{"schema_version":1,"title":"Oracle Helidon vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 68 vulnerabilities in Oracle Helidon: 0 in the last 7 days and 68 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-87289, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/helidon","json_url":"https://junglewise.ai/threats/technologies/helidon.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/helidon","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":26,"all_time":68,"critical":6,"exploited":0,"last_7_days":0,"last_30_days":13,"last_90_days":68,"last_365_days":68},"latest":[{"cve":"CVE-2026-87289","cvss":7.5,"epss":0.0046,"slug":"cve-2026-87289-oracle-helidon-webserver-static-content-denial-of-service","title":"Oracle Helidon webserver static content denial of service","severity":"high","exploited":false,"published_at":"2026-09-15T20:19:18.897+00:00","url":"https://junglewise.ai/threats/cve-2026-87289-oracle-helidon-webserver-static-content-denial-of-service"},{"cve":"CVE-2026-83488","cvss":5.4,"epss":0.0023,"slug":"cve-2026-83488-oracle-helidon-unauthorized-data-access-in-microprofile-security","title":"Oracle Helidon unauthorized data access in microprofile-security","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:56.593+00:00","url":"https://junglewise.ai/threats/cve-2026-83488-oracle-helidon-unauthorized-data-access-in-microprofile-security"},{"cve":"CVE-2026-83480","cvss":5.3,"epss":0.004,"slug":"cve-2026-83480-oracle-helidon-websocket-denial-of-service","title":"Oracle Helidon WebSocket denial of service","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:55.697+00:00","url":"https://junglewise.ai/threats/cve-2026-83480-oracle-helidon-websocket-denial-of-service"},{"cve":"CVE-2026-83460","cvss":6.5,"epss":0.0027,"slug":"cve-2026-83460-oracle-helidon-lra-unauthorized-data-access","title":"Oracle Helidon LRA unauthorized data access","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:54.813+00:00","url":"https://junglewise.ai/threats/cve-2026-83460-oracle-helidon-lra-unauthorized-data-access"},{"cve":"CVE-2026-83459","cvss":5.3,"epss":0.004,"slug":"cve-2026-83459-oracle-helidon-media-multipart-denial-of-service","title":"Oracle Helidon media multipart denial of service","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:54.71+00:00","url":"https://junglewise.ai/threats/cve-2026-83459-oracle-helidon-media-multipart-denial-of-service"},{"cve":"CVE-2026-83458","cvss":5.3,"epss":0.004,"slug":"cve-2026-83458-oracle-helidon-denial-of-service-in-json-parsing","title":"Oracle Helidon denial of service in JSON parsing","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:54.6+00:00","url":"https://junglewise.ai/threats/cve-2026-83458-oracle-helidon-denial-of-service-in-json-parsing"},{"cve":"CVE-2026-83439","cvss":8.1,"epss":0.0035,"slug":"cve-2026-83439-oracle-helidon-authentication-bypass-in-idcs-mapper","title":"Oracle Helidon authentication bypass in IDCS mapper","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:52.52+00:00","url":"https://junglewise.ai/threats/cve-2026-83439-oracle-helidon-authentication-bypass-in-idcs-mapper"},{"cve":"CVE-2026-83330","cvss":7.5,"epss":0.0046,"slug":"cve-2026-83330-oracle-helidon-websocket-denial-of-service","title":"Oracle Helidon WebSocket denial of service","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:46.207+00:00","url":"https://junglewise.ai/threats/cve-2026-83330-oracle-helidon-websocket-denial-of-service"},{"cve":"CVE-2026-83281","cvss":7.5,"epss":0.0046,"slug":"cve-2026-83281-oracle-helidon-denial-of-service-in-webserver-component","title":"Oracle Helidon denial of service in webserver component","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:40.7+00:00","url":"https://junglewise.ai/threats/cve-2026-83281-oracle-helidon-denial-of-service-in-webserver-component"},{"cve":"CVE-2026-83280","cvss":7.5,"epss":0.0046,"slug":"cve-2026-83280-oracle-helidon-denial-of-service-in-http-2","title":"Oracle Helidon denial of service in HTTP/2","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:40.593+00:00","url":"https://junglewise.ai/threats/cve-2026-83280-oracle-helidon-denial-of-service-in-http-2"},{"cve":"CVE-2026-83278","cvss":6.8,"epss":0.0022,"slug":"cve-2026-83278-oracle-helidon-neo4j-integration-unauthenticated-privilege","title":"Oracle Helidon Neo4j integration unauthenticated privilege escalation","severity":"medium","exploited":false,"published_at":"2026-09-15T20:18:40.23+00:00","url":"https://junglewise.ai/threats/cve-2026-83278-oracle-helidon-neo4j-integration-unauthenticated-privilege"},{"cve":"CVE-2026-83276","cvss":7.5,"epss":0.0046,"slug":"cve-2026-83276-oracle-helidon-http-2-denial-of-service","title":"Oracle Helidon HTTP/2 denial of service","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:40+00:00","url":"https://junglewise.ai/threats/cve-2026-83276-oracle-helidon-http-2-denial-of-service"},{"cve":"CVE-2026-83231","cvss":7,"epss":0.0028,"slug":"cve-2026-83231-oracle-helidon-mongodb-dbclient-unauthorized-data-access","title":"Oracle Helidon MongoDB DBClient unauthorized data access vulnerability","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:34.96+00:00","url":"https://junglewise.ai/threats/cve-2026-83231-oracle-helidon-mongodb-dbclient-unauthorized-data-access"},{"cve":"CVE-2026-73899","cvss":5.3,"epss":0.0032,"slug":"cve-2026-73899-oracle-helidon-unauthorized-information-disclosure-via-http","title":"Oracle Helidon unauthorized information disclosure via HTTP","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:22.543+00:00","url":"https://junglewise.ai/threats/cve-2026-73899-oracle-helidon-unauthorized-information-disclosure-via-http"},{"cve":"CVE-2026-73898","cvss":6.1,"epss":0.0025,"slug":"cve-2026-73898-oracle-helidon-data-access-vulnerability-in-imperative-web-server","title":"Oracle Helidon data access vulnerability in Imperative Web Server","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:22.44+00:00","url":"https://junglewise.ai/threats/cve-2026-73898-oracle-helidon-data-access-vulnerability-in-imperative-web-server"},{"cve":"CVE-2026-73897","cvss":6.5,"epss":0.0027,"slug":"cve-2026-73897-oracle-helidon-unauthorized-data-access-in-imperative-web-server","title":"Oracle Helidon unauthorized data access in Imperative Web Server","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:22.327+00:00","url":"https://junglewise.ai/threats/cve-2026-73897-oracle-helidon-unauthorized-data-access-in-imperative-web-server"},{"cve":"CVE-2026-73896","cvss":6.5,"epss":0.0036,"slug":"cve-2026-73896-oracle-helidon-information-disclosure-and-denial-of-service-via","title":"Oracle Helidon information disclosure and denial of service via HTTP/2","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:22.213+00:00","url":"https://junglewise.ai/threats/cve-2026-73896-oracle-helidon-information-disclosure-and-denial-of-service-via"},{"cve":"CVE-2026-73895","cvss":5.3,"epss":0.0032,"slug":"cve-2026-73895-oracle-helidon-unauthorized-data-access-in-imperative-web-server","title":"Oracle Helidon unauthorized data access in Imperative Web Server","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:22.1+00:00","url":"https://junglewise.ai/threats/cve-2026-73895-oracle-helidon-unauthorized-data-access-in-imperative-web-server"},{"cve":"CVE-2026-73894","cvss":7.3,"epss":0.0031,"slug":"cve-2026-73894-oracle-helidon-unauthorized-data-access-and-denial-of-service","title":"Oracle Helidon unauthorized data access and denial of service","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:21.983+00:00","url":"https://junglewise.ai/threats/cve-2026-73894-oracle-helidon-unauthorized-data-access-and-denial-of-service"},{"cve":"CVE-2026-73893","cvss":6.5,"epss":0.0027,"slug":"cve-2026-73893-oracle-helidon-unauthorized-data-access-vulnerability","title":"Oracle Helidon unauthorized data access vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:21.87+00:00","url":"https://junglewise.ai/threats/cve-2026-73893-oracle-helidon-unauthorized-data-access-vulnerability"},{"cve":"CVE-2026-73892","cvss":6.5,"epss":0.0027,"slug":"cve-2026-73892-oracle-helidon-unauthorized-data-access-in-imperative-web-server","title":"Oracle Helidon unauthorized data access in Imperative Web Server","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:21.757+00:00","url":"https://junglewise.ai/threats/cve-2026-73892-oracle-helidon-unauthorized-data-access-in-imperative-web-server"},{"cve":"CVE-2026-73891","cvss":7.3,"epss":0.0031,"slug":"cve-2026-73891-oracle-helidon-remote-data-manipulation-and-denial-of-service","title":"Oracle Helidon remote data manipulation and denial of service","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:21.65+00:00","url":"https://junglewise.ai/threats/cve-2026-73891-oracle-helidon-remote-data-manipulation-and-denial-of-service"},{"cve":"CVE-2026-73890","cvss":7.5,"epss":0.0044,"slug":"cve-2026-73890-oracle-helidon-denial-of-service-via-http-2","title":"Oracle Helidon denial of service via HTTP/2","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:21.533+00:00","url":"https://junglewise.ai/threats/cve-2026-73890-oracle-helidon-denial-of-service-via-http-2"},{"cve":"CVE-2026-73889","cvss":5.3,"epss":0.0032,"slug":"cve-2026-73889-oracle-helidon-unauthorized-information-disclosure-via-http","title":"Oracle Helidon unauthorized information disclosure via HTTP","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:21.407+00:00","url":"https://junglewise.ai/threats/cve-2026-73889-oracle-helidon-unauthorized-information-disclosure-via-http"},{"cve":"CVE-2026-73888","cvss":5.3,"epss":0.0032,"slug":"cve-2026-73888-oracle-helidon-information-disclosure-in-imperative-web-server","title":"Oracle Helidon information disclosure in Imperative Web Server","severity":"medium","exploited":false,"published_at":"2026-08-18T21:18:21.297+00:00","url":"https://junglewise.ai/threats/cve-2026-73888-oracle-helidon-information-disclosure-in-imperative-web-server"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":6,"exploited":0,"vulnerabilities":55},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":13},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Oracle Hyperion Financial Management","slug":"hyperion-financial-management","vulnerabilities":129,"url":"https://junglewise.ai/threats/technologies/hyperion-financial-management"},{"name":"Oracle Coherence","slug":"coherence","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/coherence"},{"name":"Oracle E-Business Suite","slug":"e-business-suite","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/e-business-suite"},{"name":"Oracle Commerce Guided Search","slug":"commerce-guided-search","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/commerce-guided-search"},{"name":"Oracle Commerce Experience Manager","slug":"commerce-experience-manager","vulnerabilities":81,"url":"https://junglewise.ai/threats/technologies/commerce-experience-manager"},{"name":"Oracle WebCenter Content","slug":"webcenter-content","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/webcenter-content"},{"name":"Oracle VirtualBox","slug":"virtualbox","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/virtualbox"},{"name":"Oracle MySQL Server","slug":"mysql-server","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/mysql-server"},{"name":"Oracle Hyperion Data Relationship Management","slug":"hyperion-data-relationship-management","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/hyperion-data-relationship-management"},{"name":"Oracle WebLogic Server","slug":"weblogic-server","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/weblogic-server"},{"name":"Oracle Java SE","slug":"java-se","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/java-se"},{"name":"Oracle MySQL Cluster","slug":"mysql-cluster","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/mysql-cluster"}],"technology":{"hub":true,"name":"Oracle Helidon","slug":"helidon","vendor":{"name":"Oracle","slug":"oracle","url":"https://junglewise.ai/threats/vendors/oracle"},"aliases":[],"category":"web-server","url":"https://junglewise.ai/threats/technologies/helidon"},"most_severe":[{"cve":"CVE-2026-71164","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server","title":"Oracle Helidon remote code execution in Imperative Web Server","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:17.703+00:00","url":"https://junglewise.ai/threats/cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server"},{"cve":"CVE-2026-71152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71152-oracle-helidon-remote-code-execution","title":"Oracle Helidon remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:16.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71152-oracle-helidon-remote-code-execution"},{"cve":"CVE-2026-71167","cvss":9.4,"epss":0.0046,"slug":"cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service","title":"Oracle Helidon unauthenticated data access and denial of service","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:18.05+00:00","url":"https://junglewise.ai/threats/cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service"},{"cve":"CVE-2026-71166","cvss":9.4,"epss":0.0046,"slug":"cve-2026-71166-oracle-helidon-remote-code-execution-in-imperative-web-server","title":"Oracle Helidon remote code execution in Imperative Web Server","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:17.93+00:00","url":"https://junglewise.ai/threats/cve-2026-71166-oracle-helidon-remote-code-execution-in-imperative-web-server"},{"cve":"CVE-2026-73866","cvss":9.1,"epss":0.0043,"slug":"cve-2026-73866-oracle-helidon-unauthorized-data-access-and-modification","title":"Oracle Helidon unauthorized data access and modification","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:18.763+00:00","url":"https://junglewise.ai/threats/cve-2026-73866-oracle-helidon-unauthorized-data-access-and-modification"},{"cve":"CVE-2026-73865","cvss":9.1,"epss":0.0043,"slug":"cve-2026-73865-oracle-helidon-unauthorized-data-access-and-modification","title":"Oracle Helidon unauthorized data access and modification","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:18.65+00:00","url":"https://junglewise.ai/threats/cve-2026-73865-oracle-helidon-unauthorized-data-access-and-modification"},{"cve":"CVE-2026-71155","cvss":8.5,"epss":0.003,"slug":"cve-2026-71155-oracle-helidon-unauthorized-data-access-vulnerability","title":"Oracle Helidon unauthorized data access vulnerability","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:16.617+00:00","url":"https://junglewise.ai/threats/cve-2026-71155-oracle-helidon-unauthorized-data-access-vulnerability"},{"cve":"CVE-2026-71159","cvss":8.2,"epss":0.0035,"slug":"cve-2026-71159-oracle-helidon-authentication-bypass-in-imperative-web-server","title":"Oracle Helidon authentication bypass in Imperative Web Server","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:17.167+00:00","url":"https://junglewise.ai/threats/cve-2026-71159-oracle-helidon-authentication-bypass-in-imperative-web-server"},{"cve":"CVE-2026-71110","cvss":8.1,"epss":0.0036,"slug":"cve-2026-71110-oracle-helidon-unauthorized-data-access-vulnerability","title":"Oracle Helidon unauthorized data access vulnerability","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:11.47+00:00","url":"https://junglewise.ai/threats/cve-2026-71110-oracle-helidon-unauthorized-data-access-vulnerability"},{"cve":"CVE-2026-83439","cvss":8.1,"epss":0.0035,"slug":"cve-2026-83439-oracle-helidon-authentication-bypass-in-idcs-mapper","title":"Oracle Helidon authentication bypass in IDCS mapper","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:52.52+00:00","url":"https://junglewise.ai/threats/cve-2026-83439-oracle-helidon-authentication-bypass-in-idcs-mapper"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}