CTIPilot

Oracle WebLogic Server Core, unauthenticated CVSS 9.8 flaw, September 2026 CSPU

cve · CVE-2026-70756

Coverage timeline
1
first 2026-09-20 → last 2026-09-29
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-20/oracle-september-2026-cspu-five-unauthenticated-cvss-10 · ATT&CK page ↗

Story timeline

  1. 2026-09-20Oracle's September 2026 Critical Security Patch Update carries fifty unauthenticated CVSS 9.8+ flaws, concentrated in Fusion Middleware's identity, forms, directory and portal components, plus E-Business Suite, Hyperion, Analytics, Enterprise Manager, Communications and Supply Chain products
    trending-vulnerabilitiesFifty credential-free, no-interaction flaws span Oracle's middleware, ERP, BI and telco-assurance lines, more than triple this entry's original count

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (50%)
  • oracle.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Oracle WebLogic Server Core, unauthenticated CVSS 9.8 flaw, September 2026 CSPU (1)

2026-09-20 · view entry permalink →

HIGHCVE-2026-83021 +49updatedNATOA2

Oracle's September 2026 Critical Security Patch Update carries fifty unauthenticated CVSS 9.8+ flaws, concentrated in Fusion Middleware's identity, forms, directory and portal components, plus E-Business Suite, Hyperion, Analytics, Enterprise Manager, Communications and Supply Chain products

Oracle published its September 2026 Critical Security Patch Update on 2026-09-15 (Rev 1, initial release) with 673 new security patches across its product families; Oracle Fusion Middleware alone accounts for 153 of them, and Oracle states that "78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials" (Oracle, 2026-09-15). Six flaws in the release carry a CVSS 3.1 base score of 10.0 in Oracle's own risk matrix with Attack Vector Network, Attack Complexity Low, Privileges Required None, User Interaction None and Scope Changed, meaning an unauthenticated request across the network reaches high confidentiality and integrity impact and crosses a security boundary (the first five also reach high availability impact; Hyperion Financial Management's is rated none): CVE-2026-83021 in the Web Container of Oracle WebLogic Server over HTTP, CVE-2026-71133 in the Authentication Engine of Oracle Access Manager over HTTP, CVE-2026-83099 in Oracle Forms Services over HTTP, CVE-2026-83059 in the OID LDAP Server of Oracle Internet Directory over LDAP, CVE-2026-83020 in the centralized third-party jars of Oracle Platform Security for Java over HTTP, and CVE-2026-87230 in the Security component of Oracle Hyperion Financial Management over HTTP (Oracle, 2026-09-15). The Netherlands' national cyber-security centre relayed the Fusion Middleware half of the release as advisory NCSC-2026-0372 on 2026-09-16 and assigned it priority "Hoog", its high rating (NCSC-NL, 2026-09-16).

The Critical Security Patch Update is Oracle's second, higher-frequency release line, published alongside the quarterly cumulative Critical Patch Update rather than replacing it: Oracle describes it as providing "targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption" and says these updates "complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs)" (Oracle, 2026-09-15). A patch calendar built only around the January, April, July and October quarterly dates therefore leaves the September release, and the four other off-quarter releases in the year, unscheduled.

Oracle discloses no exploitation technique, no proof-of-concept status and no in-the-wild activity for any of the six, which is its standing advisory practice; no source in this release names an exploited flaw. What forces the timeline is the shape of the flaws rather than an exploitation report. Each of the six is reachable by an unauthenticated network request against a component that exists to sit in front of other systems or to hold what they rely on: WebLogic's web container, Access Manager's authentication engine, an Internet Directory LDAP listener, Forms Services, the shared Java security jars underneath Fusion Middleware, and Hyperion Financial Management's own security component. Five of them are the single-sign-on, directory and application-server tiers that Swiss federal, cantonal and communal estates run legacy identity services on, and a Scope Changed rating on an authentication engine means the compromise does not stay inside the component that carries the flaw. The sixth sits elsewhere: Hyperion Financial Management is a financial-consolidation application from Oracle's separate Hyperion family, so it is the finance estate rather than the identity estate that needs checking for it.

Triage: exploitation of these components produces authentication and application-tier telemetry, not endpoint telemetry. On the identity tier, look for successful authorization decisions from Access Manager with no preceding credential-validation event, and for LDAP binds or searches against the OID listener from source ranges that no application integration uses. On the application tier, look for requests to WebLogic or Forms endpoints that return successfully without a prior session-establishment request in the same log sequence. Ordinary integrations and health checks produce the same request types, so the discriminator is the missing predecessor event, not the request itself.

This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware.

78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

This Critical Security Patch Update contains 159 new security patches for Oracle E-Business Suite. 19 of these vulnerabilities may be remotely exploitable without authentication

Oracle 2026-09-15
Updaterun 2026-09-29T0405Z-inteltitleheadlinesummaryaffected_productscvesevidencesourcing_noteactionsbody

Re-fetching Oracle's own September 2026 risk matrix confirms eight further unauthenticated, CVSS 9.8 flaws (Attack Vector Network, Privileges Required None, User Interaction None) from the same release that this entry did not originally cover, across four additional product families (Oracle, 2026-09-15). Oracle E-Business Suite carries 159 new patches, of which 19 are remotely exploitable without authentication: "This Critical Security Patch Update contains 159 new security patches for Oracle E-Business Suite. 19 of these vulnerabilities may be remotely exploitable without authentication" (Oracle, 2026-09-15). Three of those nineteen reach CVSS 9.8 with no further precondition: CVE-2026-83327 in the Applications Framework's Personalization component over SOAP, CVE-2026-83452 in Document Management and Collaboration's Internal Operations component over HTTP, and CVE-2026-83462 in the Mobile Application Server's MWA Terminal Server component over TCP, all affecting versions 12.2.3 through 12.2.15. Oracle Business Intelligence Enterprise Edition (Oracle Analytics, 50 new patches, 8 unauthenticated) carries CVE-2026-83283 in its Platform Security component (version 12.2.1.4.0, over HTTP). Oracle Enterprise Manager carries CVE-2026-41635 (Agent Next Gen / Apache Mina component, versions 13.5/24.1, over HTTP, the same patch also fixing CVE-2026-41409 and CVE-2026-42779) and CVE-2026-83355 (Enterprise Manager for Fusion Middleware's Metrics component, same versions). Oracle Communications (31 new patches, 23 unauthenticated) carries CVE-2026-44024 (Unified Assurance's Core/Fluentd component, versions 6.1.1-7.0.0, the same patch also fixing CVE-2026-44025, CVE-2026-44160 and CVE-2026-44161) and CVE-2026-17544 (Unified Assurance's Core/PHP component, version 7.0.0).

A same-day systematic re-count of the full risk matrix, every row meeting the identical bar (Access Vector Network, Privileges Required None, User Interaction None, "Remote Exploit without Auth." Yes), found that the eight-CVE figure above itself undercounted the release: thirty-two further CVSS 9.8 flaws sit inside the Fusion Middleware product line alone, on top of the four Fusion Middleware components already named for their single CVSS 10.0 flaw each. Access Manager carries four more (CVE-2026-73950, CVE-2026-73947, CVE-2026-73940, CVE-2026-47065, the Authentication Engine and a Third Party/Apache Mina component, over HTTP or T3/IIOP or TCP/IP). Forms carries five more (CVE-2026-83094, -83095, -83098, -83100, -83108, all in Forms Services/C-S/ Charmode over HTTP). Internet Directory carries five more (CVE-2026-83054, -83060, -83061, -83062, -83066, the OID LDAP Server over LDAP or T3/IIOP). Platform Security for Java carries two more (CVE-2026-82994 over LDAP, CVE-2026-82995 over SOAP, both in the centralized third-party jars). WebLogic Server carries three more (CVE-2026-70756, -70757, -70748, its Core component over T3/IIOP). The remaining thirteen are in Fusion Middleware components this entry had not previously named at all: Data Integrator (CVE-2026-83232, Console/ Repository Explorer, HTTP), Identity Manager (CVE-2026-70913 Core and CVE-2026-83042 OIM Legacy UI, both HTTP), JDeveloper (CVE-2026-73961, ADF Faces, HTTP), WebCenter Enterprise Capture (CVE-2026-83339, Client Bundle, HTTP), WebCenter Portal (CVE-2026-73956 Composer and CVE-2026-73953/-73963 Portlet Services, all HTTP), WebCenter Sites (CVE-2026-83035, -83036, -83037, HTTP) and Service Delivery Platform (CVE-2026-83000 and -83151, Messaging Enabler, over HTTP or SOAP) (Oracle, 2026-09-15). Outside Fusion Middleware, the re-count also found three more: two further Hyperion Financial Management flaws (CVE-2026-87188 over HTTP, CVE-2026-87184 over SQL, alongside the original CVE-2026-87230), one more in Oracle Analytics (CVE-2026-83269 in BI Publisher's BI Platform Security component, over HTTP, alongside CVE-2026-83283 in Business Intelligence Enterprise Edition), and one in a product line not previously covered at all, Oracle Supply Chain's Product Lifecycle Analytics (CVE-2026-83261, Core component, HTTP). The corrected total for the release is fifty unauthenticated CVSS 9.8-10.0 flaws, not the fourteen this entry originally reported nor the eight added above.

None of the fifty is reported exploited by Oracle or any other source, and none appears in the CISA Known Exploited Vulnerabilities catalog. Oracle E-Business Suite remains a high-priority addition regardless of the absence of exploitation reporting: it is the product line ShinyHunters/Cl0p mass-exploited across roughly 100 organizations in 2025 via a separate vulnerability chain, and an estate running EBS 12.2.3-12.2.15 should treat its three unauthenticated flaws as an extension of that same exposure class rather than a routine patch-cycle item. But by count, the exposure is now dominated by Fusion Middleware: Access Manager, Forms and Internet Directory alone carry five to six unauthenticated CVSS 9.8-10.0 flaws each, and an estate that patched only the original six components this entry first named has patched a small fraction of what this release actually contains.

Builds on: 2026-08-20/oracle-august-2026-cpu-three-unauthenticated-cvss-10 · 2026-06-18/cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen

vulnerability20 Sep 13:38Zmulti-sourceOpen finding ↗
Sources: Oracle · NCSC-NL