CVE-2026-87186
CRITICAL · 9.6Real vuln, high CVSS, but no KEV, no PoC, no exploitation chatter yet; early-stage alert noise.
What: Unauthenticated remote code execution in Oracle Hyperion Financial Management 11.2.26.0.000 (Security component); CVSS 9.6 CRITICAL with scope change affecting downstream systems.
Why it matters: Fresh advisory (published 2026-09-15) targeting a widely-deployed enterprise financial system. High CVSS and scope change indicate broad blast radius. Not yet KEV-listed, no public PoC chatter, but Oracle typically patches within weeks. Early social noise is vendor-driven replication, not active exploitation signal.
Where it's seen: Automated CVSS alert amplification on Bluesky; no working PoC, no defender triage posts, no urgent vendor patching announcement yet observed.
RISK: CRITICAL — Enterprise financial management RCE; high CVSS; scope change; limited patch lag expected.
Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS 3.1 breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Adjacent network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High