Technology · Oracle
Oracle Helidon vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 68 vulnerabilities in Oracle Helidon: 0 in the last 7 days and 68 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-87289, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 68
- Critical, all time
- 6
- Exploited in the wild
- 0
Latest Oracle Helidon vulnerabilities
- CVE-2026-87289: Oracle Helidon webserver static content denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-83488: Oracle Helidon unauthorized data access in microprofile-securitymediumCVSS 5.4EPSS 0.2%
- CVE-2026-83480: Oracle Helidon WebSocket denial of servicemediumCVSS 5.3EPSS 0.4%
- CVE-2026-83460: Oracle Helidon LRA unauthorized data accessmediumCVSS 6.5EPSS 0.3%
- CVE-2026-83459: Oracle Helidon media multipart denial of servicemediumCVSS 5.3EPSS 0.4%
- CVE-2026-83458: Oracle Helidon denial of service in JSON parsingmediumCVSS 5.3EPSS 0.4%
- CVE-2026-83439: Oracle Helidon authentication bypass in IDCS mapperhighCVSS 8.1EPSS 0.4%
- CVE-2026-83330: Oracle Helidon WebSocket denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-83281: Oracle Helidon denial of service in webserver componenthighCVSS 7.5EPSS 0.5%
- CVE-2026-83280: Oracle Helidon denial of service in HTTP/2highCVSS 7.5EPSS 0.5%
- CVE-2026-83278: Oracle Helidon Neo4j integration unauthenticated privilege escalationmediumCVSS 6.8EPSS 0.2%
- CVE-2026-83276: Oracle Helidon HTTP/2 denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-83231: Oracle Helidon MongoDB DBClient unauthorized data access vulnerabilityhighCVSS 7EPSS 0.3%
- CVE-2026-73899: Oracle Helidon unauthorized information disclosure via HTTPmediumCVSS 5.3EPSS 0.3%
- CVE-2026-73898: Oracle Helidon data access vulnerability in Imperative Web ServermediumCVSS 6.1EPSS 0.3%
- CVE-2026-73897: Oracle Helidon unauthorized data access in Imperative Web ServermediumCVSS 6.5EPSS 0.3%
- CVE-2026-73896: Oracle Helidon information disclosure and denial of service via HTTP/2mediumCVSS 6.5EPSS 0.4%
- CVE-2026-73895: Oracle Helidon unauthorized data access in Imperative Web ServermediumCVSS 5.3EPSS 0.3%
- CVE-2026-73894: Oracle Helidon unauthorized data access and denial of servicehighCVSS 7.3EPSS 0.3%
- CVE-2026-73893: Oracle Helidon unauthorized data access vulnerabilitymediumCVSS 6.5EPSS 0.3%
- CVE-2026-73892: Oracle Helidon unauthorized data access in Imperative Web ServermediumCVSS 6.5EPSS 0.3%
- CVE-2026-73891: Oracle Helidon remote data manipulation and denial of servicehighCVSS 7.3EPSS 0.3%
- CVE-2026-73890: Oracle Helidon denial of service via HTTP/2highCVSS 7.5EPSS 0.4%
- CVE-2026-73889: Oracle Helidon unauthorized information disclosure via HTTPmediumCVSS 5.3EPSS 0.3%
- CVE-2026-73888: Oracle Helidon information disclosure in Imperative Web ServermediumCVSS 5.3EPSS 0.3%
Most severe Oracle Helidon vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-71164: Oracle Helidon remote code execution in Imperative Web ServercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-71152: Oracle Helidon remote code executioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-71167: Oracle Helidon unauthenticated data access and denial of servicecriticalCVSS 9.4EPSS 0.5%
- CVE-2026-71166: Oracle Helidon remote code execution in Imperative Web ServercriticalCVSS 9.4EPSS 0.5%
- CVE-2026-73866: Oracle Helidon unauthorized data access and modificationcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-73865: Oracle Helidon unauthorized data access and modificationcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-71155: Oracle Helidon unauthorized data access vulnerabilityhighCVSS 8.5EPSS 0.3%
- CVE-2026-71159: Oracle Helidon authentication bypass in Imperative Web ServerhighCVSS 8.2EPSS 0.4%
- CVE-2026-71110: Oracle Helidon unauthorized data access vulnerabilityhighCVSS 8.1EPSS 0.4%
- CVE-2026-83439: Oracle Helidon authentication bypass in IDCS mapperhighCVSS 8.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 55 | 6 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 13 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/helidon.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle Helidon vulnerabilities", https://junglewise.ai/threats/technologies/helidon, 26 September 2026.