Technology · Oracle
Oracle E-Business Suite vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 83 vulnerabilities in Oracle E-Business Suite: 0 in the last 7 days and 73 in the last 90 days, 7 of them critical and 4 exploited in the wild. The most recent, CVE-2026-87167, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 73
- Critical, all time
- 7
- Exploited in the wild
- 4
About Oracle E-Business Suite
Oracle E-Business Suite is an integrated set of business applications for enterprise resource planning, customer relationship management, and supply chain management.
Latest Oracle E-Business Suite vulnerabilities
- CVE-2026-87167: Oracle Purchasing unauthorized data access and modificationhighCVSS 8.1EPSS 0.4%
- CVE-2026-87163: Oracle E-Business Suite Purchasing privilege escalationhighCVSS 8.8EPSS 0.4%
- CVE-2026-87156: Oracle E-Business Suite Product Hub unauthorized data access via HTTPhighCVSS 7.1EPSS 0.3%
- CVE-2026-87155: Oracle E-Business Suite Product Hub remote code executionhighCVSS 8.8EPSS 0.4%
- CVE-2026-87154: Oracle E-Business Suite Product Hub unauthorized data accesshighCVSS 8.1EPSS 0.4%
- CVE-2026-87152: Oracle E-Business Suite Installed Base unauthorized data access in Create Item InstancehighCVSS 8.1EPSS 0.4%
- CVE-2026-87127: Oracle Purchasing unauthorized data access in E-Business SuitehighCVSS 7.7EPSS 0.4%
- CVE-2026-87126: Oracle E-Business Suite Report Manager authorization bypasshighCVSS 7.1EPSS 0.4%
- CVE-2026-87125: Oracle Financials for Asia/Pacific privilege escalation in E-Business SuitehighCVSS 8.3EPSS 0.4%
- CVE-2026-83487: Oracle E-Business Suite Product Hub data exposurehighCVSS 7.7EPSS 0.4%
- CVE-2026-83486: Oracle E-Business Suite Product Hub information disclosure in Item CataloghighCVSS 7.7EPSS 0.4%
- CVE-2026-83485: Oracle E-Business Suite Product Hub unauthorized data accesshighCVSS 7.7EPSS 0.4%
- CVE-2026-83444: Oracle E-Business Suite Product Hub privilege escalationhighCVSS 8.8EPSS 0.4%
- CVE-2026-83437: Oracle Engineering privilege escalation in Change ManagementhighCVSS 7.7EPSS 0.4%
- CVE-2026-83433: Oracle Depot Repair unauthorized data access in E-Business SuitemediumCVSS 6.5EPSS 0.4%
- CVE-2026-83430: Oracle E-Business Suite Product Workbench privilege escalation in Internal OperationshighCVSS 8.1EPSS 0.4%
- CVE-2026-83425: Oracle E-Business Suite Complex Maintenance Repair and Overhaul unauthorized access in Internal OperationshighCVSS 8.5EPSS 0.4%
- CVE-2026-83356: Oracle E-Business Suite Enterprise Command Center Framework unauthorized data accesshighCVSS 7.7EPSS 0.3%
- CVE-2026-83332: Oracle Applications Framework unauthorized data access in PersonalizationhighCVSS 7.1EPSS 0.3%
- CVE-2026-83331: Oracle E-Business Suite Applications Framework privilege escalation in PersonalizationhighCVSS 8.8EPSS 0.4%
- CVE-2026-83329: Oracle E-Business Suite Applications Framework privilege escalation in PersonalizationhighCVSS 8.8EPSS 0.4%
- CVE-2026-83328: Oracle E-Business Suite Applications Framework privilege escalation in PersonalizationhighCVSS 7.2EPSS 0.5%
- CVE-2026-83327: Oracle E-Business Suite Applications Framework SOAP authentication bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83205: Oracle E-Business Suite Applications Framework privilege escalation in PersonalizationhighCVSS 8.8EPSS 0.4%
- CVE-2026-83189: Oracle E-Business Suite User Management privilege escalation in Proxy User DelegationhighCVSS 8.8EPSS 0.4%
Most severe Oracle E-Business Suite vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-61882: Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher…criticalexploited in the wildCVSS 9.8EPSS 99.7%
- CVE-2026-46817: Oracle E-Business Suite remote compromise in Oracle Paymentscriticalexploited in the wildCVSS 9.8EPSS 0.7%
- CVE-2022-21587: Oracle E-Business Suite Unspecified Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-61884: Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions…criticalexploited in the wildCVSS 7.5EPSS 95.9%
- CVE-2026-46933: Oracle Applications Manager privilege escalation in Internal OperationscriticalCVSS 9.9EPSS 0.4%
- CVE-2026-70926: Oracle E-Business Suite Workflow remote code execution via SMTPcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83327: Oracle E-Business Suite Applications Framework SOAP authentication bypasscriticalCVSS 9.8EPSS 0.5%
- CVE-2026-46916: Oracle E-Business Suite improper access control in Quality Management SpecshighCVSS 8.8EPSS 0.5%
- CVE-2026-87163: Oracle E-Business Suite Purchasing privilege escalationhighCVSS 8.8EPSS 0.4%
- CVE-2026-87155: Oracle E-Business Suite Product Hub remote code executionhighCVSS 8.8EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 21 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 10 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 42 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/e-business-suite.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle E-Business Suite vulnerabilities", https://junglewise.ai/threats/technologies/e-business-suite, 26 September 2026.