle Web Services Manager

CVE-2026-83265 is a high-severity vulnerability in the Web Services Agent component of Oracle Web Services Manager (part of Oracle Fusion Middleware). It allows a completely unauthenticated, remote attacker with only network access via HTTP to compromise the product, resulting in unauthorized read access to critical data and unauthorized update, insert, or delete access to some accessible data. Oracle rates this as easily exploitable with a CVSS v3.1 base score of 8.2 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-87128 – Unauthenticated Data Tampering / Information Disclosure – Oracle Hyperion Data Rela

CVE-2026-87128 is a critical, easily exploitable vulnerability in the "Access and security" component of Oracle Hyperion Data Relationship Management (DRM). It allows an unauthenticated attacker with network access via HTTP to compromise the application, resulting in unauthorized creation, deletion, or modification of critical data as well as full unauthorized read access to all accessible data. The flaw was disclosed by Oracle as part of the September 2026 Critical Security Patch Update and carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83355 – Unauthenticated RCE (Full Compromise) – Oracle Enterprise Manager for Fusion Middle

CVE-2026-83355 is a critical vulnerability in the Metrics component of Oracle Enterprise Manager for Fusion Middleware that allows a remote, unauthenticated attacker to fully compromise the affected system over HTTP. Oracle rates the flaw as easily exploitable, and it carries a CVSS v3.1 base score of 9.8 (Critical). Successful exploitation results in complete loss of confidentiality, integrity, and availability of the Enterprise Manager deployment.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-71133 – Unauthenticated Remote Takeover – Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0

CVE-2026-71133 is a critical vulnerability in the Authentication Engine component of Oracle Access Manager, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to fully compromise the product, and Oracle notes the attack may significantly impact additional products due to a scope change. The flaw carries the maximum CVSS v3.1 base score of 10.0 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83035 – Unauthenticated Remote Takeover (RCE) – Oracle WebCenter Sites 12.2.1.4.0 / 14.1.2.

CVE-2026-83035 is a critical, unauthenticated remote takeover vulnerability affecting Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw is remotely exploitable over HTTP without any authentication or user interaction, and successful exploitation can result in a complete compromise ("takeover") of the affected Oracle WebCenter Sites instance. Oracle rates this vulnerability as CRITICAL with a CVSS v3.1 base score of 9.8.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83078 – Unauthenticated Data Exposure and Modification – Oracle Siebel CRM Cloud Applicatio

CVE-2026-83078 is a high-severity (CVSS 8.2) vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications. It allows a remote, unauthenticated attacker with network access via HTTP to compromise the application, gaining unauthorized read access to critical data and unauthorized ability to update, insert, or delete a subset of application data. The flaw was disclosed by Oracle as part of its September 2026 Critical Security Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83254 – Remote Code Execution / Full System Compromise – Oracle Commerce Guided Search / Ex

CVE-2026-83254 is a high-severity vulnerability in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. It allows an unauthenticated attacker with network access via TCP to compromise the application, with the potential for complete takeover of the affected system. Oracle rates the flaw 8.1 (HIGH) and disclosed it in the September 2026 Critical Security Patch Update (CSPU).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83343 – Unauthenticated Data Exposure / Integrity Compromise – Oracle Utilities Network Man

CVE-2026-83343 is a high-severity vulnerability in the Oracle Utilities Network Management System (component: System Wide) that allows an unauthenticated, remote attacker to compromise the system over HTTP. Successful exploitation can grant complete access to all data accessible to the application and allow unauthorized modification, insertion, or deletion of some of that data. Oracle rates this as "easily exploitable," requiring no authentication or user interaction.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83284 – Unauthenticated SOAP-Based DoS and Unauthorized Data Manipulation – Oracle BI Publi

CVE-2026-83284 is a high-severity vulnerability in the BI Platform Security component of Oracle BI Publisher (part of Oracle Analytics). The flaw allows an unauthenticated, remote attacker with network access via SOAP to compromise the application, resulting in unauthorized data disclosure, unauthorized data modification, and denial of service. Oracle rates the issue as "easily exploitable" and disclosed it in the September 2026 Critical Patch Update.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-76683 – Unauthenticated Buffer Overflow (RCE) – HPE EdgeConnect SD-WAN Gateway (ECOS) 9.4.0

CVE-2026-76683 is a buffer overflow vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways (ECOS) that could allow an unauthenticated remote attacker to execute arbitrary commands on the underlying host. Exploitation requires certain preconditions outside the attacker's control, which raises attack complexity but does not require any authentication or user interaction. HPE rates this vulnerability High severity (CVSS v3.1 base score 8.1) and disclosed it alongside a broader set of EdgeConnect SD-WAN Gateway/Orchestrator vulnerabilities in advisory HPESBNW05135.

Created Date
Source
CVE-2026-76673 – Authentication Bypass / Full Compromise – HPE EdgeConnect SD-WAN Orchestrator ≤ 9.7

CVE-2026-76673 is a critical authentication bypass vulnerability in the API of HPE EdgeConnect SD-WAN Orchestrator. An unauthenticated remote attacker can circumvent existing authentication controls on the Orchestrator API to obtain administrative privileges, resulting in complete compromise of the Orchestrator host. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge