CVE-2026-71064 – Oracle Database Server

CVSS 9.6 CRITICAL Critical - Same Day Deployment

“Critical Portable Clusterware flaws can enable takeover, destructive data changes, and complete service disruption.”

Oracle addresses three Critical vulnerabilities in the Portable Clusterware component of Oracle Database Server. CVE-2026-71063 and CVE-2026-71064 allow unauthenticated attackers on the adjacent physical network segment to compromise and take over Portable Clusterware. Each has a CVSS score of 9.6, Critical severity.

CVE-2026-71102 is remotely exploitable without authentication over HTTP and can allow unauthorized modification or deletion of critical data and cause complete denial of service. Its CVSS score is 9.1, Critical severity. Affected releases include Oracle Database Server 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3.

Key Details

Affected Product
Oracle Database Server
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-284
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.