vciy

Oracle Corporation Helidon: 99 records in one advisory

99 records announced together, published 2026-08-18, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.oracle.com/security-alerts/cspuaug2026.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.

Most commonly mapped weakness across the batch: Easily exploitable vulnerability allows…

What this page does not cover

This batch is 99 of the 890 records that cite the same advisory. The other 791 are different findings announced alongside it.

370 of them are on the sibling batches linked below. The remaining 421 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: oracle-cspuaug2026-090c48f372, oracle-cspuaug2026-242cea9b39, oracle-cspuaug2026-2cf943460d, oracle-cspuaug2026-8922c502ed, oracle-cspuaug2026-97574cd1a2, oracle-cspuaug2026-998a7c4add, oracle-cspuaug2026-b95b629f66, oracle-cspuaug2026-ba534bfb8f, oracle-cspuaug2026-cfddc9bb6a

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Oracle corrected Helidon's affected versions nine days after publishing the advisory

Helidon is Oracle's Java web server library, and it takes the largest single component block in the August 2026 monthly release. What makes the block worth reading is not its size but its version ranges. The advisory's modification history records, against 27 August 2026, "Rev 3. Updated affected versions for Helidon", nine days after the first release on 18 August. The ranges it settled on do not agree with each other. Counting the rows on the page today: 101 rows name Helidon, and they carry 13 different version ranges between them. Thirty-five end at 4.4.1, 26 end at 3.2.17, 10 end at 4.5.0 and 8 end at 3.2.18, while nine rows reach back into the Helidon 1 series at 1.4.18 or 1.4.19. So this is not one release's worth of work. Ninety-nine of the 101 rows name one component, Imperative Web Server; the other two are third-party rows for Netty and gRPC. Across all 101, Oracle marks 89 as remotely exploitable without authentication and 89 as reached over plain HTTP, with scores from 3.7 up to a single 9.9.

These rows were announced together and they do not all end at the same version. Several of them stop at a Helidon release older than the one another row names, so the record you are reading may describe something already fixed in the build you run, and reading one row tells you nothing about the range on the next.

2026-08-18Oracle publishes the August 2026 Critical Security Patch Update, revision 1.
2026-08-27Revision 3 of the same advisory, described by Oracle as "Updated affected versions for Helidon".
2026-09-04Revision 4, a product name correction elsewhere in the advisory.

Oracle gives a component name and a score and no bug class, no affected method and no patch link, so this cannot tell you what any of these flaws actually is. The version ranges also moved once already, on 27 August, so the ranges printed today are not necessarily the ones a record was written against.

Written from oracle.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-60853no title heldDifficult to exploit vulnerability allows…
CVE-2026-60915no title heldDifficult to exploit vulnerability allows…
CVE-2026-70716no title heldDifficult to exploit vulnerability allows…
CVE-2026-70727no title heldEasily exploitable vulnerability allows…
CVE-2026-70908no title heldEasily exploitable vulnerability allows…
CVE-2026-70923no title heldEasily exploitable vulnerability allows…
CVE-2026-71029no title heldDifficult to exploit vulnerability allows…
CVE-2026-71065no title heldEasily exploitable vulnerability allows…
CVE-2026-71074no title heldEasily exploitable vulnerability allows…
CVE-2026-71110no title heldEasily exploitable vulnerability allows low…
CVE-2026-71152no title heldEasily exploitable vulnerability allows…
CVE-2026-71153no title heldEasily exploitable vulnerability allows…
CVE-2026-71154no title heldEasily exploitable vulnerability allows low…
CVE-2026-71155no title heldEasily exploitable vulnerability allows low…
CVE-2026-71156no title heldEasily exploitable vulnerability allows…
CVE-2026-71157no title heldEasily exploitable vulnerability allows…
CVE-2026-71158no title heldEasily exploitable vulnerability allows…
CVE-2026-71159no title heldEasily exploitable vulnerability allows…
CVE-2026-71160no title heldDifficult to exploit vulnerability allows low…
CVE-2026-71161no title heldEasily exploitable vulnerability allows…
CVE-2026-71162no title heldDifficult to exploit vulnerability allows…
CVE-2026-71164no title heldEasily exploitable vulnerability allows…
CVE-2026-71165no title heldEasily exploitable vulnerability allows low…
CVE-2026-71166no title heldEasily exploitable vulnerability allows…
CVE-2026-71167no title heldEasily exploitable vulnerability allows…
CVE-2026-73865no title heldEasily exploitable vulnerability allows…
CVE-2026-73866no title heldEasily exploitable vulnerability allows…
CVE-2026-73867no title heldEasily exploitable vulnerability allows…
CVE-2026-73868no title heldEasily exploitable vulnerability allows…
CVE-2026-73869no title heldEasily exploitable vulnerability allows…
CVE-2026-73870no title heldEasily exploitable vulnerability allows…
CVE-2026-73871no title heldEasily exploitable vulnerability allows…
CVE-2026-73872no title heldEasily exploitable vulnerability allows…
CVE-2026-73873no title heldDifficult to exploit vulnerability allows low…
CVE-2026-73874no title heldEasily exploitable vulnerability allows low…
CVE-2026-73875no title heldEasily exploitable vulnerability allows…
CVE-2026-73876no title heldEasily exploitable vulnerability allows…
CVE-2026-73877no title heldEasily exploitable vulnerability allows…
CVE-2026-73878no title heldEasily exploitable vulnerability allows…
CVE-2026-73879no title heldEasily exploitable vulnerability allows…
CVE-2026-73880no title heldEasily exploitable vulnerability allows high…
CVE-2026-73881no title heldEasily exploitable vulnerability allows low…
CVE-2026-73882no title heldEasily exploitable vulnerability allows…
CVE-2026-73883no title heldEasily exploitable vulnerability allows…
CVE-2026-73884no title heldEasily exploitable vulnerability allows…
CVE-2026-73885no title heldEasily exploitable vulnerability allows…
CVE-2026-73886no title heldEasily exploitable vulnerability allows…
CVE-2026-73887no title heldEasily exploitable vulnerability allows…
CVE-2026-73888no title heldEasily exploitable vulnerability allows…
CVE-2026-73889no title heldEasily exploitable vulnerability allows…
CVE-2026-73890no title heldEasily exploitable vulnerability allows…
CVE-2026-73891no title heldEasily exploitable vulnerability allows…
CVE-2026-73892no title heldEasily exploitable vulnerability allows…
CVE-2026-73893no title heldEasily exploitable vulnerability allows…
CVE-2026-73894no title heldEasily exploitable vulnerability allows…
CVE-2026-73895no title heldEasily exploitable vulnerability allows…
CVE-2026-73896no title heldEasily exploitable vulnerability allows…
CVE-2026-73897no title heldEasily exploitable vulnerability allows…
CVE-2026-73898no title heldEasily exploitable vulnerability allows…
CVE-2026-73899no title heldEasily exploitable vulnerability allows…
CVE-2026-73900no title heldEasily exploitable vulnerability allows…
CVE-2026-73901no title heldDifficult to exploit vulnerability allows…
CVE-2026-73902no title heldEasily exploitable vulnerability allows…
CVE-2026-73903no title heldEasily exploitable vulnerability allows…
CVE-2026-73904no title heldEasily exploitable vulnerability allows…
CVE-2026-73905no title heldEasily exploitable vulnerability allows…
CVE-2026-73906no title heldEasily exploitable vulnerability allows…
CVE-2026-73907no title heldEasily exploitable vulnerability allows…
CVE-2026-73908no title heldEasily exploitable vulnerability allows…
CVE-2026-73909no title heldDifficult to exploit vulnerability allows…
CVE-2026-73910no title heldEasily exploitable vulnerability allows…
CVE-2026-73911no title heldEasily exploitable vulnerability allows low…
CVE-2026-73912no title heldEasily exploitable vulnerability allows…
CVE-2026-73913no title heldEasily exploitable vulnerability allows low…
CVE-2026-73914no title heldEasily exploitable vulnerability allows…
CVE-2026-73915no title heldEasily exploitable vulnerability allows…
CVE-2026-73916no title heldEasily exploitable vulnerability allows…
CVE-2026-73917no title heldEasily exploitable vulnerability allows…
CVE-2026-73918no title heldEasily exploitable vulnerability allows…
CVE-2026-73919no title heldEasily exploitable vulnerability allows low…
CVE-2026-73920no title heldEasily exploitable vulnerability allows…
CVE-2026-73921no title heldEasily exploitable vulnerability allows…
CVE-2026-73922no title heldEasily exploitable vulnerability allows…
CVE-2026-73923no title heldDifficult to exploit vulnerability allows…
CVE-2026-73924no title heldEasily exploitable vulnerability allows…
CVE-2026-73925no title heldEasily exploitable vulnerability allows…
CVE-2026-73927no title heldEasily exploitable vulnerability allows…
CVE-2026-73928no title heldEasily exploitable vulnerability allows…
CVE-2026-73929no title heldEasily exploitable vulnerability allows…
CVE-2026-73930no title heldEasily exploitable vulnerability allows…
CVE-2026-73931no title heldEasily exploitable vulnerability allows…
CVE-2026-73932no title heldEasily exploitable vulnerability allows…
CVE-2026-73933no title heldEasily exploitable vulnerability allows…
CVE-2026-73934no title heldEasily exploitable vulnerability allows…
CVE-2026-73935no title heldEasily exploitable vulnerability allows…
CVE-2026-73936no title heldEasily exploitable vulnerability allows…
CVE-2026-73937no title heldEasily exploitable vulnerability allows…
CVE-2026-73938no title heldEasily exploitable vulnerability allows…
CVE-2026-73939no title heldEasily exploitable vulnerability allows…

99 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.