CVE-2026-71040 – Oracle Agile PLM

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“An unauthenticated network attacker can fully compromise confidentiality, integrity, and availability.”

Oracle addresses a Critical vulnerability in the Security component of Oracle Agile PLM. CVE-2026-71040 is remotely exploitable over HTTP without authentication and can result in high impact to confidentiality, integrity, and availability. The CVSS score is 9.8, which is Critical severity.

Oracle Agile PLM version 9.3.6 is affected. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.

Key Details

Affected Product
Oracle Agile Product Lifecycle Management
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.