Patch Tuesday
April 2026
On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.
How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.
331 records · 4 KEV
Affecting your stack
This month's records that match the products and versions in your stack.
Sign in to see the ones matching your stack; records and notifications are free. →
Microsoft · April 14
163 · 4 KEV · 2 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
69This week | CVE-2026-32201Weaponized | Microsoft SharePoint Server Spoofing Vulnerabilitymicrosoft · sharepoint server · CWE-20 | Medium6.5 | KEV | 43.4% | Apr 14, 2026 |
69This week | CVE-2026-33824Weaponized | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-415 | Critical9.8 | KEV | 1.6% | Apr 14, 2026 |
61This week | CVE-2026-33825Weaponized | Microsoft Defender Elevation of Privilege Vulnerabilitymicrosoft · defender antimalware platform · CWE-1220 | High7.8 | KEV | 0.4% | Apr 14, 2026 |
48Plan | CVE-2026-32202Weaponized | Windows Shell Spoofing Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Medium4.3 | KEV | 4.9% | Apr 14, 2026 |
36Monitor | CVE-2026-26149No exploit | Microsoft Power Apps Desktop Client Spoofing Vulnerabilitymicrosoft · power apps · CWE-150 | Critical9.0 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-26178No exploit | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-190 | High8.8 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-32157No exploit | Remote Desktop Client Remote Code Execution Vulnerabilitymicrosoft · remote desktop client · CWE-416 | High8.8 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-32171No exploit | Azure Logic Apps Elevation of Privilege Vulnerabilitymicrosoft · azure logic apps · CWE-522 | High8.8 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-32225No exploit | Windows Shell Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | High8.8 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-33120No exploit | Microsoft SQL Server Remote Code Execution Vulnerabilitymicrosoft · sql server 2016 · CWE-822 | High8.8 | — | 0.9% | Apr 14, 2026 |
34Monitor | CVE-2026-27928No exploit | Windows Hello Security Feature Bypass Vulnerabilitymicrosoft · windows server 2016 · CWE-20 | High8.7 | — | 0.7% | Apr 14, 2026 |
33Monitor | CVE-2026-32162No exploit | Windows COM Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-349 | High8.4 | — | 0.2% | Apr 14, 2026 |
- CVE-2026-3220169This week
Microsoft SharePoint Server Spoofing Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 43%microsoft · sharepoint serverApr 14, 2026
- CVE-2026-3382469This week
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 2%microsoft · windows 10 1607Apr 14, 2026
- CVE-2026-3382561This week
Microsoft Defender Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 0%microsoft · defender antimalware platformApr 14, 2026
- CVE-2026-3220248Plan
Windows Shell Spoofing Vulnerability
MediumCVSS 4.3KEVWeaponizedEPSS 5%microsoft · windows 10 1607Apr 14, 2026
- CVE-2026-2614936Monitor
Microsoft Power Apps Desktop Client Spoofing Vulnerability
CriticalCVSS 9.0No exploitEPSS 1%microsoft · power appsApr 14, 2026
- CVE-2026-2617835Monitor
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Apr 14, 2026
- CVE-2026-3215735Monitor
Remote Desktop Client Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · remote desktop clientApr 14, 2026
- CVE-2026-3217135Monitor
Azure Logic Apps Elevation of Privilege Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · azure logic appsApr 14, 2026
- CVE-2026-3222535Monitor
Windows Shell Security Feature Bypass Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Apr 14, 2026
- CVE-2026-3312035Monitor
Microsoft SQL Server Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · sql server 2016Apr 14, 2026
- CVE-2026-2792834Monitor
Windows Hello Security Feature Bypass Vulnerability
HighCVSS 8.7No exploitEPSS 1%microsoft · windows server 2016Apr 14, 2026
- CVE-2026-3216233Monitor
Windows COM Elevation of Privilege Vulnerability
HighCVSS 8.4No exploitEPSS 0%microsoft · windows 10 1809Apr 14, 2026
+151 moreAll records of the vendor
Adobe · April 14
53 · 0 KEV · 6 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-27303No exploit | Adobe Connect | Deserialization of Untrusted Data (CWE-502)adobe · connect · CWE-502 | Critical9.6 | — | 1.9% | Apr 14, 2026 |
38Monitor | CVE-2026-34615No exploit | Adobe Connect | Deserialization of Untrusted Data (CWE-502)adobe · connect · CWE-502 | Critical9.3 | — | 1.8% | Apr 14, 2026 |
37Monitor | CVE-2026-27243No exploit | Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)adobe · connect · CWE-79 | Critical9.3 | — | 0.7% | Apr 14, 2026 |
37Monitor | CVE-2026-27245No exploit | Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)adobe · connect · CWE-79 | Critical9.3 | — | 0.7% | Apr 14, 2026 |
37Monitor | CVE-2026-27246No exploit | Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)adobe · connect · CWE-79 | Critical9.3 | — | 0.7% | Apr 14, 2026 |
37Monitor | CVE-2026-27304No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Critical9.3 | — | 0.5% | Apr 14, 2026 |
34Monitor | CVE-2026-27290No exploit | Adobe Framemaker | Untrusted Search Path (CWE-426)adobe · framemaker · CWE-426 | High8.6 | — | 0.3% | Apr 14, 2026 |
34Monitor | CVE-2026-27305No exploit | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | High8.6 | — | 1.0% | Apr 14, 2026 |
34Monitor | CVE-2026-34617No exploit | Adobe Connect | Cross-site Scripting (XSS) (CWE-79)adobe · connect · CWE-79 | High8.7 | — | 0.7% | Apr 14, 2026 |
34Monitor | CVE-2026-34622No exploit | Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)adobe · acrobat · CWE-1321 | High8.6 | — | 0.7% | Apr 14, 2026 |
34Monitor | CVE-2026-34632No exploit | Photoshop Installer | CWE-427: Uncontrolled Search Path Elementadobe · photoshop installer · CWE-427 | High8.6 | — | 0.3% | Apr 15, 2026 |
33Monitor | CVE-2026-27306No exploit | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | High8.4 | — | 0.5% | Apr 14, 2026 |
- CVE-2026-2730339Monitor
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
CriticalCVSS 9.6No exploitEPSS 2%adobe · connectApr 14, 2026
- CVE-2026-3461538Monitor
Adobe Connect | Deserialization of Untrusted Data (CWE-502)
CriticalCVSS 9.3No exploitEPSS 2%adobe · connectApr 14, 2026
- CVE-2026-2724337Monitor
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · connectApr 14, 2026
- CVE-2026-2724537Monitor
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · connectApr 14, 2026
- CVE-2026-2724637Monitor
Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
CriticalCVSS 9.3No exploitEPSS 1%adobe · connectApr 14, 2026
- CVE-2026-2730437Monitor
ColdFusion | Improper Input Validation (CWE-20)
CriticalCVSS 9.3No exploitEPSS 0%adobe · coldfusionApr 14, 2026
- CVE-2026-2729034Monitor
Adobe Framemaker | Untrusted Search Path (CWE-426)
HighCVSS 8.6No exploitEPSS 0%adobe · framemakerApr 14, 2026
- CVE-2026-2730534Monitor
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
HighCVSS 8.6No exploitEPSS 1%adobe · coldfusionApr 14, 2026
- CVE-2026-3461734Monitor
Adobe Connect | Cross-site Scripting (XSS) (CWE-79)
HighCVSS 8.7No exploitEPSS 1%adobe · connectApr 14, 2026
- CVE-2026-3462234Monitor
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
HighCVSS 8.6No exploitEPSS 1%adobe · acrobatApr 14, 2026
- CVE-2026-3463234Monitor
Photoshop Installer | CWE-427: Uncontrolled Search Path Element
HighCVSS 8.6No exploitEPSS 0%adobe · photoshop installerApr 15, 2026
- CVE-2026-2730633Monitor
ColdFusion | Improper Input Validation (CWE-20)
HighCVSS 8.4No exploitEPSS 0%adobe · coldfusionApr 14, 2026
+41 moreAll records of the vendor
SAP · April 14
0 · 0 KEV · 0 criticalNo records in this window.
Siemens · April 14
5 · 0 KEV · 0 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-25654No exploit | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3).siemens · sinec nms · CWE-639 | High8.7 | — | 0.5% | Apr 14, 2026 |
34Monitor | CVE-2026-27668No exploit | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8).siemens · ruggedcom crossbow secure access manager primary (sam-p) · CWE-266 | High8.7 | — | 0.4% | Apr 14, 2026 |
27Monitor | CVE-2026-24032No exploit | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC).siemens · sinec nms · CWE-347 | Medium6.9 | — | 0.3% | Apr 14, 2026 |
25Monitor | CVE-2025-40745No exploit | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcentesiemens · simcenter 3d · CWE-295 | Medium6.3 | — | 0.1% | Apr 14, 2026 |
20Monitor | CVE-2026-33892No exploit | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Prosiemens · industrial edge management pro v1 · CWE-305 | Medium5.1 | — | 0.4% | Apr 14, 2026 |
- CVE-2026-2565434Monitor
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3).
HighCVSS 8.7No exploitEPSS 1%siemens · sinec nmsApr 14, 2026
- CVE-2026-2766834Monitor
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8).
HighCVSS 8.7No exploitEPSS 0%siemens · ruggedcom crossbow secure access manager primary (sam-p)Apr 14, 2026
- CVE-2026-2403227Monitor
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC).
MediumCVSS 6.9No exploitEPSS 0%siemens · sinec nmsApr 14, 2026
- CVE-2025-4074525Monitor
A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcente
MediumCVSS 6.3No exploitEPSS 0%siemens · simcenter 3dApr 14, 2026
- CVE-2026-3389220Monitor
A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro
MediumCVSS 5.1No exploitEPSS 0%siemens · industrial edge management pro v1Apr 14, 2026
Schneider Electric · April 14
8 · 0 KEV · 0 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2026-2399No exploit | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files oschneider-electric · powerchute serial shutdown · CWE-22 | Medium6.9 | — | 0.2% | Apr 14, 2026 |
27Monitor | CVE-2026-2402No exploit | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the usschneider-electric · powerchute serial shutdown · CWE-307 | Medium6.9 | — | 0.3% | Apr 14, 2026 |
27Monitor | CVE-2026-2404No exploit | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters tschneider-electric · powerchute serial shutdown · CWE-116 | Medium6.9 | — | 0.2% | Apr 14, 2026 |
27Monitor | CVE-2026-4832No exploit | CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauschneider electric · easergy micom p14x · CWE-798 | Medium6.9 | — | 0.4% | Apr 14, 2026 |
21Monitor | CVE-2026-2400No exploit | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reschneider-electric · powerchute serial shutdown · CWE-93 | Medium5.3 | — | 0.2% | Apr 14, 2026 |
21Monitor | CVE-2026-2403No exploit | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting loschneider-electric · powerchute serial shutdown · CWE-1284 | Medium5.3 | — | 0.2% | Apr 14, 2026 |
21Monitor | CVE-2026-2405No exploit | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seschneider-electric · powerchute serial shutdown · CWE-400 | Medium5.3 | — | 0.2% | Apr 14, 2026 |
9Monitor | CVE-2026-2401No exploit | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when schneider-electric · powerchute serial shutdown · CWE-532 | Low2.4 | — | 0.1% | Apr 14, 2026 |
- CVE-2026-239927Monitor
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files o
MediumCVSS 6.9No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-240227Monitor
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the us
MediumCVSS 6.9No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-240427Monitor
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters t
MediumCVSS 6.9No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-483227Monitor
CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unau
MediumCVSS 6.9No exploitEPSS 0%schneider electric · easergy micom p14xApr 14, 2026
- CVE-2026-240021Monitor
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to re
MediumCVSS 5.3No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-240321Monitor
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting lo
MediumCVSS 5.3No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-240521Monitor
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of se
MediumCVSS 5.3No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
- CVE-2026-24019Monitor
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when
LowCVSS 2.4No exploitEPSS 0%schneider-electric · powerchute serial shutdownApr 14, 2026
Oracle (Critical Patch Update) · April 21
102 · 0 KEV · 5 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-34275No exploit | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).oracle · advanced inbound telephony · CWE-306 | Critical9.8 | — | 0.5% | Apr 21, 2026 |
36Monitor | CVE-2026-34279No exploit | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).oracle · enterprise manager base platform · CWE-306 | Critical9.1 | — | 0.5% | Apr 21, 2026 |
36Monitor | CVE-2026-34285No exploit | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-306 | Critical9.1 | — | 0.4% | Apr 21, 2026 |
36Monitor | CVE-2026-34286No exploit | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-306 | Critical9.1 | — | 0.4% | Apr 21, 2026 |
36Monitor | CVE-2026-34287No exploit | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).oracle · identity manager connector · CWE-284 | Critical9.1 | — | 0.4% | Apr 21, 2026 |
34Monitor | CVE-2026-21997No exploit | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).oracle · life sciences empirica signal · CWE-284 | High8.5 | — | 0.2% | Apr 21, 2026 |
34Monitor | CVE-2026-34291No exploit | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).oracle · http server · CWE-284 | High8.7 | — | 0.3% | Apr 21, 2026 |
32Monitor | CVE-2026-34309No exploit | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).oracle · peoplesoft enterprise peopletools · CWE-284 | High8.1 | — | 0.4% | Apr 21, 2026 |
31Monitor | CVE-2026-35243No exploit | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).oracle · application development framework · CWE-284 | High7.8 | — | 0.2% | Apr 21, 2026 |
30Monitor | CVE-2026-22010Proof of concept | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comoracle · financial services analytical applications infrastructure · CWE-284 | High7.5 | — | 0.3% | Apr 21, 2026 |
30Monitor | CVE-2026-22011Proof of concept | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).oracle · applications dba · CWE-284 | High7.6 | — | 0.3% | Apr 21, 2026 |
30Monitor | CVE-2026-22016Proof of concept | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).oracle · jre · CWE-200 | High7.5 | — | 0.7% | Apr 21, 2026 |
- CVE-2026-3427539Monitor
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).
CriticalCVSS 9.8No exploitEPSS 1%oracle · advanced inbound telephonyApr 21, 2026
- CVE-2026-3427936Monitor
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).
CriticalCVSS 9.1No exploitEPSS 0%oracle · enterprise manager base platformApr 21, 2026
- CVE-2026-3428536Monitor
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
CriticalCVSS 9.1No exploitEPSS 0%oracle · identity manager connectorApr 21, 2026
- CVE-2026-3428636Monitor
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
CriticalCVSS 9.1No exploitEPSS 0%oracle · identity manager connectorApr 21, 2026
- CVE-2026-3428736Monitor
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).
CriticalCVSS 9.1No exploitEPSS 0%oracle · identity manager connectorApr 21, 2026
- CVE-2026-2199734Monitor
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).
HighCVSS 8.5No exploitEPSS 0%oracle · life sciences empirica signalApr 21, 2026
- CVE-2026-3429134Monitor
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).
HighCVSS 8.7No exploitEPSS 0%oracle · http serverApr 21, 2026
- CVE-2026-3430932Monitor
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).
HighCVSS 8.1No exploitEPSS 0%oracle · peoplesoft enterprise peopletoolsApr 21, 2026
- CVE-2026-3524331Monitor
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).
HighCVSS 7.8No exploitEPSS 0%oracle · application development frameworkApr 21, 2026
- CVE-2026-2201030Monitor
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (com
HighCVSS 7.5Proof of conceptEPSS 0%oracle · financial services analytical applications infrastructureApr 21, 2026
- CVE-2026-2201130Monitor
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).
HighCVSS 7.6Proof of conceptEPSS 0%oracle · applications dbaApr 21, 2026
- CVE-2026-2201630Monitor
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).
HighCVSS 7.5Proof of conceptEPSS 1%oracle · jreApr 21, 2026
+90 moreAll records of the vendor