CRITICAL 9.8 CVE-2026-73912 Published 18 Aug 2026

Helidon Imperative Web Server Critical Remote Takeover Vulnerability

Worried this affects one of your servers?

Oracle has disclosed a vulnerability in Helidon, part of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The flaw is a remote takeover vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the server.

Affected versions are Helidon 4.0.0 through 4.4.1. The vulnerability is easily exploitable and requires no user interaction.

  • Affected versions: 4.0.0-4.4.1
  • Attack vector: network access via HTTP
  • Impact: full takeover of Helidon, with high confidentiality, integrity, and availability impacts
  • CVSS 3.1 score: 9.8

Reference: CVE-2026-73912 on NVD

← Back to Security News