🛡️ Cyber Times — CISO Intelligence Update
Wednesday, 16 September 2026 · Coverage: 15 Sep 2026 08:00 IST → 16 Sep 2026 08:00 IST
The high-confidence sweep produced 30 publishable records. This edition presents 7 source-linked updates across 1 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-87230 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:49 IST Sources: NVD
CVE-2026-83099 — Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:48 IST Sources: NVD
CVE-2026-83059 — Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:48 IST Sources: NVD
CVE-2026-83021 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:48 IST Sources: NVD
CVE-2026-83020 — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:48 IST Sources: NVD
CVE-2026-71133 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)
CRITICAL — NVD CVSS 10.0 (critical). Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 16 Sep 2026 01:47 IST Sources: NVD
CVE-2026-53710 — MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs
CRITICAL — NVD CVSS 10.0 (critical). MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required getattr guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 15 Sep 2026 22:47 IST Sources: NVD
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,028 records inspected · 139 passed collection filters · 30 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.