Oracle Critical Patch Update Advisory - July 2026

Description

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch Update Advisory. Thus, prior Critical Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.

This Critical Patch Update contains 1449 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.

Affected Products and Patch Information

Security vulnerabilities addressed by this Critical Patch Update affect the products listed below.

Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.

Affected Products and Versions Patch Availability Document
GoldenGate Stream Analytics, versions 19.1.0.0.0-19.1.0.0.15, 26.1.0.0.0 Database
JD Edwards EnterpriseOne Advanced Pricing - Procurement, version 9.2 JD Edwards
JD Edwards EnterpriseOne Configurator, version 9.2 JD Edwards
JD Edwards EnterpriseOne CRM Foundation, version 9.2 JD Edwards
JD Edwards EnterpriseOne General Ledger, version 9.2 JD Edwards
JD Edwards EnterpriseOne HCM Foundation, version 9.2 JD Edwards
JD Edwards EnterpriseOne Human Resources Management, version 9.2 JD Edwards
JD Edwards EnterpriseOne Procurement and Subcontract Management, version 9.2 JD Edwards
JD Edwards EnterpriseOne Requirements Planning, version 9.2 JD Edwards
JD Edwards EnterpriseOne Solution Advisor, version 9.2 JD Edwards
JD Edwards EnterpriseOne Tools, version 9.2.26.3 JD Edwards
Management Cloud Engine, version 25.2.0.0.0 Management Cloud Engine
MySQL Cluster, versions 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1, 8.0.0-8.0.47, 8.4.0-8.4.10, 9.0.0-9.7.1 MySQL
MySQL Connectors, versions 9.7.0-9.7.1 MySQL
MySQL Router, versions 8.4.0-8.4.10, 9.7.0-9.7.1 MySQL
MySQL Server, versions 8.4.0-8.4.10, 9.0.0-9.7.1 MySQL
OPatch, versions 12.2.0.1.16-12.2.0.1.51 Database
Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.1.0, 15.1.1.0.0 Fusion Middleware
Oracle Agile Engineering Data Management, version 6.2.1 Oracle Supply Chain Products
Oracle Agile PLM, version 9.3.6 Oracle Supply Chain Products
Oracle Agile PLM MCAD Connector, version 3.6 Oracle Supply Chain Products
Oracle Agile Product Lifecycle Management for Process, version 6.2.4 Oracle Supply Chain Products
Oracle APEX, versions 24.1, 24.2, 26.1 Database
Oracle Application Testing Suite, version 13.3.0.1 Oracle Application Testing Suite
Oracle Autonomous Health Framework, versions 25.1, 26.0.0, 26.1.0, 26.2.0, 26.3.0, 26.5.0 Oracle Autonomous Health Framework
Oracle Banking Corporate Lending Process Management, versions 14.6.0-14.8.0 Contact Support
Oracle Banking Liquidity Management, versions 14.5.0-14.8.0 Contact Support
Oracle Banking Origination, versions 14.5.0-14.8.0 Contact Support
Oracle Banking Payments, versions 14.5.0-14.8.0 Contact Support
Oracle Banking Trade Finance, versions 14.6.0-14.8.0 Contact Support
Oracle Banking Trade Finance Process Management, versions 14.6.0-14.8.0 Contact Support
Oracle Banking Virtual Account Management, versions 14.5.0-14.8.0 Contact Support
Oracle BI Publisher, versions 8.2.0.0.0, 12.2.1.4.0, 26.1.0.0.0 Oracle Analytics
Oracle Business Intelligence Enterprise Edition, versions 8.2.0.0.0, 26.1.0.0.0 Oracle Analytics
Oracle Business Process Management Suite, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Cloud Native Session Border Controller, version 26.0.0 Oracle Cloud Native Session Border Controller
Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
Oracle Commerce Guided Search, version 11.4.0 Oracle Commerce
Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 Oracle Commerce
Oracle Commerce Guided Search Platform Services, version 11.4.0 Oracle Commerce
Oracle Commerce Platform, version 11.4.0 Oracle Commerce
Oracle Commerce Service Center, version 11.4.0 Oracle Commerce
Oracle Communications Billing and Revenue Management, versions 15.0.0.0.0-15.0.1.0.0, 15.1.0.0.0-15.2.0.0.0 Oracle Communications Billing and Revenue Management
Oracle Communications BRM - Elastic Charging Engine, versions 15.0.0.0.0-15.0.1.0.0, 15.1.0.0.0-15.2.0.0.0 Oracle Communications BRM - Elastic Charging Engine
Oracle Communications Cloud Native Core Binding Support Function, versions 25.1.200, 25.2.200 Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Certificate Management, version 25.2.200 Oracle Communications Cloud Native Core Certificate Management
Oracle Communications Cloud Native Core Console, versions 25.1.203, 25.2.201 Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core DBTier, versions 25.1.200, 25.2.200 Oracle Communications Cloud Native Core DBTier
Oracle Communications Cloud Native Core Network Exposure Function, versions 24.2.0, 24.2.5 Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Network Function Cloud Native Environment, version 25.2.200 Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Network Repository Function, version 25.2.201 Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Network Slice Selection Function, version 25.2.200 Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Policy, versions 24.2.0, 24.2.7, 25.1.200, 25.2.200 Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 25.1.203, 25.2.200 Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy, versions 25.1.200, 25.2.100, 25.2.200 Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Unified Data Repository, versions 25.2.200, 25.200 Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Converged Application Server, versions 8.2, 8.3 Oracle Communications Converged Application Server
Oracle Communications Convergent Charging Controller, versions 15.0.0.0.0, 15.2.0.0.0 Oracle Communications Convergent Charging Controller
Oracle Communications Diameter Signaling Router, versions 6.0.2.2.0, 6.1.0.0.0, 6.2.0.0.0, 6.3.0.0.0, 9.0.0, 9.0.0.0.0-10.0.15 Oracle Communications Diameter Signaling Router
Oracle Communications Instant Messaging Server, version 10.0.1.8.0 Oracle Communications Instant Messaging Server
Oracle Communications Messaging Server, version 8.1.0.0 Oracle Communications Messaging Server
Oracle Communications Network Analytics Data Director, versions 24.2.0, 24.2.0.0.1, 24.3.4, 25.1.200, 25.2.100, 25.2.200 Oracle Communications Network Analytics Data Director
Oracle Communications Network Charging and Control, versions 15.0.0.0.0, 15.0.1.0.0 Oracle Communications Network Charging and Control
Oracle Communications Network Integrity, versions 7.3.6, 7.4.0, 7.5.0, 8.0.0 Oracle Communications Network Integrity
Oracle Communications Offline Mediation Controller, versions 15.0.0.0.0-15.2.0.0.0 Oracle Communications Offline Mediation Controller
Oracle Communications Operations Monitor, versions 5.2, 6.0, 6.1 Oracle Communications Operations Monitor
Oracle Communications Order and Service Management, versions 7.4.1, 7.5.0, 8.0.0 Oracle Communications Order and Service Management
Oracle Communications Performance Intelligence Center, versions 10.5.0.1.0, 10.5.0.2.0 Oracle Communications Performance Intelligence Center
Oracle Communications Policy Management, version 15.0.0.0 Oracle Communications Policy Management
Oracle Communications Pricing Design Center, versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0 Oracle Communications Pricing Design Center
Oracle Communications Service Catalog and Design, versions 8.0.0.7.0-8.3.0.3.0 Oracle Communications Service Catalog and Design
Oracle Communications Session Border Controller, versions 9.3.0, 10.0.0, 10.1.0 Oracle Communications Session Border Controller
Oracle Communications Unified Assurance, versions 6.1.1-7.0.0 Oracle Communications Unified Assurance
Oracle Communications Unified Inventory Management, versions 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, 8.0.1 Oracle Communications Unified Inventory Management
Oracle Communications User Data Repository, version 15.0 Oracle Communications User Data Repository
Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Database Server, versions 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2 Database
Oracle Demantra Demand Management, versions 12.2.3-12.2.15 Oracle Supply Chain Products
Oracle E-Business Suite, versions 12.2.3-12.215, V16 Oracle E-Business Suite
Oracle Enterprise Communications Broker, versions 4.2.0, 5.0.0, 5.1.0 Oracle Enterprise Communications Broker
Oracle Enterprise Data Quality, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Enterprise Manager Base Platform, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Enterprise Manager for Fusion Middleware, version 13.5 Oracle Enterprise Manager
Oracle Enterprise Manager for MySQL Database, versions 13.5.4.0.0-13.5.5.0.0 Oracle Enterprise Manager
Oracle Essbase, version 21.8.1.0.0 Database
Oracle Financial Services Analytical Applications Infrastructure, versions 8.0.7.9.0, 8.0.8.7.0, 8.1.2.5.0 Oracle Financial Services Analytical Applications Infrastructure
Oracle Financial Services Compliance Studio, versions 8.1.2.9, 8.1.3.0, 8.1.3.1 Oracle Financial Services Compliance Studio
Oracle Financial Services Model Management and Governance, version 8.1.2.7 Oracle Financial Services Model Management and Governance
Oracle Fusion Middleware, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Global Lifecycle Management NextGen OUI Framework, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0, 15.1.1.0.0 Fusion Middleware
Oracle GoldenGate, versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.2 Database
Oracle GoldenGate Big Data and Application Adapters, versions 19.1.0.0.0-19.1.0.0.22, 21.3-21.20, 23.4-23.26.1 Database
Oracle GoldenGate Stream Analytics, versions 19.1.0.0.0-19.1.0.0.15 Database
Oracle GoldenGate Studio, versions 23.8.0-23.26.1 Database
Oracle GoldenGate Veridata, versions 23.1.0.0.0-23.26.1.0.0.0 Database
Oracle GraalVM Enterprise Edition, version 21.3.18 Java SE
Oracle GraalVM for JDK, versions 17.0.19, 21.0.11 Java SE
Oracle Graph Server and Client, versions 25.4.1, 25.4.2, 26.1.0 Database
Oracle Health Sciences Information Manager, versions 4.0.0-4.0.2 HealthCare Applications
Oracle Healthcare Data Repository, versions 8.2.0.0-8.2.0.7 HealthCare Applications
Oracle Healthcare Master Person Index, versions 5.0.0.0-5.0.9.6 HealthCare Applications
Oracle Hospitality Cruise Shipboard Property Management (SPMS), versions 23.1, 23.2 Oracle Hospitality Cruise Shipboard Property Management (SPMS)
Oracle Hospitality Simphony, versions 19.8-19.8.5, 19.9-19.9.3, 19.10 Oracle Hospitality Simphony
Oracle HTTP Server, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Java SE, versions 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 Java SE
Oracle JDeveloper, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Middleware Common Libraries and Tools, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle NoSQL Database, version 1.7 Database
Oracle Platform Security for Java, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Product Lifecycle Analytics, version 3.6.1 Oracle Supply Chain Products
Oracle Retail Allocation, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail Bulk Data Integration, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail EFTLink, versions 21.0.0-25.0.0 Retail Applications
Oracle Retail Extract Tranform and Load, version 13.2.8 Retail Applications
Oracle Retail Financial Integration, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail Integration Bus, versions 14.1.3.2, 16.0.3, 19.0.1 Retail Applications
Oracle Retail Invoice Matching, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail Price Management, version 16.0.3 Retail Applications
Oracle Retail Pricing, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail Service Backbone, versions 16.0.3, 19.0.1 Retail Applications
Oracle Retail Xstore Point of Service, versions 21.0.3, 21.0.5-25.0.1 Retail Applications
Oracle Security Service, version 12.2.1.4.0 Fusion Middleware
Oracle SOA Suite, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Solaris, versions 11.3, 11.4 Systems
Oracle Spatial Studio, versions 23.2.1, 24.2 Database
Oracle SQL Developer, versions 19.3-24.3 Database
Oracle Transportation Management, version 6.5.3 Oracle Supply Chain Products
Oracle Unified Directory, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Utilities Application Framework, versions 4.3.0.5.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0-4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10, 26.4 Oracle Utilities Applications
Oracle Utilities Network Management System, versions 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.2 Oracle Utilities Applications
Oracle Utilities Testing Accelerator, versions 7.0.0.0.8, 7.0.0.1.7, 25.4.0.0.3 Oracle Utilities Applications
Oracle VM VirtualBox, versions 7.2.8, 7.2.12 Virtualization
Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
Oracle Weblogic Server Proxy Plug-in, versions 12.2.1.4.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
PeopleSoft Enterprise CC Common Application Objects, version 9.2 PeopleSoft
PeopleSoft Enterprise CRM Common Objects, version 9.2.23 PeopleSoft
PeopleSoft Enterprise CS Campus Community, version 9.2.38 PeopleSoft
PeopleSoft Enterprise CS Financial Aid, version 9.2.38 PeopleSoft
PeopleSoft Enterprise CS Student Financials, version 9.2.38 PeopleSoft
PeopleSoft Enterprise CS Student Records, version 9.2.38 PeopleSoft
PeopleSoft Enterprise FIN Billing Argentina, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Cash Management, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Common Objects, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Common Objects Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Engineering Argentina, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN eSettlements, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Expenses, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN General Ledger Argentina, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Grants, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Manufacturing Argentina, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Manufacturing Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise FIN Pay/Bill Management, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Payables, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Program Management, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Project Costing, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Staffing Front Office, version 9.2 PeopleSoft
PeopleSoft Enterprise FIN Staffing Front Office Brazil, version 9.1 PeopleSoft
PeopleSoft Enterprise HCM Global Payroll Mexico, version 9.2 PeopleSoft
PeopleSoft Enterprise HCM Global Payroll Switzerland, version 9.2 PeopleSoft
PeopleSoft Enterprise HCM Human Resources, version 9.2 PeopleSoft
PeopleSoft Enterprise HCM Talent Acquisition Manager, version 9.2 PeopleSoft
PeopleSoft Enterprise PeopleTools, versions 8.61, 8.62 PeopleSoft
PeopleSoft Enterprise SCM eProcurement, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Inventory, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Manufacturing, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Mobile Inventory Management, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Order Management, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Purchasing, version 9.2 PeopleSoft
PeopleSoft Enterprise SCM Supplier Contract Management, version 9.2 PeopleSoft
PeopleSoft In-Memory Project Discovery, version 9.2 PeopleSoft
Primavera Gateway, versions 21.12-21.12.17 Oracle Construction and Engineering Suite
Primavera P6 Enterprise Project Portfolio Management, versions 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.2, 23.12.0-23.12.19, 24.12.0-24.12.14, 25.12.0-25.12.4 Oracle Construction and Engineering Suite
Primavera Unifier, versions 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6 Oracle Construction and Engineering Suite
Service Delivery Platform, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Siebel Applications, versions 17.0-26.5 Siebel
TimesTen In-Memory Database, versions 22.1.1.1.0, 26.1.1.1.0 Database
WebCenter Content: Imaging, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware

Risk Matrix Content

Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.

Several vulnerabilities addressed in this Critical Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.

Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).

Oracle conducts an analysis of each security vulnerability addressed by a Critical Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.

Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.

The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.

Workarounds

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update security patches as soon as possible. Until you apply the Critical Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.

Skipped Security Patch Updates

Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.

Critical Patch Update Supported Products and Versions

Patches released through the Critical Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Patch Update program are available for the versions they are currently running.

Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.

Credit Statement

The following people or organizations reported security vulnerabilities addressed by this Critical Patch Update to Oracle:

  • 1seal: CVE-2026-60147
  • 4ra1n, pyn3rd and unam4: CVE-2026-47057, CVE-2026-47058, CVE-2026-47064
  • Adam Kues of Assetnote Security Research Team: CVE-2026-60146
  • Alexander Kornbrust of Red Database Security: CVE-2026-47045, CVE-2026-47060, CVE-2026-47061
  • Artur Bandura: CVE-2026-46984, CVE-2026-46985, CVE-2026-46986
  • Asim Viladi Oglu Manizada: CVE-2026-60163
  • BBBBear: CVE-2026-47059
  • crixer (pwning_me) working with TrendAI Zero Day Initiative: CVE-2026-60155
  • Dennis Tighe: CVE-2026-60184, CVE-2026-60185, CVE-2026-60585
  • Dhiraj Mishra: CVE-2026-47043
  • Diego Palacios: CVE-2026-47047
  • Dylan Pindur of Assetnote Security Research Team: CVE-2026-60146
  • Emad Al-Mousa of Saudi Aramco's Upstream Digital Center (UDC): CVE-2026-47038
  • Erichen: CVE-2026-47041, CVE-2026-47044
  • Fushuling: CVE-2026-61082
  • Giovanni Vignone of Octane Security: CVE-2026-60161
  • Hakim Bouhachni of Calif.io: CVE-2026-47050
  • Haogang Mao of SKLCCSE Lab at Beihang University: CVE-2026-60311, CVE-2026-61093
  • Hazley Samsudin: CVE-2026-47054
  • HexRabbit of DEVCORE Research Team: CVE-2026-61211
  • Hhy: CVE-2026-60160
  • Jan Czerlunczakiewicz of STM CYBER: CVE-2026-47002
  • Jie Liang of SKLCCSE Lab at Beihang University: CVE-2026-61093
  • Jimi Sebree of Horizon3.ai: CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170
  • Joakim Bülow: CVE-2026-61081
  • Joohyun Park: CVE-2026-47053
  • Lian Owen: CVE-2026-41254
  • Omkhar Arasaratnam of Linkedin: CVE-2026-60185
  • Paolo Gentry of Octane Security: CVE-2026-60161
  • Pucagit of CyStack: CVE-2026-60585, CVE-2026-60747
  • Quan Huynh of Calif.io: CVE-2026-61094
  • RacerZ: CVE-2026-61082
  • Robert van Eijk of Octane Security: CVE-2026-60161
  • Shubham Antil of Octane Security: CVE-2026-60161
  • Shubham Shah of Assetnote Security Research Team: CVE-2026-60146
  • tonghuaroot: CVE-2026-60147
  • Trung Nguyen of CyStack: CVE-2026-60300
  • Trần Thái Dương of CyStack: CVE-2026-60150
  • Vmpr0be: CVE-2026-47055, CVE-2026-60158
  • vnth4nhnt: CVE-2026-61108, CVE-2026-61109
  • Weiheng Qiu of Vanderbilt University: CVE-2026-47008, CVE-2026-60145, CVE-2026-60194, CVE-2026-60195, CVE-2026-60718
  • Xiaobye (xiaobye_tw) of DEVCORE Research Team working with TrendAI Zero Day Initiative: CVE-2026-60159, CVE-2026-60162
  • Yukihiro Nakamura: CVE-2026-47062

Security-In-Depth Contributors

Oracle acknowledges people who have contributed to our Security-In-Depth program (see FAQ). People are acknowledged for Security-In-Depth contributions if they provide information, observations or suggestions pertaining to security vulnerability issues that result in significant modification of Oracle code or documentation in future releases, but are not of such a critical nature that they are distributed in Critical Patch Updates.

In this Critical Patch Update, Oracle recognizes the following for contributions to Oracle's Security-In-Depth program:

  • Alexander Kornbrust of Red Database Security
  • HexRabbit of DEVCORE Research Team
  • Jerry Buck
  • Khanh Vi
  • TyunS-21 [2 reports]
  • Weiheng Qiu of Vanderbilt University

On-Line Presence Security Contributors

Oracle acknowledges people who have contributed to our On-Line Presence Security program (see FAQ). People are acknowledged for contributions relating to Oracle's on-line presence if they provide information, observations or suggestions pertaining to security-related issues that result in significant modification to Oracle's on-line external-facing systems.

For this quarter, Oracle recognizes the following for contributions to Oracle's On-Line Presence Security program:

  • Mohamed Hakkou
  • Qusai Okla

Upcoming Security Release Dates

Security patches are released on the third Tuesday of each month. The next four dates are:

  • 18 August 2026 (CSPU)
  • 15 September 2026 (CSPU)
  • 20 October 2026 (CPU)
  • 17 November 2026 (CSPU)

References

 

Modification History

Date Note
2026-July-21 Rev 1. Initial Release.

 

Oracle Database Products Risk Matrices

This Critical Patch Update contains 72 new security patches for Oracle Database Products divided as follows:

  • 15 new security patches for Oracle Database Products
  • 3 new security patches for Oracle APEX
  • 4 new security patches for Oracle Autonomous Health Framework
  • 1 new security patch for Oracle Essbase
  • 1 new security patch for Oracle Global Lifecycle Management
  • 27 new security patches for Oracle GoldenGate
  • No new security patches for Oracle Graph Server and Client, but third party patches are provided
  • 1 new security patch for Oracle NoSQL Database
  • 1 new security patch for Oracle Spatial Studio
  • 5 new security patches for Oracle SQL Developer
  • 14 new security patches for Oracle TimesTen In-Memory Database

 

Oracle Database Server Risk Matrix

This Critical Patch Update contains 15 new security patches, plus additional third party patches noted below, for Oracle Database Products.  6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  3 of these patches are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed. The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61211 RDBMS Execute DBMS_CLOUD Oracle Net No 9.9 Network Low Low None Changed High High High 19.3-19.31, 23.4.0-23.26.2  
CVE-2026-47040 Oracle Net Services Connection Manager Oracle Net Yes 9.1 Network Low None None Un-
changed
High None High 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-4738 Oracle Spatial and Graph (gdal) None HTTPS No 8.8 Network Low Low None Un-
changed
High High High 19.3-19.31, 23.4.0-23.26.2  
CVE-2026-60175 RDBMS Authenticated User Oracle Net No 8.8 Network Low Low None Un-
changed
High High High 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-47046 RDBMS None Oracle Net Yes 8.2 Network Low None None Un-
changed
None Low High 23.4.0-23.26.2  
CVE-2026-7383 Database (OpenSSL) None TLS Yes 8.1 Network High None None Un-
changed
High High High 23.4.0-23.26.2  
CVE-2026-54518 Fleet Patching and Provisioning (jackson-databind) None Multiple No 7.5 Network High Low None Un-
changed
High High High 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-47045 JDBC None Oracle Net No 6.8 Network Low High Required Un-
changed
High High High 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-47039 Java VM Create Session Oracle Net No 6.5 Network Low Low None Un-
changed
None High None 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-47060 JDBC None Oracle Net Yes 6.5 Network Low None Required Un-
changed
None High None 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-46975 RDBMS None Oracle Net Yes 5.8 Network Low None None Changed None Low None 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2025-7962 Java VM (Jakarta Mail) None SMTP No 5.7 Network Low Low Required Un-
changed
None High None 19.3-19.30, 23.4.0-23.26.1  
CVE-2026-47061 JDBC None HTTP Yes 5.6 Adjacent
Network
High None Required Changed High None None 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  
CVE-2026-54515 Oracle Spatial and Graph (jackson-databind) None HTTP No 4.3 Network Low Low None Un-
changed
None Low None 21.3-21.22  
CVE-2026-47038 RDBMS None Oracle Net No 2.7 Network Low High None Un-
changed
None Low None 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2  

Additional CVEs addressed are:

  • The patch for CVE-2026-54515 also addresses CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54516, CVE-2026-54517, and CVE-2026-54518.
  • The patch for CVE-2026-7383 also addresses CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, and CVE-2026-9076.
  • The patch for CVE-2026-54518 also addresses CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, and CVE-2026-54517.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • GraalVM Multilingual Engine: CVE-2026-23865 [VEX Justification: vulnerable_code_not_in_execute_path].
  • RDBMS (Apache Tomcat): CVE-2026-43512 and CVE-2026-43515 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • RDBMS (jackson-databind): CVE-2026-54513 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • RDBMS (Perl): CVE-2026-4176, CVE-2026-27171 and CVE-2026-3381 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • RDBMS (Perl): CVE-2026-10879 [VEX Justification: vulnerable_code_not_in_execute_path].
  • RDBMS (Python): CVE-2026-7210, CVE-2025-66418, CVE-2025-66471, CVE-2025-70873, CVE-2026-21441, CVE-2026-2297, CVE-2026-25645, CVE-2026-3219, CVE-2026-34073, CVE-2026-39892, CVE-2026-40192 and CVE-2026-6192 [VEX Justification: vulnerable_code_not_in_execute_path].

Oracle Database Server Client-Only Installations

  • The following Oracle Database Server vulnerabilities included in this Critical Patch Update affect client-only installations: CVE-2026-47045, CVE-2026-47060 and CVE-2026-47061.

 

Oracle APEX Risk Matrix

This Critical Patch Update contains 3 new security patches for Oracle APEX.  2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60630 Oracle APEX Installation None No 5.5 Local Low Low None Un-
changed
High None None 24.1, 24.2, 26.1  
CVE-2026-60156 Oracle APEX General HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 24.1,24.2,26.1  
CVE-2026-54285 Oracle APEX Infrastructure (opentelemetry-js) Multiple Yes 5.3 Network Low None None Un-
changed
None None Low 24.2, 26.1  

 

Oracle Autonomous Health Framework Risk Matrix

This Critical Patch Update contains 4 new security patches for Oracle Autonomous Health Framework.  3 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-28387 Oracle Autonomous Health Framework Trace file analyzer (Python) Multiple Yes 8.1 Network High None None Un-
changed
High High High 26.2.0, 26.3.0  
CVE-2026-7383 Oracle Autonomous Health Framework Autonomous Health Framework (OpenSSL) TLS Yes 8.1 Network High None None Un-
changed
High High High 26.5.0  
CVE-2024-28168 Oracle Autonomous Health Framework Healthcheck (Apache FOP) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.1  
CVE-2026-60172 Oracle Autonomous Health Framework Developer triaging platform None No 6.3 Local High High Required Un-
changed
High High High 26.0.0, 26.1.0, 26.2.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-28387 also addresses CVE-2026-2673, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, and CVE-2026-31790.

 

Oracle Essbase Risk Matrix

This Critical Patch Update contains 1 new security patch for Oracle Essbase.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2025-68161 Oracle Essbase Essbase Web Platform (Apache Log4j) TLS Yes 4.8 Network High None None Un-
changed
Low Low None 21.8.1.0.0  

 

Oracle Global Lifecycle Management Risk Matrix

This Critical Patch Update contains 1 new security patch for Oracle Global Lifecycle Management.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-54518 OPatch Installer (jackson-databind) Multiple Yes 8.1 Network High None None Un-
changed
High High High 12.2.0.1.16-12.2.0.1.51  

Additional CVEs addressed are:

  • The patch for CVE-2026-54518 also addresses CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, and CVE-2026-54517.

 

Oracle GoldenGate Risk Matrix

This Critical Patch Update contains 27 new security patches, plus additional third party patches noted below, for Oracle GoldenGate.  9 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-2332 Oracle GoldenGate Big Data and Application Adapters Java Delivery (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 21.3-21.20, 23.4-23.26.1  
CVE-2026-60398 Oracle GoldenGate Oracle GoldenGate Microservices HTTP No 8.8 Network Low Low None Un-
changed
High High High 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1  
CVE-2026-60157 Oracle GoldenGate Service Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 19.1.0.0.0-19.29.0.0, 21.3-21.21, 23.4-23.26.1.0.0  
CVE-2026-60400 Oracle GoldenGate Admin Server Executable HTTPS No 8.8 Network Low Low None Un-
changed
High High High 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1  
CVE-2026-61106 Oracle GoldenGate Config Service Executable HTTP Yes 8.1 Network High None None Un-
changed
High High High 23.4-23.26.2  
CVE-2026-60570 Oracle GoldenGate Libraries None No 7.8 Local Low Low None Un-
changed
High High High 23.4-23.26.1  
CVE-2026-33871 Oracle GoldenGate Big Data and Application Adapters Third Party (Netty) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 21.3-21.20, 23.4-23.26.1  
CVE-2026-60396 Oracle GoldenGate Distribution Server executable HTTPS No 7.2 Network Low High None Un-
changed
High High High 21.3-21.21, 23.4-23.26.1  
CVE-2026-24281 GoldenGate Stream Analytics Security (Apache ZooKeeper) Multiple Yes 6.8 Adjacent
Network
High None None Un-
changed
High High None 19.1.0.0.0-19.1.0.0.15  
CVE-2026-60399 Oracle GoldenGate Receiver Service Executable HTTP No 6.5 Network Low Low None Un-
changed
None None High 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1  
CVE-2026-61079 Oracle GoldenGate Libraries None No 5.8 Local High High Required Un-
changed
High Low High 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.2  
CVE-2025-54920 GoldenGate Stream Analytics Third Party (Apache Spark) HTTP No 5.3 Adjacent
Network
High High None Un-
changed
Low Low High 19.1.0.0.0-19.1.0.0.15  
CVE-2026-60394 Oracle GoldenGate Admin Server Executable HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 21.3-21.21, 23.4-23.26.1  
CVE-2025-67721 Oracle GoldenGate Stream Analytics Third Party (Aircompressor) HTTP No 5.3 Network High Low None Un-
changed
High None None 19.1.0.0.0-19.1.0.0.15  
CVE-2026-61084 Oracle GoldenGate Libraries None No 4.4 Local Low Low None Un-
changed
Low Low None 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.2  
CVE-2026-60395 Oracle GoldenGate Admin Server Executable HTTP No 4.3 Network Low Low None Un-
changed
Low None None 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1  
CVE-2026-60397 Oracle GoldenGate Admin Server Executable HTTP Yes 4.3 Adjacent
Network
Low None None Un-
changed
None None Low 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1  
CVE-2026-34481 GoldenGate Stream Analytics Security (Apache Log4j) HTTP Yes 3.7 Network High None None Un-
changed
None Low None 26.1.0.0.0  
CVE-2024-29371 GoldenGate Stream Analytics Security (jose4j) HTTP Yes 3.7 Network High None None Un-
changed
None None Low 19.1.0.0.0-19.1.0.0.15  
CVE-2026-47022 GoldenGate Stream Analytics Security None No 3.3 Local Low Low None Un-
changed
None None Low 26.1.0.0.0  
CVE-2026-33871 GoldenGate Stream Analytics Security (Netty) None No 3.2 Local High None None Changed Low None None 26.1.0.0.0  
CVE-2026-35554 GoldenGate Stream Analytics Security (Apache Kafka) TCP Yes 3.1 Adjacent
Network
High None None Un-
changed
None None Low 26.1.0.0.0  
CVE-2025-67721 GoldenGate Stream Analytics Security (Aircompressor) None No 2.9 Local High None None Un-
changed
None None Low 26.1.0.0.0  
CVE-2026-21452 GoldenGate Stream Analytics Security (MessagePack) None No 2.9 Local High None None Un-
changed
None None Low 26.1.0.0.0  
CVE-2026-1002 GoldenGate Stream Analytics Security (Vert.x-Web) None No 2.9 Local High None None Un-
changed
None None Low 26.1.0.0.0  
CVE-2025-67030 GoldenGate Stream Analytics Security (Apache Maven Shared Utils) None No 1.9 Local High High None Un-
changed
Low None None 26.1.0.0.0  
CVE-2026-1225 GoldenGate Stream Analytics Security (logback) None No 1.9 Local High High None Un-
changed
None Low None 26.1.0.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-33871 also addresses CVE-2026-33870, CVE-2026-42577, and CVE-2026-42582.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • GoldenGate Stream Analytics
    • Security (Apache Commons IO): CVE-2024-47554 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (Apache Commons Lang): CVE-2025-48924 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (Apache Hadoop): CVE-2025-27821 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (Jakarta Expression Language): CVE-2021-28170 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (JinJava): CVE-2026-25526 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (Plexus Utils): CVE-2025-67030 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (jackson-databind): CVE-2023-35116 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Third Party (Apache Kafka): CVE-2026-33557 and CVE-2026-35554 [VEX Justification: component_not_present].
    • Security (Eclipse Jetty): CVE-2025-5115 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Security (Google Guava): CVE-2020-8908 [VEX Justification: vulnerable_code_not_in_execute_path].
  • Oracle GoldenGate
    • Embedded Web UI for Services (Axios): CVE-2026-25639 and CVE-2025-13465 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Embedded Web UI for Services (Lodash): CVE-2025-13465 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Embedded Web UI for Services (React): CVE-2026-22029 [VEX Justification: vulnerable_code_not_in_execute_path].
    • Extract Executable (Apache Log4j): CVE-2026-34478, CVE-2026-34480 and CVE-2026-34481 [VEX Justification: inline_mitigations_already_exist].
    • Libraries (JTOpen): CVE-2024-37997, CVE-2023-29053, CVE-2023-30796 and CVE-2024-37996 [VEX Justification: inline_mitigations_already_exist].
  • Oracle GoldenGate Big Data and Application Adapters
    • Java Delivery (Aircompressor): CVE-2025-67721 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • Java Delivery (Apache Log4j): CVE-2026-34481 and CVE-2025-68161 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • Java Delivery (Google Protobuf-Java): CVE-2024-7254 [VEX Justification: vulnerable_code_not_in_execute_path].
  • Oracle GoldenGate Stream Analytics
    • Third Party (Apache ActiveMQ): CVE-2026-41044, CVE-2026-40466 and CVE-2026-41043 [VEX Justification: component_not_present].
  • Oracle GoldenGate Studio
    • OGG Orchestration Service (Apache Commons Lang): CVE-2025-48924 [VEX Justification: vulnerable_code_not_in_execute_path].
    • OGG Orchestration Service (Bouncy Castle Java FIPS): CVE-2025-8916 and CVE-2025-8885 [VEX Justification: vulnerable_code_not_in_execute_path].
  • Oracle GoldenGate Veridata
    • Server (Mchange Commons Java): CVE-2026-27727 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
    • Thirdparty Jars (Netty): CVE-2025-67735 and CVE-2026-33870 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].

 

Oracle Graph Server and Client Risk Matrix

This Critical Patch Update contains no new security patches for exploitable vulnerabilities but does include third party patches, noted below, for the following non-exploitable third party CVEs for Oracle Graph Server and Client.  Please refer to previous Critical Patch Update Advisories if the last Critical Patch Update was not applied for the Oracle Graph Server and Client.  The English text form of this Risk Matrix can be found here.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Graph Server and Client
    • Packaging/install issues (Apache Tomcat): CVE-2026-34487, CVE-2026-34483, CVE-2026-34486 and CVE-2026-34500 [VEX Justification: component_not_present].
    • Packaging/install issues (Eclipse Jetty): CVE-2026-1605 [VEX Justification: component_not_present].
    • Packaging/install issues (Lodash): CVE-2026-4800 and CVE-2026-2950 [VEX Justification: vulnerable_code_not_present].

 

Oracle NoSQL Database Risk Matrix

This Critical Patch Update contains 1 new security patch for Oracle NoSQL Database.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2025-27821 Oracle NoSQL Database Administration (Apache Hadoop) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 1.7  

 

Oracle Spatial Studio Risk Matrix

This Critical Patch Update contains 1 new security patch for Oracle Spatial Studio.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-34481 Oracle Spatial Studio Install issues (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 23.2.1, 24.2  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle SQL Developer Risk Matrix

This Critical Patch Update contains 5 new security patches for Oracle SQL Developer.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-33557 SQL Developer Installation (Apache Kafka) TCP Yes 9.1 Network Low None None Un-
changed
High High None 19.3-24.3  
CVE-2025-27553 Oracle SQL Developer Infrastructure (Apache Commons VFS) Multiple Yes 7.5 Network Low None None Un-
changed
High None None 19.3-24.3  
CVE-2025-66566 SQL Developer Installation (lz4-java) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 19.3-24.3  
CVE-2025-48924 SQL Developer Installation (Apache Commons Lang) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 22.4.0, 23.1, 24.2, 24.2.0, 24.3  
CVE-2025-21502 SQL Developer Installation Multiple Yes 4.8 Network High None None Un-
changed
Low Low None 24.3  

Additional CVEs addressed are:

  • The patch for CVE-2025-27553 also addresses CVE-2024-47554.
  • The patch for CVE-2025-21502 also addresses CVE-2025-0509.
  • The patch for CVE-2026-33557 also addresses CVE-2024-56128, CVE-2025-27817, and CVE-2026-35554.

 

Oracle TimesTen In-Memory Database Risk Matrix

This Critical Patch Update contains 14 new security patches for Oracle TimesTen In-Memory Database.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60402 TimesTen In-Memory Database Kubernetes Operator HTTPS No 9.9 Network Low Low None Changed High High High 26.1.1.1.0  
CVE-2026-4176 TimesTen In-Memory Database Third-party components (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 26.1.1.1.0  
CVE-2026-42587 TimesTen In-Memory Database Third-party components (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 22.1.1.1.0  
CVE-2026-24308 TimesTen In-Memory Database TimesTen Grid (Apache ZooKeeper) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 22.1.1.1.0  
CVE-2026-60406 TimesTen In-Memory Database Kubernetes Operator None No 6.7 Local Low High None Un-
changed
High High High 26.1.1.1.0  
CVE-2026-60403 TimesTen In-Memory Database Kubernetes Operator HTTPS No 6.5 Network Low Low None Un-
changed
None None High 26.1.1.1.0  
CVE-2026-60404 TimesTen In-Memory Database Kubernetes Operator HTTPS No 6.5 Network Low Low None Un-
changed
None None High 26.1.1.1.0  
CVE-2026-60401 TimesTen In-Memory Database Kubernetes Operator None No 6.5 Local Low Low None Changed High None None 26.1.1.1.0  
CVE-2026-60411 TimesTen In-Memory Database ttcserver TCP Yes 6.5 Adjacent
Network
Low None None Un-
changed
None None High 26.1.1.1.0  
CVE-2026-60409 TimesTen In-Memory Database Kubernetes Operator None No 5.7 Local Low High None Changed Low Low Low 26.1.1.1.0  
CVE-2026-60407 TimesTen In-Memory Database Kubernetes Operator None No 5.6 Local High Low None Changed High None None 26.1.1.1.0  
CVE-2026-60408 TimesTen In-Memory Database Kubernetes Operator HTTPS No 4.3 Network Low Low None Un-
changed
Low None None 26.1.1.1.0  
CVE-2026-60410 TimesTen In-Memory Database Kubernetes Operator HTTPS No 4.3 Network Low Low None Un-
changed
None None Low 26.1.1.1.0  
CVE-2026-60405 TimesTen In-Memory Database Kubernetes Operator None No 3.8 Local Low Low None Changed Low None None 26.1.1.1.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-4176 also addresses CVE-2026-27171 and CVE-2026-3381.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-24308 also addresses CVE-2026-24281.

 

Oracle Application Testing Suite Risk Matrix

This Critical Patch Update contains 4 new security patches for Oracle Application Testing Suite.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Component Package and/or Privilege Required Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46876 Oracle Application Testing Suite Install Oracle Net Yes 9.8 Network Low None None Un-
changed
High High High 13.3.0.1  
CVE-2026-46924 Oracle Application Testing Suite Load Testing for Web Apps TCP Yes 9.8 Network Low None None Un-
changed
High High High 13.3.0.1  
CVE-2026-35290 Oracle Application Testing Suite OpenScript TCP Yes 9.8 Network Low None None Un-
changed
High High High 13.3.0.1  
CVE-2026-35287 Oracle Application Testing Suite OpenScript TCP Yes 7.5 Network Low None None Un-
changed
High None None 13.3.0.1  

 

Oracle Commerce Risk Matrix

This Critical Patch Update contains 39 new security patches for Oracle Commerce.  26 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61146 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP No 9.9 Network Low Low None Changed High High High 11.4.0  
CVE-2026-4176 Oracle Commerce Guided Search Content Acquisition System (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61145 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61161 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61154 Oracle Commerce Guided Search Platform Services Forge HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61129 Oracle Commerce Platform ATG Portals HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61131 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 9.8 Network Low None None Un-
changed
High High High 11.4.0  
CVE-2026-61153 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-61155 Oracle Commerce Guided Search Platform Services Forge HTTP Yes 9.1 Network Low None None Un-
changed
High None High 11.4.0  
CVE-2026-61156 Oracle Commerce Guided Search Platform Services Forge HTTPS Yes 9.1 Network Low None None Un-
changed
High High None 11.4.0  
CVE-2026-61130 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 9.1 Network Low None None Un-
changed
High None High 11.4.0  
CVE-2026-61148 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.4.0  
CVE-2026-61149 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 11.4.0  
CVE-2026-61150 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.1 Network Low Low None Un-
changed
High High None 11.4.0  
CVE-2026-61160 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 8.1 Network Low Low None Un-
changed
High None High 11.4.0  
CVE-2026-61163 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Forge HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-61137 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 8.1 Network High None None Un-
changed
High High High 11.4.0  
CVE-2026-61132 Oracle Commerce Platform Dynamo Application Framework HTTP No 7.6 Network Low Low Required Changed High Low None 11.4.0  
CVE-2026-34487 Oracle Commerce Guided Search Content Acquisition System (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-42587 Oracle Commerce Guided Search Content Acquisition System (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.4.0  
CVE-2025-48976 Oracle Commerce Guided Search Experience Manager (Apache Commons FileUpload) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.4.0  
CVE-2026-61157 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-61159 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-61158 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager RMI Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-42403 Oracle Commerce Platform Dynamo Application Framework (Apache Neethi) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 11.4.0  
CVE-2026-61133 Oracle Commerce Platform Dynamo Application Framework LDAP Yes 7.5 Network Low None None Un-
changed
High None None 11.4.0  
CVE-2026-61164 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System HTTPS Yes 7.4 Network High None None Un-
changed
High High None 11.4.0  
CVE-2026-61135 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 7.4 Network High None None Un-
changed
High High None 11.4.0  
CVE-2026-61136 Oracle Commerce Platform Dynamo Application Framework HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 11.4.0  
CVE-2026-61151 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 7.1 Network Low Low None Un-
changed
High Low None 11.4.0  
CVE-2026-61162 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Endeca Application Controller None No 7.1 Local Low Low None Un-
changed
High High None 11.4.0  
CVE-2026-61165 Oracle Commerce Guided Search Platform Services Forge HTTP No 7.1 Network Low Low None Un-
changed
Low None High 11.4.0  
CVE-2026-61134 Oracle Commerce Platform Dynamo Application Framework HTTP No 6.8 Network High Low None Un-
changed
High High None 11.4.0  
CVE-2025-14017 Oracle Commerce Guided Search Platform Services Forge (curl) None No 6.3 Local High None Required Un-
changed
High High None 11.4.0  
CVE-2026-61147 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Content Acquisition System None No 6.2 Local Low None None Un-
changed
None None High 11.4.0  
CVE-2026-34316 Oracle Commerce Service Center Commerce Service Center HTTP Yes 6.1 Network Low None Required Changed Low Low None 11.4.0  
CVE-2026-27601 Oracle Commerce Platform Business Control Center (underscore) HTTP Yes 5.9 Network High None None Un-
changed
None None High 11.4.0  
CVE-2026-61152 Oracle Commerce Guided Search / Oracle Commerce Experience Manager Experience Manager HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 11.4.0  
CVE-2025-68161 Oracle Commerce Platform Dynamo Application Framework (Apache Log4j) HTTPS Yes 4.8 Network High None None Un-
changed
Low Low None 11.4.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-4176 also addresses CVE-2026-27171 and CVE-2026-3381.
  • The patch for CVE-2026-61146 also addresses CVE-2024-21117, CVE-2024-21118, CVE-2024-21119, and CVE-2024-21120.
  • The patch for CVE-2026-42403 also addresses CVE-2026-42402.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-34487 also addresses CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34500.
  • The patch for CVE-2025-14017 also addresses CVE-2025-13034, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.

 

Oracle Communications Risk Matrix

This Critical Patch Update contains 168 new security patches, plus additional third party patches noted below, for Oracle Communications.  122 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-4176 Oracle Communications Billing and Revenue Management Platform (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-4800 Oracle Communications Cloud Native Core Binding Support Function Install (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.200  
CVE-2026-39892 Oracle Communications Cloud Native Core DBTier Configuration (Cryptography) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.1.200, 25.2.200  
CVE-2025-31651 Oracle Communications Cloud Native Core Network Exposure Function Platform (Apache Tomcat) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 24.2.0  
CVE-2025-9900 Oracle Communications Cloud Native Core Network Exposure Function Platform (LibTIFF) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 24.2.5  
CVE-2026-4176 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.200  
CVE-2026-29167 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Apache HTTP Server) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.200  
CVE-2026-4800 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.200  
CVE-2026-4176 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.2.200  
CVE-2026-4176 Oracle Communications Cloud Native Core Security Edge Protection Proxy perf-info (Perl) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 25.1.203, 25.2.200  
CVE-2026-4800 Oracle Communications Network Analytics Data Director Third Party (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 24.2.0.0.1, 24.3.4, 25.1.200  
CVE-2026-42779 Oracle Communications Network Integrity Cartridges (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 7.3.6, 7.4.0, 7.5.0, 8.0.0  
CVE-2026-2332 Oracle Cloud Native Session Border Controller Third Party (Eclipse Jetty) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 26.0.0  
CVE-2026-33557 Oracle Communications Billing and Revenue Management Platform (Apache Kafka) TCP Yes 9.1 Network Low None None Un-
changed
High High None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-40976 Oracle Communications Cloud Native Core Binding Support Function Install (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 25.1.200  
CVE-2026-40976 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 25.1.200  
CVE-2026-40976 Oracle Communications Cloud Native Core Security Edge Protection Proxy Configuration (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 25.1.203, 25.2.200  
CVE-2026-33557 Oracle Communications Cloud Native Core Service Communication Proxy Install (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 25.1.200, 25.2.100  
CVE-2026-40976 Oracle Communications Cloud Native Core Unified Data Repository Install (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 25.2.200  
CVE-2026-40976 Oracle Communications Network Analytics Data Director Third Party (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 24.2.0.0.1, 24.3.4  
CVE-2026-34520 Oracle Communications Operations Monitor Mediation Engine (AIOHTTP) HTTPS Yes 9.1 Network Low None None Un-
changed
None High High 5.2, 6.0, 6.1  
CVE-2026-33557 Oracle Communications Unified Inventory Management Third Party (Apache Kafka) TCP Yes 9.1 Network Low None None Un-
changed
High High None 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, 8.0.1  
CVE-2026-61223 Oracle Communications Converged Application Server Security TCP/IP Yes 9.0 Network High None None Changed High High High 8.2, 8.3  
CVE-2025-9900 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (LibTIFF) HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 24.2.0  
CVE-2026-61127 Oracle Communications Service Catalog and Design Solution Designer HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.0.0.7.0-8.3.0.2.0  
CVE-2026-0861 Oracle Communications Cloud Native Core Certificate Management Configuration (glibc) None No 8.4 Local Low None None Un-
changed
High High High 25.2.200  
CVE-2025-32990 Oracle Communications Cloud Native Core Network Slice Selection Function Install (GnuTLS) HTTP Yes 8.2 Network Low None None Un-
changed
None Low High 25.2.200  
CVE-2026-54518 Oracle Communications Billing and Revenue Management Platform (jackson-core) HTTP Yes 8.1 Network High None None Un-
changed
High High High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-41855 Oracle Communications BRM - Elastic Charging Engine Security issues (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-41855 Oracle Communications Cloud Native Core Binding Support Function Install (Spring Framework) HTTPS Yes 8.1 Network High None None Un-
changed
High High High 25.1.200  
CVE-2026-22747 Oracle Communications Cloud Native Core Binding Support Function Install (Spring Security) HTTPS No 8.1 Network Low Low None Un-
changed
High High None 25.1.200  
CVE-2026-41855 Oracle Communications Cloud Native Core Network Repository Function Configuration (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.2.201  
CVE-2026-41855 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.2.200  
CVE-2026-22747 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Spring Security) HTTPS No 8.1 Network Low Low None Un-
changed
High High None 25.2.200  
CVE-2026-41855 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.1.200  
CVE-2026-22747 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Spring Security) HTTPS No 8.1 Network Low Low None Un-
changed
High High None 25.1.200  
CVE-2026-41855 Oracle Communications Cloud Native Core Security Edge Protection Proxy Configuration (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.1.203, 25.2.200  
CVE-2026-22747 Oracle Communications Cloud Native Core Security Edge Protection Proxy Configuration (Spring Security) HTTPS No 8.1 Network Low Low None Un-
changed
High High None 25.1.203, 25.2.200  
CVE-2026-41855 Oracle Communications Cloud Native Core Service Communication Proxy ATS Framework (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.1.200, 25.2.100, 25.2.200  
CVE-2026-41855 Oracle Communications Cloud Native Core Unified Data Repository Install (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 25.2.200  
CVE-2026-61225 Oracle Communications Converged Application Server Core TCP/IP Yes 8.1 Network High None None Un-
changed
High High High 8.2, 8.3  
CVE-2025-5318 Oracle Communications Diameter Signaling Router Automated Test Suite (libssh) SSH No 8.1 Network Low Low None Un-
changed
High None High 9.0.0, 9.0.1, 9.1.0-10.0.15  
CVE-2026-9256 Oracle Communications Operations Monitor Mediation Engine (nginx) HTTPS Yes 8.1 Network High None None Un-
changed
High High High 5.2, 6.0, 6.1  
CVE-2026-27099 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Jenkins) HTTP No 8.0 Network Low Low Required Un-
changed
High High High 25.2.200  
CVE-2026-61224 Oracle Communications Converged Application Server Security TLS No 8.0 Network High High None Changed High High High 8.3  
CVE-2026-61091 Oracle Communications Billing and Revenue Management BRM Server None No 7.8 Local Low Low None Un-
changed
High High High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-61126 Oracle Communications Billing and Revenue Management Platform None No 7.8 Local Low Low None Un-
changed
High High High 15.0.0.0.0-15.0.1.0.0, 15.1.0.0.0-15.2.0.0.0  
CVE-2026-61053 Oracle Communications BRM - Elastic Charging Engine Diameter Gateway and SDK None No 7.8 Local Low Low None Un-
changed
High High High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2025-14821 Oracle Communications Cloud Native Core Binding Support Function Install (libssh) None No 7.8 Local Low Low None Un-
changed
High High High 25.2.200  
CVE-2025-8837 Oracle Communications Cloud Native Core Network Exposure Function Platform (JasPer) None No 7.8 Local Low Low None Un-
changed
High High High 24.2.5  
CVE-2026-43500 Oracle Communications Cloud Native Core Network Function Cloud Native Environment Configuration (Linux Kernel) None No 7.8 Local Low Low None Un-
changed
High High High 25.2.200  
CVE-2025-14821 Oracle Communications Cloud Native Core Network Slice Selection Function Install (libssh) None No 7.8 Local Low Low None Un-
changed
High High High 25.2.200  
CVE-2025-14821 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (libssh) None No 7.8 Local Low Low None Un-
changed
High High High 25.2.200  
CVE-2025-8837 Oracle Communications Cloud Native Core Security Edge Protection Proxy ATS Framework (JasPer) None No 7.8 Local Low Low None Un-
changed
High High High 25.1.203, 25.2.200  
CVE-2025-8837 Oracle Communications Cloud Native Core Service Communication Proxy ATS Framework (JasPer) None No 7.8 Local Low Low None Un-
changed
High High High 25.1.200, 25.2.100  
CVE-2025-14821 Oracle Communications Cloud Native Core Service Communication Proxy Install (libssh) None No 7.8 Local Low Low None Un-
changed
High High High 25.1.200, 25.2.100, 25.2.200  
CVE-2026-43284 Oracle Communications Diameter Signaling Router IDIH Visualization (Linux Kernel) None No 7.8 Local High Low None Changed High High High 9.1.0.0.0, 9.2.0.0.0, 9.3.0.0.0, 6.1.0.0.0, 6.2.0.0.0, 6.3.0.0.0, 6.0.2.2.0  
CVE-2026-31431 Oracle Communications Diameter Signaling Router PMAC (Linux Kernel) None No 7.8 Local Low Low None Un-
changed
High High High 9.0.0.0.0, 9.1.0.0.0, 9.2.0.0.0, 9.3.0.0.0  
CVE-2026-43500 Oracle Communications Diameter Signaling Router Platform (Loadable Kernel Module) None No 7.8 Local Low Low None Un-
changed
High High High 9.0.0.0.0-9.3.0.0.0  
CVE-2026-43284 Oracle Communications Performance Intelligence Center Security (Linux Kernel) None No 7.8 Local High Low None Changed High High High 10.5.0.1.0, 10.5.0.2.0  
CVE-2026-43500 Oracle Communications User Data Repository Platform (Linux Kernel) None No 7.8 Local Low Low None Un-
changed
High High High 15.0  
CVE-2026-34481 Management Cloud Engine Security (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.2.0.0.0  
CVE-2026-34487 Management Cloud Engine Security (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.2.0.0.0  
CVE-2026-27135 Management Cloud Engine Security (Nghttp2) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.0.0.0  
CVE-2026-27141 Oracle Cloud Native Session Border Controller Security (Golang Go) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 26.0.0  
CVE-2026-34481 Oracle Communications Billing and Revenue Management Platform (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-34481 Oracle Communications BRM - Elastic Charging Engine Security issues (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-42587 Oracle Communications BRM - Elastic Charging Engine Security issues (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-42587 Oracle Communications Cloud Native Core Binding Support Function Install (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.200  
CVE-2026-40192 Oracle Communications Cloud Native Core Binding Support Function Install (Pillow) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-21441 Oracle Communications Cloud Native Core Binding Support Function Install (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-27135 Oracle Communications Cloud Native Core Binding Support Function Install (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Binding Support Function Install (Apache Log4j) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 25.2.200  
CVE-2026-4111 Oracle Communications Cloud Native Core Certificate Management Configuration (libarchive) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-23865 Oracle Communications Cloud Native Core Certificate Management Default Component (FreeType) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.2.200  
CVE-2026-5588 Oracle Communications Cloud Native Core Certificate Management Configuration (Bouncy Castle Java Library) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 25.2.200  
CVE-2026-28390 Oracle Communications Cloud Native Core Certificate Management Configuration (OpenSSL) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-4424 Oracle Communications Cloud Native Core Console Console (libarchive) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.1.203, 25.2.201  
CVE-2026-27135 Oracle Communications Cloud Native Core Console Console (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.201  
CVE-2026-42198 Oracle Communications Cloud Native Core Console CNC Console (PostgreSQL JDBC Driver) SQL Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.201  
CVE-2025-13151 Oracle Communications Cloud Native Core DBTier Configuration (Libtasn1) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.200, 25.2.200  
CVE-2026-42587 Oracle Communications Cloud Native Core DBTier Configuration (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.200, 25.2.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Network Exposure Function Install (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 24.2.5  
CVE-2026-42587 Oracle Communications Cloud Native Core Network Exposure Function Install (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 24.2.5  
CVE-2026-21441 Oracle Communications Cloud Native Core Network Exposure Function Install (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 24.2.5  
CVE-2026-27135 Oracle Communications Cloud Native Core Network Exposure Function Install (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 24.2.5  
CVE-2026-42587 Oracle Communications Cloud Native Core Network Repository Function CONFIG (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.201  
CVE-2026-34481 Oracle Communications Cloud Native Core Network Repository Function Configuration (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.2.201  
CVE-2026-21441 Oracle Communications Cloud Native Core Network Repository Function Configuration (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.201  
CVE-2026-27135 Oracle Communications Cloud Native Core Network Repository Function NRF (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.2.201  
CVE-2026-34481 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.2.200  
CVE-2026-42587 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-40192 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Pillow) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2025-66418 Oracle Communications Cloud Native Core Network Slice Selection Function Install (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-27135 Oracle Communications Cloud Native Core Network Slice Selection Function Install (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-34487 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.2.200  
CVE-2026-42587 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-40192 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Pillow) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2025-70873 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (SQLite) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.2.200  
CVE-2026-27135 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Apache Log4j) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 25.2.200  
CVE-2025-66418 Oracle Communications Cloud Native Core Policy Policy (urllib3) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 24.2.7  
CVE-2026-21441 Oracle Communications Cloud Native Core Security Edge Protection Proxy ATS Framework (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.1.203, 25.2.200  
CVE-2026-42587 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.200  
CVE-2026-40192 Oracle Communications Cloud Native Core Security Edge Protection Proxy perf-info (Pillow) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.200  
CVE-2026-27135 Oracle Communications Cloud Native Core Security Edge Protection Proxy SEPP (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.1.203, 25.2.200  
CVE-2026-21441 Oracle Communications Cloud Native Core Service Communication Proxy Install (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.1.200, 25.2.100  
CVE-2026-34481 Oracle Communications Cloud Native Core Service Communication Proxy Signaling (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.1.200, 25.2.100, 25.2.200  
CVE-2026-27135 Oracle Communications Cloud Native Core Service Communication Proxy Signaling (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 25.1.200, 25.2.100, 25.2.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Unified Data Repository Install (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.200  
CVE-2026-34481 Oracle Communications Cloud Native Core Unified Data Repository Install (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 25.2.200  
CVE-2026-42587 Oracle Communications Cloud Native Core Unified Data Repository Install (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-30922 Oracle Communications Cloud Native Core Unified Data Repository Install (Python) TCP Yes 7.5 Network Low None None Un-
changed
None None High 25.2.200  
CVE-2026-61226 Oracle Communications Converged Application Server RTP Proxy None No 7.5 Local High High None Changed High High High 8.3  
CVE-2025-66418 Oracle Communications Diameter Signaling Router ATS Framework (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 9.0.0.0.0, 9.0.1.0.0, 9.1.0.0.0  
CVE-2026-21441 Oracle Communications Diameter Signaling Router Automated Test Suite (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 9.0.0.0.0, 9.0.1.0.0, 9.1.0.0.0  
CVE-2026-34481 Oracle Communications Instant Messaging Server XMPP Server (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 10.0.1.8.0  
CVE-2025-70873 Oracle Communications Messaging Server Core (SQLite) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 8.1.0.0  
CVE-2026-34481 Oracle Communications Messaging Server Security (Apache Log4j) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 8.1.0.0  
CVE-2026-42587 Oracle Communications Network Analytics Data Director Third Party (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 24.2.0, 24.3.4, 25.1.200, 25.2.100, 25.2.200  
CVE-2026-27135 Oracle Communications Network Analytics Data Director Third Party (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 24.2.0, 24.3.4, 25.1.200, 25.2.100, 25.2.200  
CVE-2025-13151 Oracle Communications Network Analytics Data Director Third Party (Libtasn1) TCP Yes 7.5 Network Low None None Un-
changed
None None High 24.2.0, 24.3.4, 25.1.200, 25.2.100, 25.2.200  
CVE-2026-42587 Oracle Communications Network Charging and Control Common fns (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 15.0.0.0.0, 15.0.1.0.0  
CVE-2026-34481 Oracle Communications Offline Mediation Controller NM Core (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0.0.0.0-15.2.0.0.0  
CVE-2026-21441 Oracle Communications Operations Monitor Mediation Engine (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 5.2, 6.0, 6.1  
CVE-2026-34481 Oracle Communications Order and Service Management Security (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.0, 7.5.0, 7.4.1  
CVE-2026-42587 Oracle Communications Order and Service Management Security (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 7.5.0  
CVE-2026-34481 Oracle Communications Performance Intelligence Center Management (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 10.5.0.1.0, 10.5.0.2.0  
CVE-2026-27135 Oracle Communications Performance Intelligence Center Management (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 10.5.0.1.0, 10.5.0.2.0  
CVE-2026-34481 Oracle Communications Policy Management CMP (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 15.0.0.0  
CVE-2026-34487 Oracle Communications Policy Management Configuration Management Platform (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 15.0.0.0  
CVE-2026-27135 Oracle Communications Policy Management Configuration Management Platform (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 15.0.0.0  
CVE-2026-42587 Oracle Communications Service Catalog and Design Patch (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.0.0.7.0, 8.1.0.6.0  
CVE-2026-34478 Oracle Communications Service Catalog and Design Patch Request (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.0.7.0-8.3.0.3.0  
CVE-2026-27135 Oracle Communications Session Border Controller Routing (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 9.3.0, 10.0.0, 10.1.0  
CVE-2026-27135 Oracle Communications Unified Assurance Core (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 6.1.1-7.0.0  
CVE-2025-6491 Oracle Communications Unified Assurance Core (PHP) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 7.0.0  
CVE-2026-34481 Oracle Communications Unified Inventory Management Security Component (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, 8.0.1  
CVE-2026-42587 Oracle Communications Unified Inventory Management Security Component (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 7.7.0, 7.8.0, 8.0.1  
CVE-2026-27135 Oracle Communications Unified Inventory Management Security Component (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 7.7.0, 7.8.0, 8.0.1  
CVE-2026-27135 Oracle Enterprise Communications Broker Routing (Nghttp2) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 5.1.0, 5.0.0, 4.2.0  
CVE-2026-5795 Oracle Communications Cloud Native Core Binding Support Function Install (Eclipse Jetty) HTTP Yes 7.4 Network High None None Un-
changed
High High None 25.2.200  
CVE-2026-5795 Oracle Communications Cloud Native Core Network Repository Function Configuration (Eclipse Jetty) HTTP Yes 7.4 Network High None None Un-
changed
High High None 25.2.201  
CVE-2026-5795 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (Eclipse Jetty) HTTP Yes 7.4 Network High None None Un-
changed
High High None 25.2.200  
CVE-2026-47007 Oracle Communications Pricing Design Center On-premise Deployment None No 7.3 Local Low Low None Changed High Low None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-61095 Oracle Communications Unified Inventory Management Security HTTP No 7.1 Network Low Low None Un-
changed
High Low None 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, 8.0.1  
CVE-2026-22747 Oracle Communications Cloud Native Core Network Repository Function Configuration (Spring Security) HTTP No 6.8 Network High Low None Un-
changed
High High None 25.2.201  
CVE-2026-41989 Oracle Communications Cloud Native Core Binding Support Function Install (libgcrypt) None No 6.7 Local High None None Un-
changed
None High High 25.2.200  
CVE-2026-41989 Oracle Communications Cloud Native Core Console Install (libgcrypt) None No 6.7 Local High None None Un-
changed
None High High 25.1.203  
CVE-2026-41989 Oracle Communications Cloud Native Core Policy Alarms, KPI, and Measurements (libgcrypt) None No 6.7 Local High None None Un-
changed
None High High 25.2.200  
CVE-2026-61143 Oracle Communications Convergent Charging Controller Prov IF HTTP No 6.4 Network High High Required Un-
changed
High High High 15.0.0.0.0, 15.2.0.0.0  
CVE-2026-9256 Oracle Communications Unified Assurance Core (nginx) HTTP No 6.4 Network High High Required Un-
changed
High High High 7.0.0  
CVE-2026-24051 Oracle Communications Unified Assurance Core (Google Protobuf-Java) None No 6.3 Local High High Required Un-
changed
High High High 6.1.1-7.0.0  
CVE-2026-24051 Oracle Communications Unified Assurance Core (OpenTelemetry-Go) None No 6.3 Local High High Required Un-
changed
High High High 6.1.1-7.0.0  
CVE-2025-64713 Oracle Communications Unified Assurance Core (WebAssembly Micro Runtime) None No 6.3 Local High High Required Un-
changed
High High High 6.1.1-7.0.0  
CVE-2025-14017 Oracle Communications Unified Inventory Management Security Component (curl) None No 6.3 Local High None Required Un-
changed
High High None 7.7.0, 7.8.0, 8.0.1  
CVE-2026-40976 Oracle Communications Unified Assurance Core (Spring Boot) HTTP No 6.1 Network Low High Required Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-24400 Oracle Communications Unified Assurance Core (assertj) HTTP No 6.1 Network Low High Required Un-
changed
High None High 6.1.1-7.0.0  
CVE-2026-22747 Oracle Communications Unified Assurance Core (Spring Security) HTTPS No 6.1 Network Low High Required Un-
changed
High High None 6.1.1-7.0.0  
CVE-2026-27601 Oracle Communications Billing and Revenue Management Platform (underscore) HTTP Yes 5.9 Network High None None Un-
changed
None None High 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2025-14087 Oracle Communications Cloud Native Core Console CNC Console (glib) HTTP Yes 5.6 Network High None None Un-
changed
Low Low Low 25.1.203, 25.2.201  
CVE-2026-23903 Oracle Communications Unified Assurance Core (Apache Shiro) HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 6.1.1-7.0.0  
CVE-2026-34480 Oracle Communications Unified Assurance Core (Apache Log4j) HTTP No 4.5 Network Low High Required Un-
changed
None High None 6.1.1-7.0.0  
CVE-2026-34500 Oracle Communications Unified Assurance Core (Apache Tomcat) HTTP No 4.5 Network Low High Required Un-
changed
High None None 6.1.1-7.0.0  
CVE-2026-42587 Oracle Communications Unified Assurance Core (Netty) HTTP No 4.5 Network Low High Required Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-46863 Oracle Communications Unified Assurance MySQL Server MySQL Protocol No 4.5 Network Low High Required Un-
changed
None None High 6.1.1-7.0.0  
CVE-2026-31790 Oracle Communications Unified Assurance Core (OpenSSL) TLS No 4.5 Network Low High Required Un-
changed
High None None 6.1.1-7.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-4176 also addresses CVE-2026-27171 and CVE-2026-3381.
  • The patch for CVE-2026-9256 also addresses CVE-2026-42945.
  • The patch for CVE-2026-34500 also addresses CVE-2026-34477, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34487.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-4111 also addresses CVE-2026-4424 and CVE-2026-5121.
  • The patch for CVE-2026-29167 also addresses CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, and CVE-2026-49975.
  • The patch for CVE-2026-28390 also addresses CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789, and CVE-2026-31790.
  • The patch for CVE-2026-34520 also addresses CVE-2026-22815, CVE-2026-34513, CVE-2026-34514, CVE-2026-34515, CVE-2026-34516, CVE-2026-34517, CVE-2026-34518, CVE-2026-34519, and CVE-2026-34525.
  • The patch for CVE-2026-2332 also addresses CVE-2025-11143 and CVE-2026-1605.
  • The patch for CVE-2026-22747 also addresses CVE-2026-22748, CVE-2026-22751, CVE-2026-22753, and CVE-2026-22754.
  • The patch for CVE-2026-0861 also addresses CVE-2023-5981 and CVE-2024-0553.
  • The patch for CVE-2026-27099 also addresses CVE-2026-27100.
  • The patch for CVE-2026-24400 also addresses CVE-2023-34453, CVE-2023-34454, CVE-2023-34455, CVE-2023-43642, CVE-2024-24824, CVE-2025-33042, CVE-2025-37731, and CVE-2026-22860.
  • The patch for CVE-2026-34478 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34479, CVE-2026-34480, and CVE-2026-34481.
  • The patch for CVE-2026-43284 also addresses CVE-2026-23270, CVE-2026-31402, CVE-2026-31431, and CVE-2026-43500.
  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.
  • The patch for CVE-2025-14017 also addresses CVE-2025-13034, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.
  • The patch for CVE-2025-64713 also addresses CVE-2023-39410, CVE-2024-27532, CVE-2024-47561, and CVE-2025-33042.
  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2025-6491 also addresses CVE-2025-1220, CVE-2025-14177, CVE-2025-14178, CVE-2025-14180, and CVE-2025-1735.
  • The patch for CVE-2025-66418 also addresses CVE-2025-66471.
  • The patch for CVE-2025-9900 also addresses CVE-2025-8176, CVE-2025-8177, and CVE-2025-8961.
  • The patch for CVE-2026-24051 also addresses CVE-2022-1941, CVE-2022-28948, CVE-2022-3171, CVE-2024-0406, CVE-2024-24557, CVE-2024-29018, CVE-2024-36129, CVE-2024-36623, CVE-2024-40635, CVE-2024-7254, CVE-2025-30153, CVE-2025-30204, CVE-2025-3445, CVE-2025-62725, CVE-2026-23953, and CVE-2026-23954.
  • The patch for CVE-2025-5318 also addresses CVE-2025-4877, CVE-2025-4878, CVE-2025-5351, CVE-2025-5372, CVE-2025-5449, and CVE-2025-5987.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2025-32990 also addresses CVE-2025-32988, CVE-2025-32989, and CVE-2025-6395.
  • The patch for CVE-2026-23903 also addresses CVE-2026-23901.
  • The patch for CVE-2026-41855 also addresses CVE-2026-41838, CVE-2026-41839, CVE-2026-41840, CVE-2026-41841, CVE-2026-41842, CVE-2026-41843, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852, CVE-2026-41853, and CVE-2026-41854.
  • The patch for CVE-2025-14821 also addresses CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968, and CVE-2026-40976.
  • The patch for CVE-2026-43500 also addresses CVE-2026-43284.
  • The patch for CVE-2026-40976 also addresses CVE-2026-40973, CVE-2026-40975, and CVE-2026-40977.
  • The patch for CVE-2026-23865 also addresses CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, and CVE-2026-34282.
  • The patch for CVE-2026-41989 also addresses CVE-2026-41990.
  • The patch for CVE-2026-34480 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34481.
  • The patch for CVE-2026-42779 also addresses CVE-2026-42778.
  • The patch for CVE-2026-34487 also addresses CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34500.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Communications BRM - Elastic Charging Engine
    • Elastic Charging Engine (Undertow): CVE-2021-3629 and CVE-2025-12543 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • Oracle Communications Cloud Native Core DBTier
    • CNE (pip): CVE-2025-8869 [VEX Justification: inline_mitigations_already_exist].
  • Oracle Communications Cloud Native Core Network Exposure Function
    • Platform (PCRE2): CVE-2025-58050 [VEX Justification: vulnerable_code_not_present].
    • Platform (libssh): CVE-2025-14821 and CVE-2026-0964 [VEX Justification: vulnerable_code_cannot_be_controlled_by_adversary].
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy
    • SEPP (libssh): CVE-2025-14821 and CVE-2026-0964 [VEX Justification: vulnerable_code_not_present].
  • Oracle Communications Cloud Native Core Service Communication Proxy
    • ATS Framework (Perl): CVE-2026-4176 and CVE-2026-27171 [VEX Justification: vulnerable_code_not_present].
    • Install (Spring Boot): CVE-2026-40976 and CVE-2026-40973 [VEX Justification: vulnerable_code_not_present].
  • Oracle Communications Network Analytics Data Director
    • Third Party (Apache Kafka): CVE-2026-33557 and CVE-2026-35554 [VEX Justification: vulnerable_code_not_present].
  • Oracle Communications Service Catalog and Design
    • Third Party Patch (nginx): CVE-2026-9256 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle Construction and Engineering Risk Matrix

This Critical Patch Update contains 7 new security patches for Oracle Construction and Engineering.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-4800 Primavera Unifier Integration (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6  
CVE-2026-33557 Primavera P6 Enterprise Project Portfolio Management Web Access (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 21.12.0.0-21.12.21.8, 22.12.0.0-22.12.21.2, 23.12.0-23.12.19, 24.12.0-24.12.14, 25.12.0-25.12.4  
CVE-2026-34481 Primavera Gateway Admin (Apache Log4j) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 21.12-21.12.17  
CVE-2026-24308 Primavera Unifier Integration (Apache ZooKeeper) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6  
CVE-2026-34481 Primavera Unifier Platform (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6  
CVE-2026-42402 Primavera Unifier Platform (Apache Neethi) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6  
CVE-2026-54515 Primavera Unifier Platform (jackson-core) HTTP Yes 5.3 Network Low None None Un-
changed
None Low None 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.14, 25.12.0-25.12.6  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.
  • The patch for CVE-2026-24308 also addresses CVE-2026-24281.

 

Oracle E-Business Suite Risk Matrix

This Critical Patch Update contains 410 new security patches, plus additional third party patches noted below, for Oracle E-Business Suite.  45 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the July 2026 Critical Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Patch Update Knowledge Document (July 2026), My Oracle Support Note KA923.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60880 Oracle Work in Process Internal Operations HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60773 Oracle Application Object Library Core HTTPS No 9.6 Network Low Low None Changed High High None 12.2.3-12.2.15  
CVE-2026-62549 Oracle HRMS (UK) UK Payroll HTTP No 9.6 Network Low Low None Changed High High None 12.2.3-12.2.15  
CVE-2026-62546 Oracle Applications Framework Web Utilities HTTP No 9.1 Network Low High None Changed High High High 12.2.8-12.2.15  
CVE-2026-60989 Oracle Advanced Collections Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60829 Oracle Advanced Outbound Telephony Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60863 Oracle Advanced Pricing Pricing Installation HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61110 Oracle Applications DBA ADPatch HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60675 Oracle Applications Framework Search Bean HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60676 Oracle Applications Framework Search Bean HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62534 Oracle Applications Framework Web Utilities HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.11-12.2.15  
CVE-2026-47031 Oracle Bills of Material Bill Issues HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60920 Oracle Customer Care Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60692 Oracle Enterprise Asset Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60580 Oracle Enterprise Command Center Framework Core SSH Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High V16  
CVE-2026-62498 Oracle Flow Manufacturing Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.7-12.2.15  
CVE-2026-60678 Oracle General Ledger Internal Operations SOAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61121 Oracle HRMS (UK) UK Payroll HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.8-12.2.15  
CVE-2026-60738 Oracle Installed Base Create Item Instance HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60783 Oracle iReceivables AR Web Utilities HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60932 Oracle Labor Distribution Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60872 Oracle Order Management Product Diagnostic Tools HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61320 Oracle Payables Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.8-12.2.15  
CVE-2026-60890 Oracle Payroll Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62464 Oracle Payroll Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60897 Oracle Payroll Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61289 Oracle Process Manufacturing Product Development Quality Management Specs HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.15  
CVE-2026-60681 Oracle Process Manufacturing Regulatory Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61010 Oracle Process Manufacturing Systems Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61311 Oracle Product Hub Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60901 Oracle Project Intelligence Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62478 Oracle Public Sector Financials Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60924 Oracle Public Sector Payroll Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62476 Oracle Public Sector Payroll Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60789 Oracle Sales Offline Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60960 Oracle SDP Number Portability Internal Operations None No 8.8 Local Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-62447 Oracle Trade Management Claim LOV HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60952 Oracle Transportation Execution Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60898 Oracle Warehouse Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62496 Oracle Yard Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.6-12.2.15  
CVE-2026-61322 TeleSales Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60941 Oracle Service Fulfillment Manager Fulfillment Engine HTTP No 8.7 Network Low High None Changed High High None 12.2.3-12.2.15  
CVE-2026-47033 Oracle Contracts Integration Internal Operations HTTP No 8.5 Network High Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-62513 Oracle Process Manufacturing Regulatory Management Internal Operations HTTP No 8.5 Network Low Low None Changed High Low None 12.2.3-12.2.15  
CVE-2026-61312 Oracle Product Hub Internal Operations HTTP No 8.5 Network High Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-60763 Oracle Applications Manager Command Line - RapidClone None No 8.4 Local Low None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60677 Oracle Common Application Components Oracle Common Modules HTTP No 8.4 Network High Low None Changed High High Low 12.2.3-12.2.15  
CVE-2026-60837 Oracle Price Protection Internal Operations None No 8.4 Local Low Low None Changed High High None 12.2.3-12.2.15  
CVE-2026-60582 Oracle Enterprise Command Center Framework Core HTTP No 8.3 Network Low Low None Un-
changed
Low High High V16  
CVE-2026-62473 Oracle Installed Base Create Item Instance HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-60788 Oracle Sales Offline Internal Operations HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-62456 Oracle HRMS (UK) Internal Operations HTTPS No 8.2 Network High Low None Changed High High None 12.2.3-12.2.15  
CVE-2026-61101 Oracle MES for Process Manufacturing Internal Operations HTTP Yes 8.2 Network Low None Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-60854 Oracle Quality Internal Operations HTTP No 8.2 Network Low High None Changed High Low Low 12.2.3-12.2.15  
CVE-2026-60810 Oracle Supply Chain Trading Connector Collaboration History HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60867 Oracle Advanced Pricing Pricing Installation HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60768 Oracle Applications Framework Graph / Charting HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60670 Oracle Applications Technology Stack Client System Analyzer HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60749 Oracle Assets Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61327 Oracle Bills of Material Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.13-12.2.15  
CVE-2026-60740 Oracle Cash Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60771 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60691 Oracle Content Manager Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60857 Oracle Contracts Integration Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61338 Oracle Contracts Integration Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60741 Oracle Cost Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60844 Oracle Customer Support Update Service Request HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61297 Oracle Customers Online Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61019 Oracle Customers Online Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61020 Oracle Customers Online Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60840 Oracle Demand Signal Repository Internal Operations SQL No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-47028 Oracle Document Management and Collaboration Attachments HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60736 Oracle E-Business Intelligence Definition HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61218 Oracle E-Business Suite Secure Enterprise Search Search Integration Engine HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60972 Oracle E-Business Tax Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60974 Oracle E-Business Tax Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60756 Oracle EDI Gateway All Miscellaneous EDI Issues HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60710 Oracle EDI Gateway Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61031 Oracle Financials Common Country Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60764 Oracle Financials Common Modules Common Components HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62497 Oracle Flow Manufacturing Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.13-12.2.15  
CVE-2026-60965 Oracle HRMS (France) French HR HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62530 Oracle HRMS (France) French HR HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61122 Oracle HRMS (UK) UK Payroll HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.9-12.2.15  
CVE-2026-62468 Oracle Human Resources Enterprise Command Center HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.14-12.2.15  
CVE-2026-62472 Oracle Installed Base Create Item Instance HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.4-12.2.15  
CVE-2026-60904 Oracle Installed Base Create Item Instance HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60917 Oracle Inventory Management Core Receiving HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60732 Oracle iReceivables AR Web Utilities HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60785 Oracle iReceivables AR Web Utilities HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61024 Oracle iRecruitment Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60817 Oracle iStore Shopping Cart HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61004 Oracle Landed Cost Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60948 Oracle Learning Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60852 Oracle Lease and Finance Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61037 Oracle Loans Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62445 Oracle Order Management Product Diagnostic Tools HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.4-12.2.15  
CVE-2026-60778 Oracle Payments File Transmission HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60714 Oracle Price Protection Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61329 Oracle Price Protection Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60708 Oracle Process Manufacturing Financials Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61301 Oracle Process Manufacturing Financials Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60706 Oracle Process Manufacturing Inventory Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61005 Oracle Process Manufacturing Logistics Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61030 Oracle Process Manufacturing Product Development Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62514 Oracle Process Manufacturing Regulatory Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61287 Oracle Process Manufacturing Systems Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61000 Oracle Process Manufacturing Systems Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61310 Oracle Product Hub Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-47019 Oracle Product Hub Item Catalog HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61333 Oracle Product Workbench Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-61335 Oracle Product Workbench Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-47014 Oracle Product Workbench Security HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60848 Oracle Project Contracts Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60986 Oracle Project Portfolio Analysis Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60966 Oracle Public Sector Human Resources Regression Testing HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60871 Oracle Risk Management Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60735 Oracle Sales Offline Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60979 Oracle Scripting Internal Operations HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60959 Oracle SDP Number Portability Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60942 Oracle Service Fulfillment Manager Fulfillment Engine HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60953 Oracle Telecommunications Billing Integrator Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60793 Oracle TeleSales Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60951 Oracle Time and Labor Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62494 Oracle Time and Labor Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62504 Oracle Time and Labor Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60875 Oracle Trade Management Claim LOV HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60877 Oracle Trade Management Claim LOV HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60784 Oracle Trading Community Party Search UI HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60963 Oracle Treasury Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60686 Oracle U.S. Federal Financials Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60997 Oracle Universal Work Queue Non-Media Integration issues HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60700 Oracle Universal Work Queue UWQ Server Issues HTTP Yes 8.1 Network Low None Required Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60982 Oracle US Federal Human Resources Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62451 Oracle Work in Process Internal Operations HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.14-12.2.15  
CVE-2026-60780 Oracle Workflow Internal Operations SMTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62547 Oracle Workflow Workflow Notification Mailer SMTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60807 Oracle Bills of Material Internal Operations HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60579 Oracle Enterprise Command Center Framework Core SSH Yes 8.0 Adjacent
Network
High None None Changed High High None V16  
CVE-2026-61009 Oracle Process Manufacturing Logistics Internal Operations HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-46923 Oracle Public Sector Financials (International) Authorization HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-60790 Oracle Sales Offline Internal Operations HTTP No 8.0 Network High High None Changed High High High 12.2.3-12.2.15  
CVE-2026-60973 Oracle E-Business Tax Internal Operations None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62561 Oracle HRMS (US) Internal Operations None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61090 Oracle Project Foundation Miscellaneous None No 7.8 Local Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61324 Oracle Advanced Benefits Internal Operations HTTP No 7.7 Network Low Low None Changed None High None 12.2.15  
CVE-2026-60923 Oracle Capacity Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-61125 Oracle Configure to Order Supply to Order Workbench HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-62560 Oracle HRMS (Norway) Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-62567 Oracle HRMS (UK) UK Payroll HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-61014 Oracle Inventory Management Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60824 Oracle iSupport Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60750 Oracle Payroll Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-61142 Oracle Payroll Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60683 Oracle Process Manufacturing Regulatory Management Internal Operations HTTP No 7.7 Network Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-61325 Oracle Advanced Benefits Internal Operations HTTP No 7.6 Network Low High None Changed High Low None 12.2.15  
CVE-2026-62515 Oracle Advanced Planning Command Center Internal Operations HTTP No 7.6 Network Low High None Changed High Low None 12.2.3-12.2.15  
CVE-2026-60578 Oracle Enterprise Command Center Framework Core HTTP No 7.6 Network Low High None Changed High Low None V16  
CVE-2026-62518 Oracle Production Scheduling Internal Operations HTTP No 7.6 Network Low Low None Un-
changed
Low High Low 12.2.3-12.2.15  
CVE-2026-60886 Oracle Work in Process Internal Operations HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.3-12.2.15  
CVE-2026-61141 Oracle Advanced Benefits Affordable Care Act HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.7-12.2.15  
CVE-2026-60770 Oracle Application Object Library Core HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61116 Oracle Application Object Library Core HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61114 Oracle Application Object Library DB Privileges HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61138 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTP Yes 7.5 Network High None None Changed High Low None 12.2.3-12.2.15  
CVE-2026-46941 Oracle Cost Management Cost Maintenance HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60806 Oracle Cost Management Costing Transaction Errors HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60581 Oracle Enterprise Command Center Framework Core HTTP Yes 7.5 Adjacent
Network
High None None Un-
changed
High High High V16  
CVE-2026-62521 Oracle HRMS (US) US Payroll - General HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.7-12.2.15  
CVE-2026-61309 Oracle In-Memory Cost Management for Discrete Industries Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61026 Oracle iRecruitment Internal Operations HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61337 Oracle Lease and Finance Management Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.11-12.2.15  
CVE-2026-60894 Oracle Payroll Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62495 Oracle Process Manufacturing Process Execution Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.15  
CVE-2026-60988 Oracle Project Portfolio Analysis Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60927 Oracle Public Sector Financials Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60931 Oracle Public Sector Financials Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62493 Oracle Purchasing Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.11-12.2.15  
CVE-2026-60855 Oracle Quality Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60859 Oracle Quoting Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60943 Oracle Service Fulfillment Manager Fulfillment Engine HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61113 Oracle Application Object Library Core HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60823 Oracle iSupport Internal Operations HTTP Yes 7.4 Network High None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60827 Oracle iSupport Internal Operations HTTP Yes 7.4 Network Low None Required Changed None High None 12.2.3-12.2.15  
CVE-2026-61271 Oracle Document Management and Collaboration Attachments HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61267 Oracle HCM Configuration Workbench Spreadsheet Loading HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60945 Oracle Learning Management Internal Operations HTTP No 7.3 Network Low Low Required Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60143 Oracle Workflow Workflow Notification Mailer HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61039 Oracle Advanced Supply Chain Planning Core HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61107 Oracle Applications DBA Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60755 Oracle Assets Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61027 Oracle Cost Management Inventory Costing HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61314 Oracle EDI Gateway All Miscellaneous EDI Issues HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60576 Oracle Enterprise Command Center Framework Core HTTP No 7.2 Network Low High None Un-
changed
High High High V16  
CVE-2026-61035 Oracle Financials for the Americas Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60836 Oracle HCM Common Architecture Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60900 Oracle HCM Configuration Workbench Rapid Implementation HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62548 Oracle HRMS (US) Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46954 Oracle Human Resources Data Removal Tool HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-62466 Oracle Human Resources Data Removal Tool HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60828 Oracle Interaction Blending Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61025 Oracle iRecruitment Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60813 Oracle iStore Shopping Cart HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61336 Oracle Lease and Finance Management Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.14-12.2.15  
CVE-2026-60845 Oracle Mobile Application Server MWA General Bugs HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61115 Oracle Order Management Product Diagnostic Tools HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61006 Oracle Process Manufacturing Logistics Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61285 Oracle Process Manufacturing Systems Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.11-12.2.15  
CVE-2026-60340 Oracle Project Costing Enterprise Command Center HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60910 Oracle Property Manager Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60925 Oracle Public Sector Payroll Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.4-12.2.15  
CVE-2026-60926 Oracle Public Sector Payroll Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60786 Oracle Receivables Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60787 Oracle Receivables Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60918 Oracle Shipping Execution Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.12-12.2.15  
CVE-2026-60734 Oracle Trading Community Party Search UI HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.12  
CVE-2026-60868 Oracle Advanced Pricing Pricing Installation HTTP No 7.1 Network High Low None Changed High Low None 12.2.14-12.2.15  
CVE-2026-60870 Oracle Advanced Pricing Pricing Installation HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60774 Oracle Applications Framework Search Bean [Incl. Advanced] HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60799 Oracle Compensation Workbench Compensation Workbench HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60800 Oracle Compensation Workbench Compensation Workbench HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-62443 Oracle Contracts Integration Internal Operations HTTP Yes 7.1 Network Low None Required Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-60577 Oracle Enterprise Command Center Framework Core HTTP No 7.1 Network Low Low None Un-
changed
High Low None V16  
CVE-2026-60739 Oracle Field Service Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60772 Oracle Financials Common Modules Common Components HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-61119 Oracle HRMS (UK) UK Payroll HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-62557 Oracle HRMS (UK) UK Payroll HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-62565 Oracle HRMS (US) US Payroll Year End HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-62469 Oracle Human Resources Enterprise Command Center None No 7.1 Local Low Low None Un-
changed
High High None 12.2.14-12.2.15  
CVE-2026-60908 Oracle Installed Base Create Item Instance HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-60703 Oracle Interaction Blending Internal Operations None No 7.1 Local Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60176 Oracle Payments File Transmission HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  
CVE-2026-60838 Oracle Price Protection Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-61334 Oracle Price Protection Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-61299 Oracle Process Manufacturing Logistics Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.3-12.2.15  
CVE-2026-61049 Oracle Production Scheduling Internal Operations HTTP Yes 7.1 Adjacent
Network
High None Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60984 Oracle Project Portfolio Analysis Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-60985 Oracle Project Portfolio Analysis Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-60987 Oracle Project Portfolio Analysis Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.3-12.2.15  
CVE-2026-61012 Oracle Time and Labor Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
None High Low 12.2.3-12.2.15  
CVE-2026-61120 Oracle HRMS (US) Internal Operations None No 7.0 Local High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60744 Oracle Cost Management Internal Operations HTTP No 6.8 Network High Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62559 Oracle HRMS (US) Internal Operations HTTP No 6.8 Network Low High None Changed High None None 12.2.3-12.2.15  
CVE-2026-60795 Oracle iSetup General Ledger Update Transform, Reports HTTP No 6.8 Network High Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60862 Oracle Order Management Product Diagnostic Tools HTTP No 6.8 Network Low High None Changed High None None 12.2.3-12.2.15  
CVE-2026-60687 Oracle U.S. Federal Financials Internal Operations HTTPS Yes 6.8 Network High None None Changed High None None 12.2.3-12.2.15  
CVE-2026-60776 Oracle Application Object Library AOL Generic Loader None No 6.7 Local Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60846 Oracle Mobile Application Server MWA Terminal Server HTTP No 6.7 Network Low High None Un-
changed
High Low High 12.2.3-12.2.15  
CVE-2026-61043 Oracle Production Scheduling Internal Operations None No 6.7 Local Low Low Required Changed Low High None 12.2.3-12.2.15  
CVE-2026-62503 Oracle Time and Labor Internal Operations HTTP No 6.7 Network Low High None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-60775 Pasta Internal Operations None No 6.7 Local Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61328 Oracle Cost Management Cost Planning HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60892 Oracle HRMS (Norway) Norway Payroll HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.8-12.2.15  
CVE-2026-62465 Oracle HRMS (US) Internal Operations None No 6.6 Local Low Low None Un-
changed
Low Low High 12.2.9-12.2.15  
CVE-2026-60825 Oracle iSupport Internal Operations HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60826 Oracle iSupport Internal Operations HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61046 Oracle Production Scheduling Internal Operations HTTP No 6.6 Network High High None Changed Low High None 12.2.3-12.2.15  
CVE-2026-61013 Oracle Time and Labor Internal Operations HTTP No 6.6 Network High High None Changed High Low None 12.2.3-12.2.15  
CVE-2026-60701 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 6.6 Network High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-61251 HRMS (Australia) Payroll HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61323 Oracle Advanced Benefits Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.15  
CVE-2026-60521 Oracle Advanced Pricing Price List HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61111 Oracle Application Object Library Core None No 6.5 Local Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60761 Oracle Applications DBA Internal Operations None No 6.5 Local Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60322 Oracle Applications Manager Oracle Diagnostics Interfaces HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60843 Oracle Citizen Interaction Center Internal Operations HTTP No 6.5 Network Low High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62488 Oracle Contracts Integration Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
None High None 12.2.3-12.2.15  
CVE-2026-60165 Oracle Cost Management Enterprise Command Center HTTP No 6.5 Network Low High None Un-
changed
High High None V16  
CVE-2026-60899 Oracle HCM Configuration Workbench Rapid Implementation HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-62556 Oracle HRMS (US) Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.6-12.2.15  
CVE-2026-62562 Oracle HRMS (US) Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61249 Oracle Learning Management Import And Export HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61112 Oracle Order Management Product Diagnostic Tools HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61250 Oracle Payroll Payroll HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60893 Oracle Payroll Internal Operations None No 6.5 Local Low Low None Changed High None None 12.2.3-12.2.15  
CVE-2026-60835 Oracle Price Protection Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-62480 Oracle Public Sector Financials Internal Operations HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60978 Oracle Scripting Internal Operations HTTP No 6.5 Network Low High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-62470 Oracle Self-Service Human Resources Manager Self-Service HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60812 Oracle Supply Chain Trading Connector Collaboration History HTTP No 6.5 Network Low Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61262 Oracle Teleservice Service Diagnostics Scripts HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.3-12.215  
CVE-2026-61023 Oracle Inventory Management Internal Operations None No 6.4 Local High High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60864 Oracle Order Management Product Diagnostic Tools HTTP No 6.4 Network Low Low None Changed Low Low None 12.2.3-12.2.15  
CVE-2026-61282 Oracle Advanced Benefits Self Service Benefits HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.4-12.2.15  
CVE-2026-62542 Oracle Advanced Benefits Self Service Benefits HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60491 Oracle Advanced Inbound Telephony SDK client integration HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61256 Oracle Advanced Inbound Telephony Servers HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60777 Oracle Application Object Library Core HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61283 Oracle Bills of Material Web Services HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61294 Oracle Common Applications Calendar Calendar Synchronizations HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61051 Oracle Concurrent Processing BI Publisher Integration HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60574 Oracle Content Manager Cover Letter HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60572 Oracle E-Business Suite Integrated SOA Gateway Web Service Provider HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62528 Oracle HCM Configuration Workbench Install HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62453 Oracle HRMS (UK) Internal Operations HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61117 Oracle HRMS (UK) Internal Operations HTTP No 6.3 Network High Low None Changed High None None 12.2.8-12.2.15  
CVE-2026-62524 Oracle HRMS (US) US Payroll - General HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62527 Oracle Learning Management Import And Export HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62474 Oracle Lease and Finance Management Lease Authoring HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61277 Oracle Marketing Audience HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60573 Oracle Partner Management Partner Dashboard HTTPS No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61216 Oracle Payroll Payroll HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61304 Oracle Price Protection Internal Operations HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61274 Oracle Product Hub Item Catalog HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61275 Oracle Product Hub Role Based Security HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61269 Oracle Product Workbench WebUI HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60587 Oracle Project Foundation Project Definition HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61279 Oracle Proposals Proposals HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62525 Oracle Quality Quality Workbench HTML system HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61280 Oracle Sales for Handhelds Outlook Sync Win 32 HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60688 Oracle Scheduler Rules UI HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60697 Oracle Site Hub Site Hierarchy Flows HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-62519 Oracle Succession planning Succession plan HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61266 Oracle Supply Chain Globalization Copy Inventory Organization HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60811 Oracle Supply Chain Trading Connector Collaboration History HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-61278 Oracle Workflow Workflow Notification Mailer HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60575 Oracle Workflow Workflow Notification Mailer HTTP No 6.3 Network Low Low None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60805 Oracle Cost Management Cost Planning HTTP No 6.2 Network High High None Un-
changed
High High Low 12.2.3-12.2.15  
CVE-2026-62444 Oracle Contracts Integration Internal Operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-62487 Oracle Contracts Integration Internal Operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60802 Oracle E-Business Intelligence Internal Operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60815 Oracle iStore Shopping Cart HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60685 Oracle iSupport Internal Operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60842 Oracle Knowledge Management Search HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.5-12.2.15  
CVE-2026-62505 Oracle Time and Labor Internal Operations HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-62484 Oracle Contracts Integration Internal Operations HTTP Yes 5.9 Network High None None Un-
changed
None High None 12.2.3-12.2.15  
CVE-2026-60801 Oracle E-Business Intelligence Internal Operations HTTP No 5.9 Network High High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60695 Oracle Enterprise Asset Management Internal Operations HTTP No 5.9 Network High High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60762 Oracle Applications Technology Stack Configuration None No 5.7 Local High High None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60321 Oracle Project Manufacturing PJM Command Center None No 5.7 Local High High None Un-
changed
High High None V16  
CVE-2026-60336 Oracle Project Manufacturing PJM Command Center None No 5.7 Local High High None Un-
changed
High High None V16  
CVE-2026-60940 Oracle Service Contracts Internal Operations HTTP No 5.7 Network High High Required Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-60154 Oracle Application Object Library Core HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61264 Oracle Call Center Technology RDBMS and UI HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60717 Oracle Complex Maintenance, Repair and Overhaul Common Utilities HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60724 Oracle Customer Interaction History Outcome-Result HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61060 Oracle E-Business Suite Secure Enterprise Search Search Integration Engine HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60694 Oracle Enterprise Asset Management Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60588 Oracle Enterprise Asset Management Work Definition Issues HTTPS No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60962 Oracle Flow Manufacturing Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60344 Oracle HRMS (France) French HR Payroll HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61252 Oracle HRMS (Hong Kong) Hong Kong Payroll HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.13-12.2.15  
CVE-2026-61253 Oracle HRMS (Japanese) Oracle Payroll Japanese HTTPS Yes 5.4 Network Low None Required Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61255 Oracle HRMS (New Zealand) New Zealand Payroll HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61254 Oracle HRMS (Republic of Korea) Korean Payroll HTTP Yes 5.4 Network Low None Required Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61260 Oracle HRMS (UK) UK Payroll HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61064 Oracle iRecruitment Install / Upgrade Issues HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61257 Oracle iSupport Call Back HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61221 Oracle Item Master iSet-up bugs HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61261 Oracle Knowledge Management User Interface HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61200 Oracle Labor Distribution Internal Operations HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60310 Oracle Performance Management Appraisals HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61083 Oracle Performance Management Appraisals HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60911 Oracle Property Manager Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-60912 Oracle Property Manager Internal Operations HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-62479 Oracle Public Sector Financials Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-62482 Oracle Public Sector Financials Internal Operations HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61080 Oracle Public Sector Human Resources Regression Testing HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61263 Oracle Scripting Scripting Admin HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60571 Oracle SDP Number Portability Installation HTTP No 5.4 Network Low Low None Un-
changed
None Low Low 12.2.3-12.2.15  
CVE-2026-61075 Oracle Self-Service Human Resources Internal Operations HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60794 Oracle TeleSales Internal Operations HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60957 Oracle Transportation Execution Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.3-12.2.15  
CVE-2026-62563 Oracle Work in Process Internal Operations HTTP No 5.4 Network Low Low Required Changed Low Low None 12.2.5-12.2.15  
CVE-2026-62490 Oracle Contracts Integration Internal Operations HTTP No 5.3 Network High Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60816 Oracle iStore Shopping Cart HTTP No 5.3 Network High Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-62517 Oracle Production Scheduling Internal Operations HTTP Yes 5.3 Network High None Required Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-61050 Oracle Production Scheduling User Interface HTTP No 5.3 Network High Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-62507 Oracle Time and Labor Internal Operations HTTP No 5.3 Network High Low None Un-
changed
None High None 12.2.3-12.2.15  
CVE-2026-60888 Oracle Work in Process Internal Operations HTTP No 5.3 Network High Low None Un-
changed
High None None 12.2.3-12.2.15  
CVE-2026-60149 Oracle Workflow Workflow Notification Mailer None No 5.2 Local High High None Un-
changed
Low Low High 12.2.3-12.2.15  
CVE-2026-62486 Oracle Contracts Integration Internal Operations HTTP Yes 5.0 Network High None Required Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60907 Oracle Installed Base Create Item Instance HTTP No 5.0 Network High Low None Un-
changed
Low Low Low 12.2.4-12.2.15  
CVE-2026-61247 Oracle Workflow Workflow Notification Mailer SMTP Yes 4.8 Network High None None Un-
changed
None Low Low 12.2.3-12.2.15  
CVE-2026-61044 Oracle Production Scheduling Internal Operations HTTP No 4.7 Network Low High None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60337 Oracle Project Manufacturing PJM Command Center None No 4.7 Local High High None Un-
changed
High Low None V16  
CVE-2026-60684 Oracle Applications Framework Upload Attachments HTTP No 4.6 Network Low Low Required Un-
changed
Low Low None 12.2.8-12.2.15  
CVE-2026-61315 Oracle EDI Gateway EDI HTTP No 4.3 Network Low Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-61316 Oracle EDI Gateway EDI HTTP No 4.3 Network Low Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-62483 Oracle Project Contracts Internal Operations HTTP No 4.3 Network Low Low None Un-
changed
None Low None 12.2.3-12.2.15  
CVE-2026-61292 Oracle U.S. Federal Financials Internal Operations HTTP No 4.3 Network Low Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-62489 Oracle Contracts Integration Internal Operations HTTP No 4.2 Network High Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60760 Oracle Enterprise Asset Management Internal Operations HTTP No 4.2 Network High Low None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-61123 Oracle HRMS (US) Internal Operations HTTP No 4.2 Network High Low None Un-
changed
Low None Low 12.2.3-12.2.15  
CVE-2026-60832 Oracle Interaction Blending Internal Operations RMI No 4.1 Network High High None Un-
changed
Low Low Low 12.2.3-12.2.15  
CVE-2026-60938 Oracle Labor Distribution Internal Operations None No 4.1 Local High High None Un-
changed
None High None 12.2.3-12.2.15  
CVE-2026-61036 Oracle HRMS (Norway) Norway Payroll HTTP No 3.8 Network Low High None Un-
changed
Low Low None 12.2.3-12.2.15  
CVE-2026-60919 Oracle iSupplier Portal Internal Operations HTTP Yes 3.7 Network High None None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-61015 Oracle Time and Labor Internal Operations HTTP Yes 3.7 Network High None None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-60338 Oracle Project Manufacturing PJM Command Center None No 3.6 Local High Low None Un-
changed
None Low Low V16  
CVE-2026-60896 Oracle Work in Process Internal Operations None No 3.6 Local High Low None Un-
changed
Low None Low 12.2.3-12.2.15  
CVE-2026-60144 Oracle Workflow Workflow Notification Mailer None No 3.6 Local High Low None Un-
changed
None Low Low 12.2.3-12.2.15  
CVE-2026-60847 Oracle Order Entry Internal Operations None No 3.4 Local Low High None Un-
changed
None Low Low 12.2.3-12.2.15  
CVE-2026-61048 Oracle Inventory Optimization User Interface HTTP No 3.1 Network High Low None Un-
changed
None None Low 12.2.3-12.2.15  
CVE-2026-60922 Oracle iSupplier Portal Internal Operations HTTP No 3.1 Network High Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-60936 Oracle Labor Distribution Internal Operations HTTP No 3.1 Network High Low None Un-
changed
None None Low 12.2.3-12.2.15  
CVE-2026-60937 Oracle Labor Distribution Internal Operations HTTP No 3.1 Network High Low None Un-
changed
None Low None 12.2.3-12.2.15  
CVE-2026-60939 Oracle Project Contracts Internal Operations HTTP No 3.1 Network High Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-60339 Oracle Project Manufacturing PJM Command Center HTTP No 3.1 Network High Low None Un-
changed
Low None None V16  
CVE-2026-60929 Oracle Public Sector Financials Internal Operations HTTP No 3.1 Network High Low None Un-
changed
None Low None 12.2.3-12.2.15  
CVE-2026-60930 Oracle Public Sector Financials Internal Operations HTTP No 3.1 Network High Low None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-62508 Oracle Time and Labor Internal Operations HTTP No 3.1 Network High Low None Un-
changed
None None Low 12.2.3-12.2.15  
CVE-2026-60950 Oracle HRMS (Ireland) Internal Operations HTTP No 2.2 Network High High None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-61214 Oracle HRMS (UK) UK Payroll HTTP No 2.2 Network High High None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-60804 Oracle E-Business Intelligence Definition HTTP No 2.0 Network High High Required Un-
changed
None Low None 12.2.3-12.2.15  
CVE-2026-61303 Oracle EDI Gateway Internal Operations None No 1.9 Local High High None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-61028 Oracle Inventory Management Internal Operations None No 1.9 Local High High None Un-
changed
None None Low 12.2.3-12.2.15  
CVE-2026-61047 Oracle Production Scheduling Internal Operations None No 1.9 Local High High None Un-
changed
None Low None 12.2.3-12.2.15  
CVE-2026-60913 Oracle Property Manager Internal Operations None No 1.9 Local High High None Un-
changed
Low None None 12.2.3-12.2.15  
CVE-2026-60891 Oracle Work in Process Internal Operations None No 1.9 Local High High None Un-
changed
Low None None 12.2.3-12.2.15  

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Bills of Material
    • Setup Workbench: CVE-2026-60151 [VEX Justification: vulnerable_code_not_present].

 

Oracle Enterprise Manager Risk Matrix

This Critical Patch Update contains 27 new security patches for Oracle Enterprise Manager.  13 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.

Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the July 2026 Critical Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Patch Update July 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU231.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46994 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 13.5, 24.1  
CVE-2020-9547 Oracle Enterprise Manager Base Platform Security Framework (jackson-databind) HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46989 Oracle Enterprise Manager Base Platform UI Framework HTTPS No 9.1 Network Low Low None Changed High Low Low 13.5, 24.1  
CVE-2026-46992 Oracle Enterprise Manager Base Platform Enterprise Config Management HTTPS No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46995 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46998 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS Yes 8.8 Network Low None Required Un-
changed
High High High 13.5, 24.1  
CVE-2026-47004 Oracle Enterprise Manager Base Platform Self Update Framework HTTPS No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46993 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS No 8.2 Network High Low None Changed High High None 13.5, 24.1  
CVE-2026-46987 Oracle Enterprise Manager Base Platform Application Service Level Mgmt HTTPS No 7.7 Network Low Low None Changed High None None 13.5, 24.1  
CVE-2014-3643 Oracle Enterprise Manager for Fusion Middleware Web Services Management (Eclipse Jersey) HTTPS Yes 7.5 Network Low None None Un-
changed
High None None 13.5  
CVE-2026-46990 Oracle Enterprise Manager Base Platform Enterprise Config Management HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 13.5, 24.1  
CVE-2026-46988 Oracle Enterprise Manager Base Platform Connector Framework HTTPS No 7.2 Network Low High None Un-
changed
High High High 13.5, 24.1  
CVE-2026-47005 Oracle Enterprise Manager Base Platform Self Update Framework HTTPS No 7.2 Network Low High None Un-
changed
High High High 13.5, 24.1  
CVE-2026-47006 Oracle Enterprise Manager Base Platform Self Update Framework HTTPS No 7.2 Network Low High None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46996 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS No 7.1 Network Low Low None Un-
changed
Low High None 13.5, 24.1  
CVE-2026-46999 Oracle Enterprise Manager Base Platform Discovery Framework HTTPS Yes 7.0 Network High None None Un-
changed
Low High Low 13.5, 24.1  
CVE-2026-46997 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS No 6.5 Network Low Low None Un-
changed
None High None 13.5, 24.1  
CVE-2026-47002 Oracle Enterprise Manager Base Platform UI Framework HTTPS Yes 6.1 Network Low None Required Changed Low Low None 13.5, 24.1  
CVE-2026-47003 Oracle Enterprise Manager Base Platform UI Framework HTTPS Yes 5.9 Network High None None Un-
changed
High None None 13.5, 24.1  
CVE-2026-47001 Oracle Enterprise Manager Base Platform Web Services Framework HTTPS No 5.4 Network Low Low None Un-
changed
Low Low None 13.5, 24.1  
CVE-2026-46984 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 13.5, 24.1  
CVE-2026-46985 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 13.5, 24.1  
CVE-2026-46986 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS Yes 5.3 Network Low None None Un-
changed
Low None None 13.5, 24.1  
CVE-2025-8916 Oracle Enterprise Manager Base Platform Agent Next Gen (Bouncy Castle Java Library) HTTPS Yes 5.3 Network Low None None Un-
changed
None None Low 13.5, 24.1  
CVE-2025-68161 Oracle Enterprise Manager for MySQL Database EM Plugin: General (Apache Log4j) HTTPS Yes 4.8 Network High None None Un-
changed
Low Low None 13.5.4.0.0-13.5.5.0.0  
CVE-2026-46991 Oracle Enterprise Manager Base Platform Enterprise Config Management None No 4.4 Local Low Low None Un-
changed
Low Low None 13.5, 24.1  
CVE-2026-47000 Oracle Enterprise Manager Base Platform Security Framework HTTPS No 3.5 Network Low Low Required Un-
changed
None Low None 24.1  

Additional CVEs addressed are:

  • The patch for CVE-2020-9547 also addresses CVE-2019-14892, CVE-2019-20330, and CVE-2020-8840.

 

Oracle Financial Services Applications Risk Matrix

This Critical Patch Update contains 31 new security patches for Oracle Financial Services Applications.  26 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-4800 Oracle Banking Corporate Lending Process Management Base (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.6.0-14.8.0  
CVE-2026-4800 Oracle Financial Services Analytical Applications Infrastructure Infrastructure (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.0.7.9.0, 8.0.8.7.0, 8.1.2.5.0  
CVE-2026-4800 Oracle Financial Services Compliance Studio Reports (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.1.2.9  
CVE-2026-61097 Oracle Banking Trade Finance Process Management Common HTTP Yes 9.6 Network Low None Required Changed High High Low 14.6.0-14.8.0  
CVE-2026-33557 Oracle Banking Corporate Lending Process Management Base (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 14.6.0-14.8.0  
CVE-2026-33557 Oracle Banking Origination Configuration (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 14.6.0-14.8.0  
CVE-2026-22732 Oracle Banking Virtual Account Management Platform (Spring Security) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 14.6.0-14.8.0  
CVE-2026-33557 Oracle Financial Services Analytical Applications Infrastructure Third Party (Apache Kafka) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 8.0.7.9.0, 8.0.8.7.0, 8.1.2.5.0  
CVE-2026-40976 Oracle Financial Services Compliance Studio Reports (Spring Boot) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 8.1.3.1  
CVE-2026-41044 Oracle Financial Services Analytical Applications Infrastructure Platform (Apache ActiveMQ) HTTP No 8.8 Network Low Low None Un-
changed
High High High 8.0.7.9.0, 8.0.8.7.0, 8.1.2.5.0  
CVE-2026-61102 Oracle Banking Trade Finance Infrastructure HTTP No 8.1 Network Low Low None Un-
changed
High High None 14.6.0-14.8.0  
CVE-2026-61105 Oracle Banking Trade Finance Infrastructure HTTP No 8.1 Network Low Low None Un-
changed
High High None 14.6.0-14.8.0  
CVE-2026-22747 Oracle Financial Services Compliance Studio Reports (Spring Security) HTTP No 8.1 Network Low Low None Un-
changed
High High None 8.1.3.1  
CVE-2026-24308 Oracle Banking Corporate Lending Process Management Base (Apache ZooKeeper) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 14.6.0-14.8.0  
CVE-2026-21441 Oracle Banking Corporate Lending Process Management Base (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 14.6.0-14.8.0  
CVE-2025-41249 Oracle Banking Liquidity Management Common (Spring Framework) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 14.6.0-14.8.0  
CVE-2026-21441 Oracle Banking Liquidity Management Common (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 14.6.0-14.8.0  
CVE-2026-21441 Oracle Banking Origination Configuration (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 14.6.0-14.8.0  
CVE-2025-41248 Oracle Banking Payments Payments Core (Spring Security) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 14.5.0-14.8.0  
CVE-2024-47561 Oracle Banking Virtual Account Management Common Core (Apache Avro) HTTP No 7.5 Network High Low None Un-
changed
High High High 14.6.0-14.8.0  
CVE-2026-44248 Oracle Banking Virtual Account Management Platform (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 14.5.0-14.8.0  
CVE-2026-34481 Oracle Financial Services Analytical Applications Infrastructure Platform (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.0.7.9.0, 8.0.8.7.0, 8.1.2.5.0  
CVE-2026-34481 Oracle Financial Services Compliance Studio Reports (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.1.2.9  
CVE-2025-70873 Oracle Financial Services Compliance Studio Reports (SQLite) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 8.1.2.9  
CVE-2026-21441 Oracle Financial Services Compliance Studio Reports (urllib3) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.1.2.9  
CVE-2026-34481 Oracle Financial Services Model Management and Governance Installer (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.1.2.7  
CVE-2026-5795 Oracle Financial Services Compliance Studio Reports (Eclipse Jetty) HTTP Yes 7.4 Network High None None Un-
changed
High High None 8.1.3.0  
CVE-2025-33042 Oracle Banking Corporate Lending Process Management Base (Apache Avro) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 14.6.0-14.8.0  
CVE-2025-33042 Oracle Banking Liquidity Management Common (Apache Avro) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 14.5.0-14.8.0  
CVE-2025-33042 Oracle Banking Origination Configuration (Apache Avro) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 14.5.0-14.8.0  
CVE-2026-61220 Oracle Banking Origination Configuration HTTP Yes 6.1 Network Low None Required Changed Low Low None 14.5.0.16.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-22747 also addresses CVE-2026-22748, CVE-2026-22751, CVE-2026-22753, and CVE-2026-22754.
  • The patch for CVE-2026-41044 also addresses CVE-2026-40466 and CVE-2026-41043.
  • The patch for CVE-2026-40976 also addresses CVE-2026-40973, CVE-2026-40975, and CVE-2026-40977.
  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-21441 also addresses CVE-2025-66418.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.
  • The patch for CVE-2026-24308 also addresses CVE-2026-24281.
  • The patch for CVE-2026-44248 also addresses CVE-2025-67735, CVE-2026-33870, CVE-2026-33871, CVE-2026-41417, CVE-2026-42577, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42582, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-42587.

 

Oracle Food and Beverage Applications Risk Matrix

This Critical Patch Update contains 4 new security patches for Oracle Food and Beverage Applications.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60168 Oracle Hospitality Simphony POS HTTP Yes 9.1 Network Low None None Un-
changed
None High High 19.8-19.8.5, 19.9-19.9.3, 19.10  
CVE-2026-60169 Oracle Hospitality Simphony POS HTTP Yes 8.1 Network High None None Un-
changed
High High High 19.8-19.8.5, 19.9-19.9.3, 19.10  
CVE-2026-60167 Oracle Hospitality Simphony POS HTTP Yes 7.5 Network Low None None Un-
changed
High None None 19.8-19.8.5, 19.9-19.9.3, 19.10  
CVE-2026-60170 Oracle Hospitality Simphony POS HTTP Yes 7.5 Network Low None None Un-
changed
High None None 19.8-19.8.5, 19.9-19.9.3, 19.10  

 

Oracle Fusion Middleware Risk Matrix

This Critical Patch Update contains 355 new security patches, plus additional third party patches noted below, for Oracle Fusion Middleware.  219 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60358 Oracle Access Manager Authentication Engine HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60217 Oracle Coherence Core TCP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-47056 Oracle Data Integrator Rest Service HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60365 Oracle HTTP Server Oracle Weblogic Server Proxy Plug-in for Oracle HTTP Server HTTP Yes 10.0 Network Low None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60366 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60360 Oracle Unified Directory OUD Core LDAP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60644 Oracle WebCenter Content Web Content Management HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60365 Oracle Weblogic Server Proxy Plug-in WebLogic Server Proxy Plug-In for Third-Party Web Servers HTTP Yes 10.0 Network Low None None Changed High High None 15.1.1.0.0  
CVE-2026-60389 Service Delivery Platform Messaging Enabler HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60379 Service Delivery Platform Messaging Enabler SOAP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60333 Oracle Access Manager Authentication Engine HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60542 Oracle Business Process Management Suite Human Workflow T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60531 Oracle Identity Manager Connector Core HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60537 Oracle Managed File Transfer MFT Runtime Server HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60547 Oracle Managed File Transfer MFT Runtime Server HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60369 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60361 Oracle Unified Directory OUD Core LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60422 Oracle Unified Directory OUD Core LDAP No 9.9 Network Low Low None Changed High High Low 14.1.2.1.0  
CVE-2026-60429 Oracle Unified Directory OUD Core LDAP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60663 Oracle WebCenter Content Web Content Management HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60447 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60456 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60459 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60445 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60457 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60458 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60461 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60524 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60561 Oracle WebCenter Portal Runtime Tools HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60562 Oracle WebCenter Portal Runtime Tools HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60565 Oracle WebCenter Portal Runtime Tools HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60568 Oracle WebCenter Portal Runtime Tools HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60552 Oracle WebCenter Sites WebCenter Sites HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60206 Oracle WebLogic Server Core SAML No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60377 Service Delivery Platform Messaging Enabler T3, IIOP No 9.9 Network Low Low None Changed High High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60381 Service Delivery Platform Messaging Enabler T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60328 Oracle Access Manager Authentication Engine HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60355 Oracle Access Manager Authentication Engine HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61065 Oracle Access Manager Authentication Engine HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-41409 Oracle Access Manager Centralized Thirdparty Jars (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 15.1.1.0.0  
CVE-2026-41409 Oracle Business Process Management Suite BPM Foundation Services (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60225 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60232 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60241 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60242 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60244 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60247 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60259 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60272 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60275 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60278 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60279 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60286 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60289 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60290 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60308 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60264 Oracle Coherence Core HTTP/2 Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60280 Oracle Coherence Core HTTP/2 Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60276 Oracle Coherence Core HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60197 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60209 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60210 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60212 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60215 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60216 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60219 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60221 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60224 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60226 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60227 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60228 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60229 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60230 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60234 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60236 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60240 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60246 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60250 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60251 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60253 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60254 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60256 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60257 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60258 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60262 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60269 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60274 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60285 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60287 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60288 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60296 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60297 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60298 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60299 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60300 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60302 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60306 Oracle Coherence Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60999 Oracle Data Integrator Rest Service HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-60363 Oracle HTTP Server Apache Plugin HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60364 Oracle HTTP Server Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61196 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60329 Oracle Identity Manager OIM Legacy UI T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60532 Oracle Identity Manager Connector PeopleSoft Applications HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60535 Oracle Identity Manager Connector PeopleSoft Applications HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-41409 Oracle Middleware Common Libraries and Tools Third Party (Apache Mina) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60367 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60372 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60538 Oracle SOA Suite Enterprise Scheduling System HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60541 Oracle SOA Suite Enterprise Scheduling System HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60362 Oracle Unified Directory OUD Core LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60435 Oracle WebCenter Content Content Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61100 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60446 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60460 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60566 Oracle WebCenter Portal Runtime Tools HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60551 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60555 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61140 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-60199 Oracle WebLogic Server Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60291 Oracle WebLogic Server Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60292 Oracle WebLogic Server Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60200 Oracle WebLogic Server Core SOAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60294 Oracle WebLogic Server Core SOAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60198 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60202 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60204 Oracle WebLogic Server Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60205 Oracle WebLogic Server Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60378 Service Delivery Platform Messaging Enabler HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60380 Service Delivery Platform Messaging Enabler HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60386 Service Delivery Platform Messaging Enabler HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60374 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60375 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60376 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60384 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60385 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60387 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60388 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60441 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60442 Service Delivery Platform Messaging Enabler T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60463 WebCenter Content: Imaging Core T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60239 Oracle Coherence Core HTTP No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60540 Oracle SOA Suite Integration Business Insight HTTP No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60564 Oracle WebCenter Portal Runtime Tools HTTP No 9.6 Network Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60248 Oracle Coherence Core None No 9.3 Local Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60220 Oracle Coherence Core TCP Yes 9.3 Network Low None Required Changed High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60631 Oracle WebCenter Content Content Server HTTP Yes 9.3 Network Low None Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60632 Oracle WebCenter Content Content Server HTTP Yes 9.3 Network Low None Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60326 Oracle Access Manager Authentication Engine HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60267 Oracle Coherence Core TLS Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-33557 Oracle Enterprise Data Quality General (Apache Kafka) TCP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60438 Oracle HTTP Server mod_ssl HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60567 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61197 Oracle Identity Manager OIM Legacy UI HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60649 Oracle WebCenter Content Web Content Management HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60208 Oracle WebLogic Server Core HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60249 Oracle Coherence Core HTTP No 9.0 Adjacent
Network
Low Low None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60424 Oracle Unified Directory OUD Core LDAP Yes 9.0 Network High None None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-47037 Oracle Access Manager Authentication Engine HTTP No 8.8 Network Low Low None Un-
changed
High High High 14.1.2.1.0  
CVE-2026-60211 Oracle Coherence Core TCP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60218 Oracle Coherence Core TCP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60261 Oracle Coherence Core TCP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60268 Oracle Coherence Core TCP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60309 Oracle Coherence Core TCP Yes 8.8 Adjacent
Network
Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-41044 Oracle Enterprise Data Quality General (Apache ActiveMQ) HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60545 Oracle Managed File Transfer MFT Runtime Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60549 Oracle Managed File Transfer MFT Runtime Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2025-67030 Oracle Middleware Common Libraries and Tools Third Party (Apache Commons Lang) HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 14.1.2.0.0  
CVE-2026-60373 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61246 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60439 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60455 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60368 Oracle Platform Security for Java Centralized Thirdparty Jars SOAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60539 Oracle SOA Suite Integration Business Insight HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60419 Oracle Unified Directory OUD Core LDAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60423 Oracle Unified Directory OUD Core LDAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60430 Oracle Unified Directory OUD Core LDAP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60334 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60633 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60634 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60635 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60636 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60637 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60638 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60639 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60664 Oracle WebCenter Content Content Server HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60651 Oracle WebCenter Content Web Content Management HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60654 Oracle WebCenter Content Web Content Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60655 Oracle WebCenter Content Web Content Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60656 Oracle WebCenter Content Web Content Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2022-25315 Oracle WebCenter Content Web Content Management (LibExpat) HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61098 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61099 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60563 Oracle WebCenter Portal Runtime Tools HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60203 Oracle WebLogic Server Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60207 Oracle WebLogic Server Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60343 Oracle WebLogic Server Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60313 Oracle WebLogic Server Core RMI No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60464 WebCenter Content: Imaging Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60472 WebCenter Content: Imaging Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60503 WebCenter Content: Imaging Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60465 WebCenter Content: Imaging Core T3, IIOP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60214 Oracle Coherence Core TCP No 8.7 Adjacent
Network
Low Low None Changed High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60427 Oracle Unified Directory OUD Core LDAP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60437 Oracle Unified Directory OUD Core LDAP No 8.7 Network Low High None Changed None High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60443 Oracle WebCenter Content Content Server HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60448 Oracle WebCenter Content Content Server HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60523 Oracle WebCenter Content Content Server HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60553 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.7 Network High None None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60469 WebCenter Content: Imaging Core HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60470 WebCenter Content: Imaging Core HTTP No 8.7 Network Low Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60327 Oracle Access Manager Authentication Engine HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60356 Oracle Access Manager Authentication Engine HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60559 Oracle Access Manager Authentication Engine HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60235 Oracle Coherence Core TCP Yes 8.6 Network Low None None Un-
changed
Low Low High 15.1.1.0.0  
CVE-2026-60431 Oracle HTTP Server mod_proxy HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60536 Oracle Identity Manager Connector PeopleSoft Applications HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60359 Oracle Unified Directory OUD Core HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60550 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60556 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60293 Oracle WebLogic Server WLS - Web Services HTTP Yes 8.6 Network Low None None Changed High None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60295 Oracle Coherence Core TCP No 8.5 Network High Low None Changed High High High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60330 Oracle Identity Manager OIM Legacy UI HTTP No 8.5 Network High Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60420 Oracle Unified Directory OUD Core LDAP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60426 Oracle Unified Directory OUD Core LDAP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60444 Oracle WebCenter Content Content Server HTTP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60452 WebCenter Content: Imaging Core HTTP No 8.5 Network Low Low None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60723 Oracle Data Integrator Market Place None No 8.4 Local Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60196 Oracle WebLogic Server Core HTTP No 8.4 Adjacent
Network
Low High None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60383 Service Delivery Platform Messaging Enabler None No 8.4 Local Low Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60640 Oracle WebCenter Content Content Server HTTP Yes 8.3 Network High None Required Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60471 WebCenter Content: Imaging Core T3, IIOP Yes 8.3 Adjacent
Network
High None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60284 Oracle Coherence Core HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60255 Oracle Coherence Core TCP Yes 8.2 Network Low None None Un-
changed
None Low High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60544 Oracle SOA Suite B2B Engine HTTP Yes 8.2 Network Low None None Un-
changed
High None Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60421 Oracle Unified Directory OUD Core LDAP No 8.2 Network High Low None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60428 Oracle Unified Directory OUD Core LDAP Yes 8.2 Network Low None None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60525 Oracle WebCenter Content Content Server HTTP No 8.2 Network High Low None Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60416 Oracle Access Manager Authentication Engine HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60222 Oracle Coherence Core T3, IIOP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60273 Oracle Coherence Core TCP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60277 Oracle Coherence Core TCP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60281 Oracle Coherence Core TCP Yes 8.1 Adjacent
Network
Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-54512 Oracle Global Lifecycle Management NextGen OUI Framework NextGen Installer (jackson-databind) HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0, 15.1.1.0.0  
CVE-2026-60323 Oracle Identity Manager OIM Legacy UI HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60560 Oracle Identity Manager REST WebServices HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60543 Oracle SOA Suite B2B Engine HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60417 Oracle Unified Directory OUD Core LDAP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60520 Oracle Unified Directory OUD Core LDAP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60462 Oracle WebCenter Content Content Server HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60653 Oracle WebCenter Content Web Content Management HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60450 Oracle WebCenter Content Content Server HTTPS Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61092 Oracle WebCenter Enterprise Capture Client Bundle HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60558 Oracle WebCenter Sites WebCenter Sites HTTP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60201 Oracle WebLogic Server Core T3, IIOP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60312 Oracle WebLogic Server Core T3, IIOP Yes 8.1 Network High None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60325 Oracle Access Manager Authentication Engine HTTP No 8.0 Adjacent
Network
Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-61067 Oracle Access Manager Authentication Engine HTTP No 8.0 Adjacent
Network
Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60533 Oracle Identity Manager Connector Generic Unix Connector LDAP Yes 8.0 Adjacent
Network
High None None Changed None High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60371 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 8.0 Adjacent
Network
High Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60643 Oracle WebCenter Content Content Server HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60646 Oracle WebCenter Content Web Content Management HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60648 Oracle WebCenter Content Web Content Management HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60650 Oracle WebCenter Content Web Content Management HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60652 Oracle WebCenter Content Web Content Management HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60271 Oracle Coherence Core None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60625 Oracle Data Integrator Studio None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60454 Oracle HTTP Server Core None No 7.8 Local Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60530 Oracle HTTP Server mod_http2.so None No 7.8 Local Low Low None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-60534 Oracle Identity Manager Connector PeopleSoft Applications HTTP No 7.7 Network High High None Changed High High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60548 Oracle SOA Suite Integration Business Insight HTTP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60657 Oracle WebCenter Content Content Server HTTP No 7.7 Network High Low Required Changed High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60440 Service Delivery Platform Messaging Enabler HTTP No 7.7 Network Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60522 Oracle WebCenter Content Content Server HTTP No 7.6 Network Low Low Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60641 Oracle WebCenter Content Content Server HTTP Yes 7.6 Network Low None Required Un-
changed
High Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60642 Oracle WebCenter Content Content Server HTTP Yes 7.6 Network Low None Required Un-
changed
High Low Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60528 Oracle WebLogic Server Console HTTP No 7.6 Network Low High None Changed Low High None 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-34481 Oracle Business Process Management Suite Runtime Engine (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-34481 Oracle Coherence Centralized Thirdparty Jars (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-42587 Oracle Coherence Centralized Thirdparty Jars (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60223 Oracle Coherence Core TCP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60252 Oracle Coherence Core TCP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60263 Oracle Coherence Core TCP Yes 7.5 Network Low None None Un-
changed
High None None 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60301 Oracle Coherence Core TCP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60320 Oracle Data Integrator Patchset Assistant HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2025-7962 Oracle Enterprise Data Quality General (Jakarta Mail) SMTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-5588 Oracle Global Lifecycle Management NextGen OUI Framework NextGen Installer (Bouncy Castle Java Library) HTTPS Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 14.1.2.1.0, 15.1.1.0.0  
CVE-2026-34481 Oracle Identity Manager Installer (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60629 Oracle JDeveloper Data Visualization Tools HTTP Yes 7.5 Network High None None Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60622 Oracle JDeveloper Security Framework HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-34481 Oracle Managed File Transfer MFT Runtime Server (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-34481 Oracle Middleware Common Libraries and Tools Third Party (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 14.1.2.0.0  
CVE-2026-1605 Oracle Middleware Common Libraries and Tools Third Party (Eclipse Jetty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 14.1.2.0.0  
CVE-2026-34480 Oracle Middleware Common Libraries and Tools Third Party Analysis Tool (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0  
CVE-2026-5598 Oracle Middleware Common Libraries and Tools Third Party (Bouncy Castle Java Library) HTTPS Yes 7.5 Network Low None None Un-
changed
High None None 14.1.2.0.0  
CVE-2026-60370 Oracle Platform Security for Java Centralized Thirdparty Jars HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60425 Oracle Unified Directory OUD Core LDAP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60436 Oracle Unified Directory OUD Core LDAP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60658 Oracle WebCenter Content Content Server HTTP Yes 7.5 Network High None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60554 Oracle WebCenter Sites WebCenter Sites HTTP Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-34481 Oracle WebLogic Server Centralized Thirdparty Jars (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-5598 Oracle WebLogic Server Centralized Thirdparty Jars (Bouncy Castle Java Library) HTTPS Yes 7.5 Network Low None None Un-
changed
High None None 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-60364 Oracle Weblogic Server Proxy Plug-in WebLogic Server Proxy Plug-In for Third-Party Web Servers HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60382 Service Delivery Platform Messaging Enabler HTTP Yes 7.5 Network Low None None Un-
changed
None None High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60467 WebCenter Content: Imaging Core HTTP Yes 7.5 Network High None Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60245 Oracle Coherence Core None No 7.2 Local High Low Required Changed High High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60345 Oracle JDeveloper ADF Shared Components HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-42404 Oracle Middleware Common Libraries and Tools Third Party (Apache Neethi) HTTP Yes 7.2 Network Low None None Changed Low Low None 14.1.2.0.0  
CVE-2026-60546 Oracle SOA Suite Integration Business Insight HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60418 Oracle Unified Directory OUD Core LDAP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60519 Oracle Unified Directory OUD Core LDAP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60335 Oracle WebCenter Content Content Server HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60645 Oracle WebCenter Content Web Content Management HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60529 Oracle WebLogic Server Console HTTP No 7.2 Network Low High None Un-
changed
High High High 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60153 Oracle WebLogic Server Console HTTPS No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60466 WebCenter Content: Imaging Core HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60502 WebCenter Content: Imaging Core T3, IIOP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60305 Oracle Coherence Core TCP No 7.1 Network Low Low None Un-
changed
Low High None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60647 Oracle WebCenter Content Web Content Management HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60449 Oracle WebCenter Content Content Server None No 7.1 Local Low None None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2025-68431 Oracle WebCenter Enterprise Capture Client Bundle (libheif) HTTP Yes 7.1 Network Low None Required Un-
changed
Low None High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60527 Oracle WebLogic Server Console None No 7.1 Local Low None None Changed High None None 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60451 WebCenter Content: Imaging Core HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60468 WebCenter Content: Imaging Core HTTP No 7.1 Network Low Low None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61061 Oracle JDeveloper Security Framework None No 7.0 Local High Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60213 Oracle Coherence Core HTTP Yes 6.5 Network High None None Un-
changed
None Low High 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60243 Oracle Coherence Core TCP No 6.5 Network Low Low None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60304 Oracle Coherence Core TCP No 6.5 Network Low Low None Un-
changed
None None High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60319 Oracle Data Integrator Patchset Assistant None No 6.5 Local Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60350 Oracle JDeveloper ADF Faces None No 6.5 Local Low Low None Changed High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60557 Oracle WebCenter Sites WebCenter Sites HTTP Yes 6.5 Network Low None Required Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-61217 Oracle Security Service Oracle SSL API TLS No 6.4 Network High Low Required Un-
changed
High High None 12.2.1.4.0  
CVE-2026-60146 Oracle Access Manager Authentication Engine HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60265 Oracle Coherence Core None No 6.0 Local Low High None Changed High None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60266 Oracle Coherence Core TLS Yes 5.9 Network High None None Un-
changed
High None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60348 Oracle JDeveloper ADF Faces HTTP Yes 5.9 Network High None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60349 Oracle JDeveloper Java Business Objects HTTP No 5.9 Network High Low None Un-
changed
High None Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-22737 Oracle Middleware Common Libraries and Tools Third Party (Spring Framework) HTTP Yes 5.9 Network High None None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60270 Oracle Coherence Core HTTP No 5.5 Network Low High None Un-
changed
High Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60231 Oracle Coherence Core HTTP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60238 Oracle Coherence Core HTTP Yes 5.4 Network High None None Changed Low Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60282 Oracle Coherence Core TCP No 5.4 Network Low Low None Un-
changed
Low Low None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60342 Oracle Access Manager Authentication Engine HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-60260 Oracle Coherence Core HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60283 Oracle Coherence Core HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60237 Oracle Coherence Core TCP Yes 5.3 Network Low None None Un-
changed
Low None None 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60501 Service Delivery Platform Messaging Enabler None No 5.2 Local Low Low None Changed Low Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60351 Oracle JDeveloper ADF Faces HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60303 Oracle Coherence Core HTTP No 4.3 Network Low Low None Un-
changed
None None Low 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60307 Oracle Coherence Core HTTP No 4.3 Network Low Low None Un-
changed
Low None None 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-60233 Oracle Coherence Core TCP No 4.3 Network Low Low None Un-
changed
None None Low 15.1.1.0.0  
CVE-2026-60352 Oracle JDeveloper ADF Faces HTTP Yes 3.7 Network High None None Un-
changed
Low None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60354 Oracle JDeveloper Data Visualization Tools HTTP Yes 3.7 Network High None None Un-
changed
Low None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-60318 Oracle Data Integrator Patchset Assistant None No 3.3 Local Low Low None Un-
changed
Low None None 12.2.1.4.0, 14.1.2.0.0  
CVE-2025-48924 Oracle Fusion Middleware Oracle Database Client for Fusion Middleware (Apache Commons Lang) Multiple No 3.3 Local Low None Required Un-
changed
None None Low 14.1.2.0.0  
CVE-2026-60353 Oracle JDeveloper ADF Faces HTTP No 3.1 Network High Low None Un-
changed
Low None None 12.2.1.4.0, 14.1.2.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-33557 also addresses CVE-2026-35554.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-5598 also addresses CVE-2026-0636, CVE-2026-3505, and CVE-2026-5588.
  • The patch for CVE-2026-5588 also addresses CVE-2026-0636.
  • The patch for CVE-2026-41409 also addresses CVE-2024-52046, CVE-2026-41635, CVE-2026-42778, and CVE-2026-42779.
  • The patch for CVE-2026-34480 also addresses CVE-2026-34477, CVE-2026-34478, and CVE-2026-34479.
  • The patch for CVE-2026-54512 also addresses CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, CVE-2026-54517, and CVE-2026-54518.
  • The patch for CVE-2025-67030 also addresses CVE-2025-48924.
  • The patch for CVE-2026-41044 also addresses CVE-2026-40466 and CVE-2026-41043.
  • The patch for CVE-2026-1605 also addresses CVE-2025-11143.
  • The patch for CVE-2026-42404 also addresses CVE-2026-42402 and CVE-2026-42403.
  • The patch for CVE-2026-22737 also addresses CVE-2024-38820 and CVE-2026-22735.

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Fusion Middleware
    • Oracle Database Client for Fusion Middleware (assertj): CVE-2026-24400 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle Analytics Risk Matrix

This Critical Patch Update contains 7 new security patches for Oracle Analytics.  5 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60719 Oracle BI Publisher Web Service API HTTP No 9.9 Network Low Low None Changed High High Low 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  
CVE-2026-60173 Oracle BI Publisher BI Platform Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.2.0.0.0, 12.2.1.4.0  
CVE-2026-60671 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP Yes 8.6 Network Low None None Un-
changed
Low Low High 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-60674 Oracle Business Intelligence Enterprise Edition BI Platform Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-34480 Oracle Business Intelligence Enterprise Edition Platform Security (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.2.0.0.0, 26.01.0.0.0  
CVE-2026-39892 Oracle Business Intelligence Enterprise Edition Visual Analyzer (Cryptography) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 8.2.0.0.0  
CVE-2026-60673 Oracle BI Publisher XML Services HTTP No 6.5 Network Low Low None Un-
changed
High None None 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0  

 

Oracle HealthCare Applications Risk Matrix

This Critical Patch Update contains 4 new security patches for Oracle HealthCare Applications.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-34481 Oracle Health Sciences Information Manager Health Policy Engine (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 4.0.0-4.0.2  
CVE-2026-34481 Oracle Healthcare Data Repository FHIR Server (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 8.2.0.0-8.2.0.7  
CVE-2026-34481 Oracle Healthcare Master Person Index Master Index Data Manager (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 5.0.0.0-5.0.9.6  
CVE-2025-33042 Oracle Healthcare Master Person Index Relationship Management (Apache Avro) HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 5.0.0.0-5.0.9.6  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle Hospitality Applications Risk Matrix

This Critical Patch Update contains 2 new security patches for Oracle Hospitality Applications.  Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-4800 Oracle Hospitality Cruise Shipboard Property Management (SPMS) Next-Gen SPMS (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 23.1, 23.2  
CVE-2026-42587 Oracle Hospitality Cruise Shipboard Property Management (SPMS) Next-Gen SPMS (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 23.1, 23.2  

Additional CVEs addressed are:

  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.
  • The patch for CVE-2026-42587 also addresses CVE-2025-67735, CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.

 

Oracle Java SE Risk Matrix

This Critical Patch Update contains 19 new security patches, plus additional third party patches noted below, for Oracle Java SE.  17 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

The CVSS scores below assume that a user running a Java applet or Java Web Start application has administrator privileges (typical on Windows). When the user does not run with administrator privileges (typical on Solaris and Linux), the corresponding CVSS impact scores for Confidentiality, Integrity, and Availability are "Low" instead of "High", lowering the CVSS Base Score. For example, a Base Score of 9.6 becomes 7.1.

Java Management Service, available to all users, can help you find vulnerable Java versions in your systems. Java SE Subscribers and customers running in Oracle Cloud can use Java Management Service to update Java Runtimes and to do further security reviews like identifying potentially vulnerable third party libraries used by your Java programs. Existing Java Management Service user click here to log in to your dashboard. The Java Management Service Documentation provides a list of features available to everyone and those available only to customers. Learn more about using Java Management Service to monitor and secure your Java Installations.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-62574 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Install None No 7.8 Local Low Low None Un-
changed
High High High Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18  
CVE-2026-47057 Oracle Java SE Scripting Multiple Yes 7.5 Network Low None None Un-
changed
None None High Oracle Java SE: 8u491, 8u491-perf, 11.0.31 See Note 1
CVE-2026-41254 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition 2D (Little CMS) Multiple Yes 7.5 Network Low None None Un-
changed
None None High Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-47063 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Libraries Multiple Yes 7.5 Network Low None None Un-
changed
None High None Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-47058 Oracle Java SE Scripting Multiple Yes 7.4 Network High None None Un-
changed
High High None Oracle Java SE: 8u491, 8u491-perf, 11.0.31 See Note 1
CVE-2026-60526 Oracle Java SE Installation None No 6.7 Local High Low Required Un-
changed
High High High Oracle Java SE: 8u491, 8u491-perf See Note 1
CVE-2026-60147 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Security Multiple Yes 6.5 Network Low None None Un-
changed
Low Low None Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-46968 Oracle Java SE JSSE TLS Yes 5.9 Network High None None Un-
changed
None High None Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 2
CVE-2026-47013 Oracle Java SE JavaFX Multiple Yes 5.3 Network Low None None Un-
changed
None None Low Oracle Java SE: 8u491 See Note 1
CVE-2026-47027 Oracle Java SE Libraries Multiple Yes 5.3 Network Low None None Un-
changed
None None Low Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-47021 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition 2D Multiple Yes 5.3 Network Low None None Un-
changed
None None Low Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-46917 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition JSSE TLS Yes 5.3 Network Low None None Un-
changed
None None Low Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 2
CVE-2026-47059 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition 2D Multiple Yes 3.7 Network High None None Un-
changed
None None Low Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 3
CVE-2026-47010 Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition ImageIO Multiple Yes 3.7 Network High None None Un-
changed
None Low None Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19, 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18 See Note 1
CVE-2026-47030 Oracle Java SE JavaFX Multiple Yes 3.1 Network High None Required Un-
changed
None Low None Oracle Java SE: 8u491 See Note 3
CVE-2026-47034 Oracle Java SE JavaFX Multiple Yes 3.1 Network High None Required Un-
changed
None Low None Oracle Java SE: 8u491 See Note 3
CVE-2026-47035 Oracle Java SE JavaFX Multiple Yes 3.1 Network High None Required Un-
changed
None Low None Oracle Java SE: 8u491 See Note 3
CVE-2026-60164 Oracle Java SE JavaFX Multiple Yes 3.1 Network High None Required Un-
changed
Low None None Oracle Java SE: 8u491 See Note 3
CVE-2026-60166 Oracle Java SE JavaFX Multiple Yes 3.1 Network High None Required Un-
changed
Low None None Oracle Java SE: 8u491 See Note 3

Notes:

  1. This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security.
  2. This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service.
  3. This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).
 

Additional patches included for the following non-exploitable CVEs for this Oracle product family:

  • Oracle Java SE
    • 2D (libpng): CVE-2026-34757 and CVE-2026-33636 [VEX Justification: vulnerable_code_not_in_execute_path].

 

Oracle JD Edwards Risk Matrix

This Critical Patch Update contains 20 new security patches for Oracle JD Edwards.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60627 JD Edwards EnterpriseOne Tools Installation Security HTTP No 9.9 Network Low Low None Changed High High High 9.2.26.3  
CVE-2026-60489 JD Edwards EnterpriseOne CRM Foundation CRM Foundation HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2  
CVE-2026-60490 JD Edwards EnterpriseOne CRM Foundation CRM Foundation HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2  
CVE-2026-60493 JD Edwards EnterpriseOne Human Resources Management Human Resources HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2  
CVE-2026-60618 JD Edwards EnterpriseOne Procurement and Subcontract Management Procurement HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2  
CVE-2026-60499 JD Edwards EnterpriseOne Solution Advisor Solution Advisor HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2  
CVE-2026-60621 JD Edwards EnterpriseOne Tools Web Runtime Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 9.2.26.3  
CVE-2021-22555 JD Edwards EnterpriseOne General Ledger E1 Foundation (swift) None No 7.8 Local Low Low None Un-
changed
High High High 9.2  
CVE-2026-60496 JD Edwards EnterpriseOne Advanced Pricing - Procurement Advanced Pricing JDENET No 7.5 Network High Low None Un-
changed
High High High 9.2  
CVE-2026-60497 JD Edwards EnterpriseOne CRM Foundation CRM Foundation JDENET No 7.5 Network High Low None Un-
changed
High High High 9.2  
CVE-2026-60619 JD Edwards EnterpriseOne HCM Foundation Time Accounting and HRM Base HTTP No 7.5 Network High Low None Un-
changed
High High High 9.2  
CVE-2026-60498 JD Edwards EnterpriseOne Human Resources Management Human Resources JDENET No 7.5 Network High Low None Un-
changed
High High High 9.2  
CVE-2026-60495 JD Edwards EnterpriseOne Requirements Planning Requirements Planning JDENET No 7.5 Network High Low None Un-
changed
High High High 9.2  
CVE-2026-60492 JD Edwards EnterpriseOne HCM Foundation OW HR PR Foundation HTTP No 7.1 Network Low Low None Un-
changed
Low None High 9.2  
CVE-2026-60494 JD Edwards EnterpriseOne General Ledger E1 Foundation HTTP Yes 7.0 Network High None None Un-
changed
Low Low High 9.2  
CVE-2026-60620 JD Edwards EnterpriseOne Configurator Configuration Management HTTP No 6.4 Network High Low None Un-
changed
Low Low High 9.2  
CVE-2026-60626 JD Edwards EnterpriseOne Tools Installation Security None No 6.0 Local Low High None Changed None High None 9.2.26.3  
CVE-2026-60628 JD Edwards EnterpriseOne Tools Installation Security HTTPS Yes 3.7 Adjacent
Network
High None Required Un-
changed
Low Low None 9.2.26.3  
CVE-2026-60346 JD Edwards EnterpriseOne Tools Interoperability Security JDENET Yes 3.7 Network High None None Un-
changed
None None Low 9.2.26.3  
CVE-2026-60347 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security None No 3.6 Local High Low None Un-
changed
None Low Low 9.2.26.3  

 

Oracle MySQL Risk Matrix

This Critical Patch Update contains 54 new security patches for Oracle MySQL.  9 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60193 MySQL Connectors Connector/Net MySQL Protocol No 8.5 Network High Low None Changed High High High 9.7.0-9.7.1  
CVE-2026-60163 MySQL Server, MySQL Cluster Server: Group Replication Plugin None No 8.4 Local Low None None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60315 MySQL Server, MySQL Cluster Server: X Plugin X Protocol Yes 8.2 Network Low None None Un-
changed
Low None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60192 MySQL Connectors Connector/Net MySQL Protocol Yes 8.1 Network High None None Un-
changed
High High High 9.7.0-9.7.1  
CVE-2026-60586 MySQL Connectors Connector/J MySQL Protocol No 7.7 Network Low Low None Changed High None None 9.7.0-9.7.1  
CVE-2026-60180 MySQL Connectors Connector/C++ X Protocol Yes 7.5 Network Low None None Un-
changed
None None High 9.7.0-9.7.1  
CVE-2026-60314 MySQL Router Router: General HTTP Yes 7.5 Network Low None None Un-
changed
None None High 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60317 MySQL Connectors Connector/Net MySQL Protocol Yes 7.4 Network High None None Un-
changed
High High None 9.7.0-9.7.1  
CVE-2026-60179 MySQL Connectors Connector/C++ X Protocol Yes 7.4 Network High None None Un-
changed
High High None 9.7.0-9.7.1  
CVE-2026-60725 MySQL Router Router: General HTTP Yes 7.4 Network High None None Un-
changed
High High None 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-61094 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 7.2 Network Low High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60316 MySQL Server, MySQL Cluster Server: X Plugin X Protocol No 7.2 Network Low High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60623 MySQL Connectors Connector/J MySQL Protocol No 7.1 Network High Low None Un-
changed
High High Low 9.7.0-9.7.1  
CVE-2026-60181 MySQL Server, MySQL Cluster Server: Configurator None No 6.7 Local High Low Required Un-
changed
High High High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60178 MySQL Server, MySQL Cluster Server: Clone Plugin MySQL Protocol No 6.6 Network High High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60585 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 6.6 Network High High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-61082 MySQL Connectors Connector/J MySQL Protocol Yes 6.5 Network Low None Required Un-
changed
High None None 9.7.0-9.7.1  
CVE-2026-60624 MySQL Connectors Connector/J X Protocol Yes 6.5 Network Low None Required Un-
changed
None None High 9.7.0-9.7.1  
CVE-2026-61108 MySQL Server, MySQL Cluster Server: GIS MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60718 MySQL Server, MySQL Cluster Server: JSON MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-61109 MySQL Server, MySQL Cluster Server: JSON MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-47064 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60174 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60324 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-61093 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60311 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 6.5 Network Low Low None Un-
changed
None None High MySQL Server: 9.0.0-9.7.1; MySQL Cluster: 9.0.0-9.7.1  
CVE-2026-60183 MySQL Server, MySQL Cluster Server: Clone Plugin None No 6.4 Local High High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60332 MySQL Server, MySQL Cluster Server: Group Replication GCS None No 6.4 Local High High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60331 MySQL Server, MySQL Cluster Server: Replication None No 6.4 Local High High None Un-
changed
High High High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60747 MySQL Server, MySQL Cluster Server: Replication None No 6.2 Local Low None None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60569 MySQL Cluster Cluster: NDB Operator None No 5.1 Local High None None Un-
changed
High None None 8.0.0-8.0.47,8.4.0-8.4.10,9.7.0-9.7.1  
CVE-2026-60171 MySQL Cluster Server: Optimizer MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High 8.0.0-8.0.47  
CVE-2026-47008 MySQL Server, MySQL Cluster InnoDB MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-47052 MySQL Server, MySQL Cluster InnoDB MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60194 MySQL Server, MySQL Cluster Server: JSON Duality MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60195 MySQL Server, MySQL Cluster Server: JSON Duality MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-60145 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-61128 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-61144 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1  
CVE-2026-47023 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.9 Network Low High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60177 MySQL Server, MySQL Cluster Server: Clone Plugin MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60182 MySQL Server, MySQL Cluster Server: Clone Plugin MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-46936 MySQL Server, MySQL Cluster Server: DDL MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60186 MySQL Server, MySQL Cluster Server: Group Replication Plugin MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-47012 MySQL Server, MySQL Cluster Server: Optimizer MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60184 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60185 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60187 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60188 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60189 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 4.4 Network High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60191 MySQL Server, MySQL Cluster Server: Replication None No 4.1 Local High High None Un-
changed
None None High MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-61096 MySQL Server, MySQL Cluster Server: Pluggable Auth None No 2.9 Local High None None Un-
changed
None Low None MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-61081 MySQL Server, MySQL Cluster Server: Performance Schema MySQL Protocol No 2.7 Network Low High None Un-
changed
Low None None MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  
CVE-2026-60190 MySQL Server, MySQL Cluster Server: Replication MySQL Protocol No 2.2 Network High High None Un-
changed
None None Low MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10, 9.7.0-9.7.1  

 

Oracle PeopleSoft Risk Matrix

This Critical Patch Update contains 84 new security patches for Oracle PeopleSoft.  45 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61237 PeopleSoft Enterprise FIN Common Objects Argentina Integration HTTP Yes 9.9 Network Low None None Changed High Low Low 9.1  
CVE-2026-61242 PeopleSoft Enterprise FIN Common Objects Argentina Staffing HTTP No 9.9 Network Low Low None Changed High High High 9.1  
CVE-2026-61239 PeopleSoft Enterprise FIN Common Objects Argentina eProcurement HTTP Yes 9.9 Network Low None None Changed Low High Low 9.1  
CVE-2026-61072 PeopleSoft Enterprise FIN Staffing Front Office Brazil Staffing HTTP No 9.9 Network Low Low None Changed High High High 9.1  
CVE-2026-61076 PeopleSoft Enterprise HCM Talent Acquisition Manager Job Opening HTTP No 9.9 Network Low Low None Changed High High High 9.2  
CVE-2026-61209 PeopleSoft In-Memory Project Discovery Project Discovery HTTP No 9.9 Network Low Low None Changed High High High 9.2  
CVE-2026-61233 PeopleSoft Enterprise FIN Common Objects Brazil Integration HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.1  
CVE-2026-61245 PeopleSoft Enterprise FIN Manufacturing Brazil Integration HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 9.1  
CVE-2026-61203 PeopleSoft Enterprise FIN Expenses Expenses HTTP Yes 9.4 Network Low None None Un-
changed
High High Low 9.2  
CVE-2026-61207 PeopleSoft Enterprise SCM eProcurement Manage Requisition Status HTTP Yes 9.3 Network Low None None Changed High Low None 9.2  
CVE-2026-60606 PeopleSoft Enterprise CC Common Application Objects Common Application Objects HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.2  
CVE-2026-61238 PeopleSoft Enterprise FIN Common Objects Argentina eProcurement HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.1  
CVE-2026-61244 PeopleSoft Enterprise FIN Manufacturing Argentina Manufacturing HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.1  
CVE-2026-61235 PeopleSoft Enterprise HCM Global Payroll Switzerland Global Payroll for Switzerland HTTP No 9.1 Network Low High None Changed High High High 9.2  
CVE-2026-61059 PeopleSoft Enterprise SCM Order Management Security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.2  
CVE-2026-61201 PeopleSoft Enterprise CRM Common Objects Common Objects HTTP Yes 9.0 Network High None None Changed High High High 9.2.23  
CVE-2026-61204 PeopleSoft Enterprise FIN Program Management Primavera Integration HTTP No 9.0 Network Low Low Required Changed High High High 9.2  
CVE-2026-60594 PeopleSoft Enterprise CS Campus Community Integration and Interfaces HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2.38  
CVE-2026-60602 PeopleSoft Enterprise CS Student Financials Billing HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2.38  
CVE-2026-60603 PeopleSoft Enterprise CS Student Records Australian Features HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2.38  
CVE-2026-61062 PeopleSoft Enterprise FIN Cash Management Cash Management None No 8.8 Local Low Low None Changed High High High 9.2  
CVE-2026-61243 PeopleSoft Enterprise FIN Common Objects Argentina Staffing HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.1  
CVE-2026-61063 PeopleSoft Enterprise SCM Supplier Contract Management Security None No 8.8 Local Low Low None Changed High High High 9.2  
CVE-2026-61078 PeopleSoft Enterprise CC Common Application Objects Common Application Objects HTTP No 8.7 Network Low Low Required Changed High High None 9.2  
CVE-2026-60597 PeopleSoft Enterprise FIN Cash Management Cash Management HTTP Yes 8.7 Network High None None Changed High High None 9.2  
CVE-2026-47017 PeopleSoft Enterprise PeopleTools Process Scheduler HTTP No 8.7 Network Low Low Required Changed High High None 8.61, 8.62  
CVE-2026-60615 PeopleSoft Enterprise CS Campus Community Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 9.2.38  
CVE-2026-61240 PeopleSoft Enterprise FIN Common Objects Argentina eSettlements HTTP Yes 8.2 Adjacent
Network
Low None None Changed High Low None 9.1  
CVE-2026-60665 PeopleSoft Enterprise HCM Global Payroll Switzerland Global Payroll for Switzerland HTTP No 8.2 Network High Low None Changed High High None 9.2  
CVE-2026-60668 PeopleSoft Enterprise HCM Human Resources French Public Sector Specific HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 9.2  
CVE-2026-61089 PeopleSoft Enterprise SCM Inventory Security HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 9.2  
CVE-2026-61205 PeopleSoft Enterprise SCM Purchasing Purchasing HTTP Yes 8.2 Network Low None None Un-
changed
Low High None 9.2  
CVE-2026-60599 PeopleSoft Enterprise CS Student Records Research Tracking HTTPS No 8.1 Network Low Low None Un-
changed
High High None 9.2.38  
CVE-2026-61074 PeopleSoft Enterprise FIN Common Objects Brazil eProcurement HTTP Yes 8.1 Network High None None Un-
changed
High High High 9.1  
CVE-2026-60600 PeopleSoft Enterprise FIN Project Costing Projects None No 7.8 Local Low None Required Un-
changed
High High High 9.2  
CVE-2026-61055 PeopleSoft Enterprise SCM Order Management Security None No 7.8 Local Low Low None Un-
changed
High High High 9.2  
CVE-2026-60604 PeopleSoft Enterprise CS Campus Community Security HTTP No 7.5 Network High Low None Un-
changed
High High High 9.2.38  
CVE-2026-60605 PeopleSoft Enterprise CS Student Records Higher Ed Statistics Agency - UK HESA HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.2.38  
CVE-2026-60598 PeopleSoft Enterprise CS Student Records Research Tracking HTTP No 7.5 Network High Low None Un-
changed
High High High 9.2.38  
CVE-2026-61232 PeopleSoft Enterprise FIN Common Objects Brazil Common Objects HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.1  
CVE-2026-61073 PeopleSoft Enterprise FIN Common Objects Brazil Purchasing HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.1  
CVE-2026-61236 PeopleSoft Enterprise FIN Common Objects Brazil Staffing HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.1  
CVE-2026-61087 PeopleSoft Enterprise FIN Payables Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.2  
CVE-2026-60593 PeopleSoft Enterprise FIN Staffing Front Office Staffing Front Office HTTP Yes 7.5 Network Low None None Un-
changed
None High None 9.2  
CVE-2025-59465 PeopleSoft Enterprise PeopleTools OpenSearch Dashboards (Node.js) HTTP/2 Yes 7.5 Network Low None None Un-
changed
None None High 8.61, 8.62  
CVE-2026-61085 PeopleSoft Enterprise SCM Inventory Security HTTPS Yes 7.5 Network Low None None Un-
changed
High None None 9.2  
CVE-2026-61088 PeopleSoft Enterprise SCM Manufacturing Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.2  
CVE-2026-61077 PeopleSoft Enterprise SCM Mobile Inventory Management Security None No 7.5 Local High Low None Changed High High None 9.2  
CVE-2026-61086 PeopleSoft Enterprise SCM Order Management Security HTTPS Yes 7.5 Network Low None None Un-
changed
High None None 9.2  
CVE-2026-61234 PeopleSoft Enterprise FIN Common Objects Brazil eProcurement HTTP Yes 7.4 Network High None None Un-
changed
High High None 9.1  
CVE-2026-60667 PeopleSoft Enterprise HCM Human Resources Core TCP Yes 7.4 Network High None None Un-
changed
None High High 9.2  
CVE-2026-47026 PeopleSoft Enterprise PeopleTools OpenSearch Dashboards HTTP Yes 7.4 Network Low None Required Changed High None None 8.61,8.62  
CVE-2026-61210 PeopleSoft Enterprise SCM Manufacturing Security HTTPS Yes 7.4 Network High None None Un-
changed
High High None 9.2  
CVE-2026-61068 PeopleSoft Enterprise FIN Billing Argentina Billing HTTP No 7.2 Network Low High None Un-
changed
High High High 9.1  
CVE-2026-60614 PeopleSoft Enterprise CS Campus Community Person Data HTTP No 7.1 Network High Low None Un-
changed
Low High High 9.2.38  
CVE-2026-47015 PeopleSoft Enterprise PeopleTools PIA Core Technology HTTP Yes 7.1 Network Low None Required Changed Low Low Low 8.62  
CVE-2025-68431 PeopleSoft Enterprise PeopleTools XML Publisher (libheif) HTTP Yes 7.1 Network Low None Required Un-
changed
Low None High 8.61,8.62  
CVE-2026-60612 PeopleSoft Enterprise CS Financial Aid Commonline Loans HTTP No 6.8 Network High Low None Un-
changed
High High None 9.2.38  
CVE-2026-60666 PeopleSoft Enterprise HCM Human Resources Security Oracle Net No 6.8 Network High Low None Un-
changed
High High None 9.2  
CVE-2026-60613 PeopleSoft Enterprise CS Student Records Research Tracking HTTP No 6.6 Network High High None Un-
changed
High High High 9.2.38  
CVE-2026-60616 PeopleSoft Enterprise CS Campus Community Security HTTP Yes 6.5 Network High None None Un-
changed
High Low None 9.2.38  
CVE-2026-60617 PeopleSoft Enterprise CS Campus Community Security HTTP Yes 6.5 Network High None None Un-
changed
Low High None 9.2.38  
CVE-2026-60609 PeopleSoft Enterprise CS Campus Community Communication HTTPS No 6.5 Network Low Low None Un-
changed
High None None 9.2.38  
CVE-2026-60608 PeopleSoft Enterprise CS Financial Aid Institutional Methodology Need Analysis None No 6.1 Local Low Low None Un-
changed
Low High None 9.2.38  
CVE-2025-66021 PeopleSoft Enterprise PeopleTools File Processing (Java HTML Sanitizer) HTTP Yes 6.1 Network Low None Required Changed Low Low None 8.62  
CVE-2026-60610 PeopleSoft Enterprise CS Campus Community Security HTTPS Yes 5.9 Network High None None Un-
changed
High None None 9.2.38  
CVE-2026-61103 PeopleSoft Enterprise CS Campus Community Security HTTPS Yes 5.9 Adjacent
Network
High None None Un-
changed
High Low None 9.2.38  
CVE-2026-61069 PeopleSoft Enterprise FIN General Ledger Argentina General Ledger HTTP No 5.9 Network High Low None Un-
changed
None High Low 9.1  
CVE-2026-60669 PeopleSoft Enterprise HCM Global Payroll Mexico Global Payroll for Mexico HTTP No 5.9 Network High Low None Un-
changed
None High Low 9.2  
CVE-2026-60607 PeopleSoft Enterprise CS Financial Aid FM Need Analysis Calculator None No 5.5 Local Low Low None Un-
changed
High None None 9.2.38  
CVE-2026-60595 PeopleSoft Enterprise FIN Pay/Bill Management Paybill Management None No 5.5 Local Low Low None Un-
changed
High None None 9.2  
CVE-2026-47024 PeopleSoft Enterprise PeopleTools Panel Processor HTTP No 5.4 Network Low Low Required Changed Low Low None 8.62  
CVE-2026-60152 PeopleSoft Enterprise PeopleTools Panel Processor HTTP Yes 5.4 Network Low None Required Un-
changed
Low Low None 8.61, 8.62  
CVE-2026-47048 PeopleSoft Enterprise PeopleTools Security HTTP No 5.4 Network Low Low Required Changed Low Low None 8.61,8.62  
CVE-2026-47051 PeopleSoft Enterprise PeopleTools Security HTTP No 5.4 Network Low Low Required Changed Low Low None 8.61, 8.62  
CVE-2026-60611 PeopleSoft Enterprise CS Campus Community Security HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 9.2.38  
CVE-2026-61070 PeopleSoft Enterprise FIN Common Objects Argentina Cash Management HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 9.1  
CVE-2026-47049 PeopleSoft Enterprise PeopleTools PIA Core Technology HTTP No 4.9 Network Low High None Un-
changed
High None None 8.61,8.62  
CVE-2026-61057 PeopleSoft Enterprise FIN eSettlements eSettlements HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 9.2  
CVE-2026-61056 PeopleSoft Enterprise FIN Grants Grants HTTP Yes 4.8 Network High None None Un-
changed
Low Low None 9.2  
CVE-2026-60601 PeopleSoft Enterprise FIN Common Objects Security None No 4.4 Local High Low Required Un-
changed
None High None 9.2  
CVE-2026-61104 PeopleSoft Enterprise CS Student Records Research Tracking HTTP Yes 3.7 Network High None None Un-
changed
Low None None 9.2.38  
CVE-2026-61071 PeopleSoft Enterprise FIN Engineering Argentina Engineering HTTP No 3.3 Network High High None Un-
changed
Low Low None 9.1  
CVE-2026-60596 PeopleSoft Enterprise FIN eSettlements eSettlements None No 2.3 Local Low High None Un-
changed
Low None None 9.2  

Additional CVEs addressed are:

  • The patch for CVE-2025-59465 also addresses CVE-2025-55130, CVE-2025-55131, CVE-2025-55132, CVE-2025-59466, CVE-2026-21636, CVE-2026-21637, and CVE-2026-21710.

 

Oracle Retail Applications Risk Matrix

This Critical Patch Update contains 22 new security patches for Oracle Retail Applications.  20 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46982 Oracle Retail Integration Bus RIB Kernal HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.3.2  
CVE-2026-46983 Oracle Retail Integration Bus RIB Kernal HTTP Yes 9.8 Network Low None None Un-
changed
High High High 16.0.3  
CVE-2026-41855 Oracle Retail Financial Integration PeopleSoft Integration (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 16.0.3, 19.0.1  
CVE-2026-41855 Oracle Retail Integration Bus RIB Kernal (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 16.0.3, 19.0.1  
CVE-2026-41855 Oracle Retail Service Backbone RSB Installation (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail Bulk Data Integration BDI Job Scheduler (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail EFTLink Installation (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 21.0.0-25.0.0  
CVE-2026-34481 Oracle Retail Extract Tranform and Load Mathematical Operators (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 13.2.8  
CVE-2026-34481 Oracle Retail Financial Integration EBS Integration (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail Financial Integration PeopleSoft Integration (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail Integration Bus RIB Kernal (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail Price Management Security (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3  
CVE-2026-34481 Oracle Retail Service Backbone RSB Installation (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 16.0.3, 19.0.1  
CVE-2026-34481 Oracle Retail Xstore Point of Service Point of Sale (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 21.0.5-25.0.1  
CVE-2026-34487 Oracle Retail Xstore Point of Service Xenvironment (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 21.0.5-25.0.1  
CVE-2026-42587 Oracle Retail Xstore Point of Service Xenvironment (Netty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 22.0.3,23.0.3,24.0.2  
CVE-2026-46943 Oracle Retail EFTLink Core/Plugin HTTPS Yes 7.4 Network High None None Un-
changed
High High None 21.0.0-25.0.0  
CVE-2025-48924 Oracle Retail Allocation Security (Apache Commons Lang) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 16.0.3, 19.0.1  
CVE-2025-48924 Oracle Retail Invoice Matching Security (Apache Commons Lang) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 16.0.3, 19.0.1  
CVE-2025-48924 Oracle Retail Pricing Pricing - Security (Apache Commons Lang) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 19.0.1,16.0.3  
CVE-2026-21954 Oracle Retail Xstore Point of Service Xstore Mobile HTTP No 4.3 Network Low Low None Un-
changed
Low None None 21.0.3  
CVE-2026-21953 Oracle Retail Xstore Point of Service Xstore Mobile None No 3.3 Local Low Low None Un-
changed
Low None None 21.0.3  

Additional CVEs addressed are:

  • The patch for CVE-2026-34487 also addresses CVE-2026-24734, CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, CVE-2026-34500, and CVE-2026-43515.
  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-42587 also addresses CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, and CVE-2026-44248.
  • The patch for CVE-2026-41855 also addresses CVE-2026-41838, CVE-2026-41839, CVE-2026-41840, CVE-2026-41841, CVE-2026-41842, CVE-2026-41843, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852, CVE-2026-41853, and CVE-2026-41854.

 

Oracle Siebel CRM Risk Matrix

This Critical Patch Update contains 45 new security patches for Oracle Siebel CRM.  32 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60711 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 9.9 Network Low Low None Changed High High High 22.3-26.5  
CVE-2026-1229 Siebel CRM Cloud Applications Siebel Cloud Manager (CIRCL) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 22.3-26.5  
CVE-2026-47036 Siebel CRM Development Siebel Approval Manager HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.3  
CVE-2026-34520 Siebel CRM Cloud Applications Siebel Cloud Manager (AIOHTTP) HTTP Yes 9.1 Network Low None None Un-
changed
None High High 22.3-26.5  
CVE-2026-33186 Siebel CRM Cloud Applications Siebel Cloud Manager (gRPC) HTTP/2 Yes 9.1 Network Low None None Un-
changed
High High None 22.3-26.5  
CVE-2026-24400 Siebel CRM Deployment Server Infrastructure (jackson-core) HTTP Yes 9.1 Network Low None None Un-
changed
High None High 17.0-26.4  
CVE-2026-22732 Siebel CRM Development Siebel Approval Manager (Spring Security) HTTP Yes 9.1 Network Low None None Un-
changed
High High None 17.0-26.5  
CVE-2026-24400 Siebel CRM Integration REST (jackson-core) HTTP Yes 9.1 Network Low None None Un-
changed
High None High 17.0-26.5  
CVE-2025-67030 Siebel CRM Integration Open Integration (Plexus Utils) HTTP Yes 8.8 Network Low None Required Un-
changed
High High High 25.12-26.5  
CVE-2026-35204 Siebel CRM Cloud Applications Siebel Cloud Manager (Helm) None No 8.6 Local Low None Required Changed High High High 22.3-26.4  
CVE-2025-59250 Siebel CRM Administration Data Archival (JDBC Driver for SQL Server) SQL Yes 8.1 Network Low None Required Un-
changed
High High None 17.0-26.5  
CVE-2026-60690 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 7.7 Network Low Low None Changed High None None 22.3-26.5  
CVE-2026-24734 Siebel Apps - Marketing Marketing (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 17.0-26.5  
CVE-2026-60689 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 22.3-26.5  
CVE-2026-60704 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 7.5 Network Low None None Un-
changed
High None None 22.3-26.5  
CVE-2025-9624 Siebel CRM Cloud Applications Siebel Cloud Manager (OpenSearch) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 22.3-26.5  
CVE-2021-3283 Siebel CRM Cloud Applications Siebel Cloud Manager (Traefik) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 22.3-26.5  
CVE-2026-47018 Siebel CRM Cloud Applications Siebel Cloud Manager HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 22.3-26.5  
CVE-2026-24308 Siebel CRM Deployment Server Infrastructure (Apache ZooKeeper) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 17.0-26.5  
CVE-2026-34478 Siebel CRM Development Siebel Approval Manager (Apache Log4j) SYSLOG Yes 7.5 Network Low None None Un-
changed
None High None 17.0-26.5  
CVE-2026-1605 Siebel CRM End User Desktop Integration Siebel Agent (Eclipse Jetty) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 17.0-26.5  
CVE-2025-67721 Siebel CRM Integration Open Integration (Aircompressor) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 25.12-26.5  
CVE-2026-34478 Siebel CRM Integration EAI (Apache Log4j) SYSLOG Yes 7.5 Network Low None None Un-
changed
None High None 17.0-26.5  
CVE-2025-5222 Siebel CRM Deployment Server Infrastructure (ICU) None No 7.4 Local High None None Un-
changed
High High High 17.0-26.4  
CVE-2025-12383 Siebel CRM Integration REST (Eclipse Jersey) HTTPS Yes 7.4 Network High None None Un-
changed
High High None 17.0-26.5  
CVE-2026-26960 Siebel CRM End User Open UI (React) None No 7.1 Local Low None Required Un-
changed
High High None 17.0-26.5  
CVE-2026-60705 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 7.0 Network High None None Un-
changed
High Low Low 22.3-26.5  
CVE-2026-24051 Siebel CRM Cloud Applications Siebel Cloud Manager (OpenTelemetry-Go) None No 7.0 Local High Low None Un-
changed
High High High 22.3-26.5  
CVE-2026-26007 Siebel CRM Cloud Applications Siebel Cloud Manager (Cryptography) HTTP Yes 6.5 Network Low None Required Un-
changed
High None None 22.3-26.4  
CVE-2026-60712 Siebel CRM Cloud Applications Siebel Cloud Manager None No 6.5 Local Low Low None Changed High None None 22.3-26.5  
CVE-2026-34500 Siebel CRM Integration EAI (Apache Tomcat) HTTPS Yes 6.5 Network High None None Un-
changed
High Low None 17.0-26.5  
CVE-2026-40179 Siebel CRM Cloud Applications Siebel Cloud Manager (Prometheus) HTTP Yes 6.1 Network Low None Required Changed Low Low None 22.3-26.4  
CVE-2025-26791 Siebel CRM End User User Interface (DOMPurify) HTTP Yes 6.1 Network Low None Required Changed Low Low None 17.0-26.5  
CVE-2026-22737 Siebel CRM Development Siebel Approval Manager (Spring Framework) HTTP Yes 5.9 Network High None None Un-
changed
High None None 17.0-26.5  
CVE-2025-13837 Siebel CRM Cloud Applications Siebel Cloud Manager (Python) None No 5.5 Local Low None Required Un-
changed
None None High 22.3-26.4  
CVE-2023-40577 Siebel CRM Cloud Applications Siebel Cloud Manager (Alertmanager) HTTP No 5.4 Network Low Low Required Changed Low Low None 22.3-26.5  
CVE-2025-68480 Siebel CRM Cloud Applications Siebel Cloud Manager (Marshmallow) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 22.3-26.4  
CVE-2024-39908 Siebel CRM Cloud Applications Siebel Cloud Manager (REXML) HTTP Yes 5.3 Network Low None None Un-
changed
None None Low 22.3-26.4  
CVE-2026-60713 Siebel CRM Cloud Applications Siebel Cloud Manager None No 4.4 Local Low Low None Un-
changed
Low Low None 22.3-26.5  
CVE-2026-27205 Siebel CRM Cloud Applications Siebel Cloud Manager (Flask) HTTP Yes 4.3 Network Low None Required Un-
changed
Low None None 22.3-26.4  
CVE-2026-60709 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 4.2 Adjacent
Network
High None None Un-
changed
Low Low None 22.3-26.5  
CVE-2026-60357 Siebel CRM Integration Siebel Server Sync for Exchange HTTP Yes 3.7 Network High None None Un-
changed
None Low None 17.0-26.5  
CVE-2026-47011 Siebel CRM Deployment Application Interface HTTP No 2.6 Network High Low Required Un-
changed
Low None None 17.0-26.4  
CVE-2026-47032 Siebel CRM End User Redwood UI HTTP No 2.6 Network High High Required Changed None None Low 24.4-26.3  
CVE-2026-47016 Siebel CRM Integration Event Publish and Subscribe None No 1.9 Physical High High None Changed Low None None 17.0-26.4  

Additional CVEs addressed are:

  • The patch for CVE-2026-34500 also addresses CVE-2025-66614, CVE-2026-25854, CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34487.
  • The patch for CVE-2026-24308 also addresses CVE-2022-3171, CVE-2023-35116, CVE-2024-6763, CVE-2024-7254, CVE-2025-12183, CVE-2025-58057, CVE-2025-66566, CVE-2025-8916, and CVE-2026-24281.
  • The patch for CVE-2026-26960 also addresses CVE-2025-11953, CVE-2025-29088, CVE-2025-58767, CVE-2025-6965, and CVE-2026-24842.
  • The patch for CVE-2026-34520 also addresses CVE-2026-22815, CVE-2026-34513, CVE-2026-34514, CVE-2026-34515, CVE-2026-34516, CVE-2026-34517, CVE-2026-34518, CVE-2026-34519, and CVE-2026-34525.
  • The patch for CVE-2025-26791 also addresses CVE-2024-45801, CVE-2024-47875, and CVE-2024-48910.

 

Oracle Supply Chain Risk Matrix

This Critical Patch Update contains 39 new security patches for Oracle Supply Chain.  16 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-61041 Oracle Demantra Demand Management Product Security HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-61167 Oracle Agile PLM Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.3.6  
CVE-2026-61183 Oracle Agile Product Lifecycle Management for Process Reporting HTTP Yes 9.8 Network Low None None Un-
changed
High High High 6.2.4  
CVE-2026-61178 Oracle Agile Product Lifecycle Management for Process Installation TCP Yes 9.8 Network Low None None Un-
changed
High High High 6.2.4  
CVE-2026-61186 Oracle Agile Engineering Data Management Install HTTP Yes 9.4 Network Low None None Un-
changed
Low High High 6.2.1  
CVE-2026-61175 Oracle Product Lifecycle Analytics Installation Issues HTTP Yes 9.3 Network Low None None Changed High None Low 3.6.1  
CVE-2026-61171 Oracle Agile PLM Security HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.3.6  
CVE-2026-61184 Oracle Agile Product Lifecycle Management for Process Product Quality Management HTTP Yes 9.1 Network Low None None Un-
changed
High High None 6.2.4  
CVE-2026-61174 Oracle Product Lifecycle Analytics Installation Issues None No 9.0 Local Low None None Changed High High None 3.6.1  
CVE-2026-61168 Oracle Agile PLM Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.3.6  
CVE-2026-61166 Oracle Agile PLM User and User Group HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.3.6  
CVE-2026-61179 Oracle Agile Product Lifecycle Management for Process Product Quality Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 6.2.4  
CVE-2026-61180 Oracle Agile Product Lifecycle Management for Process Product Quality Management HTTP No 8.8 Network Low Low None Un-
changed
High High High 6.2.4  
CVE-2026-62516 Oracle Demantra Demand Management Product Security SQL No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-60583 Oracle Transportation Management Install HTTP No 8.8 Network Low Low None Un-
changed
High High High 6.5.3  
CVE-2026-61170 Oracle Agile PLM Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 9.3.6  
CVE-2026-61181 Oracle Agile Product Lifecycle Management for Process Product Quality Management HTTP No 7.6 Network Low Low Required Changed High Low None 6.2.4  
CVE-2026-60584 Oracle Transportation Management CSV Management HTTP No 7.6 Network Low Low None Un-
changed
High Low Low 6.5.3  
CVE-2026-34487 Oracle Agile PLM Folders, Files & Attachments (Apache Tomcat) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.3.6  
CVE-2026-61172 Oracle Agile PLM Security HTTP Yes 7.5 Network Low None None Un-
changed
High None None 9.3.6  
CVE-2026-61188 Oracle Agile Product Lifecycle Management for Process Installation HTTP No 7.5 Network High Low None Un-
changed
High High High 6.2.4  
CVE-2026-34481 Oracle Product Lifecycle Analytics Installation Issues (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 3.6.1  
CVE-2026-61173 Oracle Agile PLM Security HTTP Yes 7.4 Network High None None Un-
changed
High High None 9.3.6  
CVE-2026-61185 Oracle Agile Product Lifecycle Management for Process Installation HTTP Yes 7.4 Adjacent
Network
Low None None Changed High None None 6.2.4  
CVE-2026-61182 Oracle Agile Product Lifecycle Management for Process Data Import None No 6.7 Local Low High None Un-
changed
High High High 6.2.4  
CVE-2026-61176 Oracle Product Lifecycle Analytics Installation Issues HTTP No 6.7 Network Low High None Un-
changed
High High Low 3.6.1  
CVE-2026-61189 Oracle Agile Engineering Data Management Install None No 6.5 Local Low Low None Changed High None None 6.2.1  
CVE-2026-61194 Oracle Agile Engineering Data Management Core TCP No 6.5 Network Low Low None Un-
changed
None None High 6.2.1  
CVE-2026-61195 Oracle Agile Engineering Data Management Core TCP No 6.5 Network Low Low None Un-
changed
None None High 6.2.1  
CVE-2026-47009 Oracle Agile PLM Folders, Files & Attachments HTTP Yes 6.5 Network Low None Required Un-
changed
High None None 9.3.6  
CVE-2026-61169 Oracle Agile PLM Security None No 6.5 Local Low Low None Changed High None None 9.3.6  
CVE-2026-60433 Oracle Transportation Management Integration HTTP No 6.5 Network Low High None Un-
changed
High High None 6.5.3  
CVE-2026-61190 Oracle Agile Engineering Data Management Install HTTP No 6.4 Network High Low Required Un-
changed
High High None 6.2.1  
CVE-2026-61192 Oracle Agile Engineering Data Management Install HTTP No 5.3 Network High Low None Un-
changed
None None High 6.2.1  
CVE-2025-68161 Oracle Agile PLM Security (Apache Log4j) TCP Yes 4.8 Network High None None Un-
changed
Low Low None 9.3.6  
CVE-2025-68161 Oracle Agile PLM MCAD Connector CAX Client (Apache Log4j) TCP Yes 4.8 Network High None None Un-
changed
Low Low None 3.6  
CVE-2026-61191 Oracle Agile Engineering Data Management Document Management None No 4.4 Local Low Low None Un-
changed
None Low Low 6.2.1  
CVE-2026-60434 Oracle Transportation Management Authentication HTTP No 4.3 Network Low Low None Un-
changed
Low None None 6.5.3  
CVE-2026-61187 Oracle Agile Engineering Data Management Install None No 2.8 Local Low Low Required Un-
changed
None None Low 6.2.1  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-34487 also addresses CVE-2026-34483, CVE-2026-34486, and CVE-2026-34500.

 

Oracle Systems Risk Matrix

This Critical Patch Update contains 6 new security patches for Oracle Systems.  None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-60661 Oracle Solaris Filesystems None No 7.8 Local High Low None Changed High High High 11.4  
CVE-2026-61202 Oracle Solaris Utility None No 7.5 Local High Low None Changed High High None 11.3, 11.4  
CVE-2026-60659 Oracle Solaris Filesystems None No 7.1 Local Low Low None Un-
changed
None High High 11.4  
CVE-2026-60834 Oracle Solaris Utility RAD No 7.1 Network High Low None Changed High Low None 11.4  
CVE-2026-60833 Oracle Solaris Utility None No 7.0 Local High Low None Un-
changed
High High High 11.4  
CVE-2026-61052 Oracle Solaris Filesystems None No 5.5 Local Low Low None Un-
changed
None None High 11.4  

 

Oracle Utilities Applications Risk Matrix

This Critical Patch Update contains 14 new security patches for Oracle Utilities Applications.  10 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-4800 Oracle Utilities Testing Accelerator Tools (Lodash) HTTP Yes 9.8 Network Low None None Un-
changed
High High High 7.0.0.0.8, 7.0.0.1.7, 25.4.0.0.3  
CVE-2025-58050 Oracle Utilities Network Management System Third Party (PCRE2) HTTP Yes 9.1 Network Low None None Un-
changed
High None High 2.6.0.1.0-2.6.0.1.11, 2.6.0.2.0-2.6.0.2.7  
CVE-2026-41855 Oracle Utilities Testing Accelerator Tools (Spring Framework) HTTP Yes 8.1 Network High None None Un-
changed
High High High 7.0.0.0.8, 7.0.0.1.7, 25.4.0.0.3  
CVE-2026-22747 Oracle Utilities Testing Accelerator Tools (Spring Security) HTTPS No 8.1 Network Low Low None Un-
changed
High High None 7.0.0.0.8, 7.0.0.1.7, 25.4.0.0.3  
CVE-2026-34481 Oracle Utilities Application Framework Security (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10, 26.4  
CVE-2026-29062 Oracle Utilities Application Framework Third Party (jackson-core) HTTP Yes 7.5 Network Low None None Un-
changed
None None High 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10, 26.4  
CVE-2026-3505 Oracle Utilities Application Framework Security (Bouncy Castle Java Library) HTTPS Yes 7.5 Network Low None None Un-
changed
None None High 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10, 26.4  
CVE-2026-24308 Oracle Utilities Network Management System NMS Monitor (Apache ZooKeeper) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.11  
CVE-2026-34481 Oracle Utilities Testing Accelerator Tools (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 7.0.0.0.8, 7.0.0.1.7, 25.4.0.0.3  
CVE-2026-46981 Oracle Utilities Network Management System Mobile HTTP Yes 7.2 Network Low None None Changed Low Low None 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.2  
CVE-2026-21441 Oracle Utilities Network Management System Third Party (urllib3) HTTP No 6.5 Network Low Low None Un-
changed
None None High 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.11, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.1  
CVE-2026-0540 Oracle Utilities Application Framework Security (DOMPurify) HTTP Yes 6.1 Network Low None Required Changed Low Low None 4.3.0.5.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0-4.4.0.4.0, 4.5.0.0.0-4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4, 25.10, 26.4  
CVE-2026-46948 Oracle Utilities Network Management System Security HTTP No 4.6 Network Low Low Required Un-
changed
Low Low None 2.4.0.1.0-2.4.0.1.32, 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.2.0-2.6.0.2.7, 25.12.0.0.0  
CVE-2026-46980 Oracle Utilities Network Management System Mobile HTTP No 4.3 Network Low Low None Un-
changed
Low None None 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, 25.12.0.0.0-25.12.0.0.2  

Additional CVEs addressed are:

  • The patch for CVE-2026-22747 also addresses CVE-2026-22748, CVE-2026-22751, CVE-2026-22753, and CVE-2026-22754.
  • The patch for CVE-2026-41855 also addresses CVE-2026-40976, CVE-2026-41838, CVE-2026-41839, CVE-2026-41840, CVE-2026-41841, CVE-2026-41842, CVE-2026-41843, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-41848, CVE-2026-41850, CVE-2026-41851, CVE-2026-41852, CVE-2026-41853, and CVE-2026-41854.
  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.
  • The patch for CVE-2026-0540 also addresses CVE-2025-15599.
  • The patch for CVE-2026-29062 also addresses CVE-2026-54512.
  • The patch for CVE-2026-4800 also addresses CVE-2026-2950.
  • The patch for CVE-2026-24308 also addresses CVE-2026-24281.

 

Oracle Virtualization Risk Matrix

This Critical Patch Update contains 16 new security patches for Oracle Virtualization.  None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-47047 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.12  
CVE-2026-47054 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.12 See Note 1
CVE-2026-60150 Oracle VM VirtualBox Core None No 7.8 Local Low Low None Un-
changed
High High High 7.2.12  
CVE-2026-60155 Oracle VM VirtualBox Core None No 7.5 Local High High None Changed High High High 7.2.12  
CVE-2026-60159 Oracle VM VirtualBox Core None No 7.5 Local High High None Changed High High High 7.2.12  
CVE-2026-47050 Oracle VM VirtualBox Core None No 7.4 Local Low High Required Changed None High High 7.2.8  
CVE-2026-60158 Oracle VM VirtualBox Core None No 6.4 Local High Low None Changed None High Low 7.2.12  
CVE-2026-60161 Oracle VM VirtualBox Core None No 6.1 Local Low None Required Un-
changed
None Low High 7.2.12  
CVE-2026-60162 Oracle VM VirtualBox Core None No 6.1 Local High High None Changed High None Low 7.2.12  
CVE-2026-47041 Oracle VM VirtualBox Core None No 6.0 Local Low High None Changed None None High 7.2.12  
CVE-2026-47053 Oracle VM VirtualBox Core None No 5.6 Local Low Low Required Un-
changed
None High Low 7.2.12  
CVE-2026-47044 Oracle VM VirtualBox Core None No 5.5 Local Low Low None Un-
changed
None None High 7.2.12  
CVE-2026-47062 Oracle VM VirtualBox Core None No 5.5 Local Low Low None Un-
changed
None None High 7.2.12  
CVE-2026-47043 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed Low None None 7.2.12  
CVE-2026-47055 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed None Low None 7.2.12  
CVE-2026-60160 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed Low None None 7.2.12  

Notes:

  1. This vulnerability applies to Windows host only.