Technology · Oracle
Oracle JDeveloper vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in Oracle JDeveloper: 0 in the last 7 days and 17 in the last 90 days, 2 of them critical and 1 exploited in the wild. The most recent, CVE-2026-83424, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 2
- Exploited in the wild
- 1
About Oracle JDeveloper
An integrated development environment for building service-oriented applications using Java and XML.
Latest Oracle JDeveloper vulnerabilities
- CVE-2026-83424: Oracle JDeveloper unauthorized information disclosurehighCVSS 7.5EPSS 0.4%
- CVE-2026-83423: Oracle JDeveloper authentication bypass in Security FrameworkhighCVSS 8.8EPSS 0.4%
- CVE-2026-83306: Oracle JDeveloper privilege escalation in Resource Catalog ServiceshighCVSS 8.8EPSS 0.4%
- CVE-2026-83266: Oracle JDeveloper authentication bypass in Resource Catalog ServiceshighCVSS 8.2EPSS 0.4%
- CVE-2026-83067: Oracle JDeveloper data manipulation and denial of service in ADF Shared ComponentshighCVSS 8.1EPSS 0.4%
- CVE-2026-73961: Oracle JDeveloper remote code execution in ADF FacescriticalCVSS 9.8EPSS 0.5%
- CVE-2026-61061: Oracle JDeveloper compromise in Security FrameworkhighCVSS 7
- CVE-2026-60629: Oracle JDeveloper data access vulnerability in Data Visualization ToolshighCVSS 7.5
- CVE-2026-60622: Oracle JDeveloper information disclosure in Security FrameworkhighCVSS 7.5
- CVE-2026-60354: Oracle JDeveloper information disclosure in Data Visualization ToolslowCVSS 3.7
- CVE-2026-60353: Oracle JDeveloper information disclosure in ADF FaceslowCVSS 3.1
- CVE-2026-60352: Oracle JDeveloper information disclosure in ADF FaceslowCVSS 3.7
- CVE-2026-60351: Oracle JDeveloper unauthorized data access in ADF FacesmediumCVSS 4.8
- CVE-2026-60350: Oracle JDeveloper information disclosure in ADF FacesmediumCVSS 6.5
- CVE-2026-60349: Oracle JDeveloper information disclosure in Java Business ObjectsmediumCVSS 5.9
- CVE-2026-60348: Oracle JDeveloper information disclosure in ADF FacesmediumCVSS 5.9
- CVE-2026-60345: Oracle JDeveloper takeover in ADF Shared ComponentshighCVSS 7.2
- CVE-2022-21445: Oracle ADF Faces Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2017-3255: Oracle JDeveloper information disclosure in ADF FacesmediumCVSS 5.8
Most severe Oracle JDeveloper vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-21445: Oracle ADF Faces Deserialization of Untrusted Data Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-73961: Oracle JDeveloper remote code execution in ADF FacescriticalCVSS 9.8EPSS 0.5%
- CVE-2026-83423: Oracle JDeveloper authentication bypass in Security FrameworkhighCVSS 8.8EPSS 0.4%
- CVE-2026-83306: Oracle JDeveloper privilege escalation in Resource Catalog ServiceshighCVSS 8.8EPSS 0.4%
- CVE-2026-83266: Oracle JDeveloper authentication bypass in Resource Catalog ServiceshighCVSS 8.2EPSS 0.4%
- CVE-2026-83067: Oracle JDeveloper data manipulation and denial of service in ADF Shared ComponentshighCVSS 8.1EPSS 0.4%
- CVE-2026-83424: Oracle JDeveloper unauthorized information disclosurehighCVSS 7.5EPSS 0.4%
- CVE-2026-60629: Oracle JDeveloper data access vulnerability in Data Visualization ToolshighCVSS 7.5
- CVE-2026-60622: Oracle JDeveloper information disclosure in Security FrameworkhighCVSS 7.5
- CVE-2026-60345: Oracle JDeveloper takeover in ADF Shared ComponentshighCVSS 7.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 11 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 6 | 1 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/jdeveloper.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Oracle JDeveloper vulnerabilities", https://junglewise.ai/threats/technologies/jdeveloper, 28 September 2026.