CVE-2026-62638 in Oracle Reports Developer earns a 9.1 CVSS base score—an unauthenticated network-exploitable authentication bypass with high integrity and availability impact. By the math, it's critical. But the EPSS of 0.00441 tells a different story: this flaw sits in a product whose relevance contracted years ago, running mostly in forgotten internal deployments where attacker attention has moved on.

The gap between that 9.1 and that EPSS is the real signal, and it's worth reading carefully. Oracle Reports Developer isn't just deprecated—it's a runtime interpreter for report definitions that organizations often leave running long after migration because the infrastructure sits at the intersection of legacy database schemas and undocumented workflows. The product wasn't built with modern security telemetry in mind, which means many installations have never had authentication-layer monitoring at all. That's not a gap created by the low EPSS; it's a gap that predated it.

The historical pattern matters here. Oracle Fusion Middleware authentication components have a documented lineage of high-severity, low-EPSS flaws—exactly the scoring profile that makes defenders unconsciously deprioritize them. But that deprioritization is itself the risk amplifier. When a forgotten component with high privilege access drops below the SOC's attention threshold, it becomes exactly the lateral movement pivot that appears in incident reports years later: the initial access vector nobody remembered existed.

Treat this CVE as a technical debt marker. Organizations still running Oracle Reports Developer are likely carrying other unpatched legacy components with similar scoring gaps. Your priority isn't just patching this flaw—it's discovering whether Oracle Reports Developer runtime infrastructure still exists in your environment at all, and whether it's instrumented. The absence of monitoring for this component is the more dangerous condition than the vulnerability itself. If you find orphaned instances, treat them as high-priority deprecation candidates regardless of what the EPSS says about exploitation probability today.