← back

CVE-2026-87186

CRITICAL · 9.6
hype MIXED · 38 hack

Real vuln, high CVSS, but no KEV, no PoC, no exploitation chatter yet; early-stage alert noise.

What: Unauthenticated remote code execution in Oracle Hyperion Financial Management 11.2.26.0.000 (Security component); CVSS 9.6 CRITICAL with scope change affecting downstream systems.

Why it matters: Fresh advisory (published 2026-09-15) targeting a widely-deployed enterprise financial system. High CVSS and scope change indicate broad blast radius. Not yet KEV-listed, no public PoC chatter, but Oracle typically patches within weeks. Early social noise is vendor-driven replication, not active exploitation signal.

Where it's seen: Automated CVSS alert amplification on Bluesky; no working PoC, no defender triage posts, no urgent vendor patching announcement yet observed.

RISK: CRITICAL — Enterprise financial management RCE; high CVSS; scope change; limited patch lag expected.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/16/2026, 2:23:12 AM

Description

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 6.0
vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Adjacent network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High