Oracle Corporation Helidon: 99 records in one advisory
99 records announced together, published 2026-08-18, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.oracle.com/security-alerts/cspuaug2026.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
Held sources describe every record in this batch identically. Nothing but the identifier and the publication time separates one from another here.
Most commonly mapped weakness across the batch: Easily exploitable vulnerability allows…
What this page does not cover
This batch is 99 of the 890 records that cite the same advisory. The other 791 are different findings announced alongside it.
370 of them are on the sibling batches linked below. The remaining 421 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: oracle-cspuaug2026-090c48f372, oracle-cspuaug2026-242cea9b39, oracle-cspuaug2026-2cf943460d, oracle-cspuaug2026-8922c502ed, oracle-cspuaug2026-97574cd1a2, oracle-cspuaug2026-998a7c4add, oracle-cspuaug2026-b95b629f66, oracle-cspuaug2026-ba534bfb8f, oracle-cspuaug2026-cfddc9bb6a
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Oracle corrected Helidon's affected versions nine days after publishing the advisory
Helidon is Oracle's Java web server library, and it takes the largest single component block in the August 2026 monthly release. What makes the block worth reading is not its size but its version ranges. The advisory's modification history records, against 27 August 2026, "Rev 3. Updated affected versions for Helidon", nine days after the first release on 18 August. The ranges it settled on do not agree with each other. Counting the rows on the page today: 101 rows name Helidon, and they carry 13 different version ranges between them. Thirty-five end at 4.4.1, 26 end at 3.2.17, 10 end at 4.5.0 and 8 end at 3.2.18, while nine rows reach back into the Helidon 1 series at 1.4.18 or 1.4.19. So this is not one release's worth of work. Ninety-nine of the 101 rows name one component, Imperative Web Server; the other two are third-party rows for Netty and gRPC. Across all 101, Oracle marks 89 as remotely exploitable without authentication and 89 as reached over plain HTTP, with scores from 3.7 up to a single 9.9.
These rows were announced together and they do not all end at the same version. Several of them stop at a Helidon release older than the one another row names, so the record you are reading may describe something already fixed in the build you run, and reading one row tells you nothing about the range on the next.
Oracle gives a component name and a score and no bug class, no affected method and no patch link, so this cannot tell you what any of these flaws actually is. The version ranges also moved once already, on 27 August, so the ranges printed today are not necessarily the ones a record was written against.
Written from oracle.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
99 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.