Oracle Critical Security Patch Update Advisory - June 2026

Description

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. Prior Critical Patch Update and Critical Security Patch Update advisories should be reviewed for information regarding earlier published security patches. Refer to Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins for information about Oracle Security advisories.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay.

This Critical Security Patch Update contains 245 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at June 2026 Critical Security Patch Update: Executive Summary and Analysis.

Please note that since the release of the May 2026 Critical Security Patch Update, Oracle has released a Security Alert for Oracle PeopleSoft PeopleTools, CVE-2026-35273 (June 10, 2026). Customers are strongly advised to apply the June 2026 Critical Security Patch Update for Oracle PeopleSoft PeopleTools and Oracle PeopleSoft Enterprise Applications, which includes patches for this Alert as well as additional patches.

Affected Products and Patch Information

Security vulnerabilities addressed by this Critical Security Patch Update affect the products listed below.

Please click on the links in the Patch Availability Document column below to access the documentation for patch availability information and installation instructions.

Affected Products and Versions Patch Availability Document
APM - Application Performance Management, versions 13.5, 24.1 Oracle Enterprise Manager
Identity Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Identity Manager Connector, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
JD Edwards EnterpriseOne Accounts Payable, version 9.2 JD Edwards
JD Edwards EnterpriseOne General Ledger, version 9.2 JD Edwards
JD Edwards EnterpriseOne Human Resources Management, version 9.2 JD Edwards
JD Edwards EnterpriseOne Order Promising, version 9.2 JD Edwards
JD Edwards EnterpriseOne Project Costing, version 9.2 JD Edwards
JD Edwards EnterpriseOne Tools, versions 9.2.0.0-9.2.26.2 JD Edwards
MySQL Cluster, versions 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0 MySQL
MySQL NDB Cluster, versions 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0 MySQL
MySQL Router, versions 8.4.0-8.4.9, 9.0.0-9.7.0 MySQL
MySQL Server, versions 8.4.0-8.4.9, 9.0.0-9.7.0 MySQL
MySQL Shell, versions 8.4.0-8.4.9, 9.0.0-9.7.0, 2026.2.0+9.6.1 MySQL
Oracle Access Manager, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Agile PLM, version 9.3.6 Oracle Supply Chain Products
Oracle Application Development Framework (ADF), versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware
Oracle Communications Convergent Charging Controller, versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0 Oracle Communications Convergent Charging Controller
Oracle Communications Network Charging and Control, versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0 Oracle Communications Network Charging and Control
Oracle Communications Network Integrity, versions 7.3.6, 7.4.0, 7.5.0, 8.0.0 Oracle Communications Network Integrity
Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle E-Business Suite, versions 12.2.3-12.2.15, V15, V16 Oracle E-Business Suite
Oracle Enterprise Manager Base Platform, versions 13.5, 24.1 Oracle Enterprise Manager
Oracle Solaris, version 11.4 Systems
Oracle Unified Directory, versions 12.2.1.4.0, 14.1.2.1.0 Fusion Middleware
Oracle Virtual Directory, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle VM VirtualBox, version 7.2.8 Virtualization
Oracle WebCenter Content, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Portal, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
PeopleSoft Enterprise CS Campus Community, version 9.2.38 PeopleSoft
PeopleSoft Enterprise CS Student Financials, version 9.2.38 PeopleSoft
PeopleSoft Enterprise PT PeopleTools, versions 8.61, 8.62 PeopleSoft
Siebel Applications, versions 17.0-26.5 Siebel
WebCenter Content: Imaging, versions 12.2.1.4.0, 14.1.2.0.0 Fusion Middleware
WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 Fusion Middleware

Risk Matrix Content

Risk matrices list only security vulnerabilities that are newly addressed by the patches associated with this advisory. Risk matrices for previous security patches can be found in previous Critical Patch Update advisories, Critical Security Patch Update advisories and Alerts. An English text version of the risk matrices provided in this document is here.

Several vulnerabilities addressed in this Critical Security Patch Update affect multiple products. Each vulnerability is identified by a CVE ID. A vulnerability that affects multiple products will appear with the same CVE ID in all risk matrices.

Security vulnerabilities are scored using CVSS version 3.1 (see Oracle CVSS Scoring for an explanation of how Oracle applies CVSS version 3.1).

Oracle conducts an analysis of each security vulnerability addressed by a Critical Security Patch Update. Oracle does not disclose detailed information about this security analysis to customers, but the resulting Risk Matrix and associated documentation provide information about conditions required to exploit the vulnerability and the potential impact of a successful exploit. Oracle provides this information so that customers may conduct their own risk analysis based on the particulars of their product usage. For more information, see Oracle vulnerability disclosure policies.

Third party component vulnerabilities that are deemed not exploitable in the context of their inclusion in an Oracle product are listed, with VEX justifications, below the respective Oracle product's risk matrix.

The protocol in the risk matrix implies that all of its secure variants are affected as well. For example, if HTTP is listed as an affected protocol, it implies that HTTPS is also affected. The secure variant of a protocol is listed in the risk matrix only if it is the only variant affected.

Workarounds

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Security Patch Update security patches as soon as possible. Until you apply the Critical Security Patch Update patches, it may be possible to reduce the risk of successful attack by blocking network protocols required by an attack. For attacks that require certain privileges or access to certain packages, removing the privileges or the ability to access the packages from users that do not need the privileges may help reduce the risk of successful attack. Both approaches may break application functionality, so Oracle strongly recommends that customers test changes on non-production systems. Neither approach should be considered a long-term solution as neither corrects the underlying problem.

Skipped Security Patch Updates

Oracle strongly recommends that customers apply security patches as soon as possible. For customers that have skipped one or more security patches and are concerned about products that do not have security patches announced in this Critical Security Patch Update, please review previous Critical Patch Update and Critical Security Patch Update advisories to determine appropriate actions.

Critical Security Patch Update Supported Products and Versions

Patches released through the Critical Security Patch Update program are provided only for product versions that are covered under the Premier Support or Extended Support phases of the Lifetime Support Policy. Oracle recommends that customers plan product upgrades to ensure that patches released through the Critical Security Patch Update program are available for the versions they are currently running.

Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update. However, it is likely that earlier versions of affected releases are also affected by these vulnerabilities. As a result, Oracle recommends that customers upgrade to supported versions.

Credit Statement

The following people or organizations reported security vulnerabilities addressed by this Critical Security Patch Update to Oracle:

  • 4ra1n, pyn3rd and unam4: CVE-2026-46863
  • Adam Kues of Assetnote Security Research Team: CVE-2026-35261
  • Andrea Carlo Maria Dattola of TIM Security Red Team Research: CVE-2026-35258
  • Asim Viladi Oglu Manizada: CVE-2026-46862
  • Dhiraj Mishra: CVE-2026-46974
  • Diego Palacios: CVE-2026-35275
  • Dylan Pindur of Assetnote Security Research Team: CVE-2026-35261
  • Ilyass El Hadi of Armadin: CVE-2026-46859
  • Khanh Vi: CVE-2026-46874
  • Marco Ventura of TIM Security Red Team Research: CVE-2026-35258
  • Massimiliano Brolli of TIM Security Red Team Research: CVE-2026-35258
  • Shubham Shah of Assetnote Security Research Team: CVE-2026-35261
  • vmpr0be: CVE-2026-46977
  • Weiheng Qiu of Vanderbilt University: CVE-2026-46860
  • Xiaobye of DEVCORE Research Team working with TrendAI Zero Day Initiative: CVE-2026-46873
  • Yuhao Jiang: CVE-2026-46768, CVE-2026-46815, CVE-2026-46816, CVE-2026-46825, CVE-2026-46877

Security-In-Depth Contributors

Oracle acknowledges people who have contributed to our Security-In-Depth program (see FAQ). People are acknowledged for Security-In-Depth contributions if they provide information, observations or suggestions pertaining to security vulnerability issues that result in significant modification of Oracle code or documentation in future releases, but are not of such a critical nature that they are distributed in Critical Security Patch Updates.

In this Critical Security Patch Update, Oracle recognizes the following for contributions to Oracle's Security-In-Depth program:

  • Scott (WebbinRoot) of NetSPI

Upcoming Security Release Dates

Security patches are released on the third Tuesday of each month, except the initial May CSPU release. The next four dates are:

  • 21 July 2026 (CPU)
  • 18 August 2026 (CSPU)
  • 15 September 2026 (CSPU)
  • 20 October 2026 (CPU)

References

 

Modification History

Date Note
2026-June-16 Rev 1. Initial Release.

 


 

Oracle Communications Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Communications.  All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2025-70873 Oracle Communications Convergent Charging Controller Common fns (SQLite) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2025-70873 Oracle Communications Network Charging and Control Common fns (SQLite) HTTP Yes 7.5 Network Low None None Un-
changed
High None None 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, 15.2.0.0.0  
CVE-2026-34481 Oracle Communications Network Integrity Other (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 7.3.6, 7.4.0, 7.5.0, 8.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2025-68161, CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle E-Business Suite Risk Matrix

This Critical Security Patch Update contains 55 new security patches for Oracle E-Business Suite.  6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

Oracle E-Business Suite products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle E-Business Suite products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle E-Business Suite risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle E-Business Suite products, Oracle recommends that customers apply the June 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Oracle E-Business Suite. For information on what patches need to be applied to your environments, refer to Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document (June 2026), My Oracle Support Note KA923.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46933 Oracle Applications Manager Internal Operations HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-46895 Oracle Enterprise Command Center Framework Core HTTP No 9.9 Network Low Low None Changed High High High V15, V16  
CVE-2026-46897 Oracle Enterprise Command Center Framework Core HTTP No 9.9 Network Low Low None Changed High High Low V15, V16  
CVE-2026-46901 Oracle Enterprise Command Center Framework Core HTTP No 9.9 Network Low Low None Changed High High Low V15, V16  
CVE-2026-46900 Oracle Enterprise Command Center Framework Core HTTPS No 9.9 Network Low Low None Changed High High High V15, V16  
CVE-2026-46918 Oracle Process Manufacturing Product Development Internal Operations HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-46963 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-46964 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 9.9 Network Low Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-46902 Oracle Enterprise Command Center Framework Core HTTPS Yes 9.8 Network Low None None Un-
changed
High High High V15, V16  
CVE-2026-46899 Oracle Enterprise Command Center Framework Core HTTP No 9.6 Network Low Low None Changed High High None V15, V16  
CVE-2026-46949 Oracle Advanced Outbound Telephony Internal Operations HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-46896 Oracle Enterprise Command Center Framework Core HTTP No 9.1 Network Low High None Changed High High High V15, V16  
CVE-2026-46930 Oracle In-Memory Cost Management for Discrete Industries Internal Operations HTTPS Yes 9.1 Network Low None None Un-
changed
High High None 12.2.12-12.2.15  
CVE-2026-46944 Oracle iSupport Internal Operations HTTP No 9.1 Network Low High None Changed High High High 12.2.3-12.2.15  
CVE-2026-46945 Oracle iSupport Internal Operations HTTP No 9.1 Network Low High None Changed High High High 12.2.3-12.2.15  
CVE-2026-46946 Oracle iSupport Internal Operations HTTP No 9.1 Network Low High None Changed High High High 12.2.3-12.2.15  
CVE-2026-46947 Oracle Advanced Outbound Telephony Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46950 Oracle Advanced Outbound Telephony Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46929 Oracle Cost Management Cost Planning HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46940 Oracle Cost Management Cost Planning HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46931 Oracle Enterprise Asset Management Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.6-12.2.15  
CVE-2026-46937 Oracle iSetup General Ledger Update Transform, Reports HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46972 Oracle Outsourced Mfg for Discrete Industries Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46973 Oracle Outsourced Mfg for Discrete Industries Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46942 Oracle Process Manufacturing Process Planning Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46916 Oracle Process Manufacturing Product Development Quality Management Specs HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46961 Oracle Project Portfolio Analysis Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46962 Oracle Project Portfolio Analysis Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46967 Oracle Public Sector Financials (International) Authorization HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46951 Oracle Quality Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46952 Oracle Quality Internal Operations HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46928 Oracle Spares Management Internal Operations HTTPS No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46965 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46915 Oracle Complex Maintenance, Repair and Overhaul Production HTTP No 8.5 Network High Low None Changed High High High 12.2.3-12.2.15  
CVE-2026-46939 Oracle Configure to Order Supply to Order Workbench HTTP No 8.1 Network Low Low None Un-
changed
High High None 12.2.3-12.2.15  
CVE-2026-46898 Oracle Enterprise Command Center Framework Core HTTPS Yes 8.1 Network Low None Required Un-
changed
High High None V15, V16  
CVE-2026-46927 Oracle Receivables Internal Operations SOAP Yes 8.1 Network High None None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46894 Oracle iSupplier Portal Home Page HTTPS No 8.0 Network Low Low Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46934 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46935 Oracle Complex Maintenance, Repair and Overhaul Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46971 Oracle HR Intelligence Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46955 Oracle Human Resources Person HTTP Yes 7.5 Network High None Required Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46957 Oracle iSupplier Portal Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46958 Oracle Subledger Accounting Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46959 Oracle Subledger Accounting Internal Operations HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46966 Oracle Universal Work Queue Work Provider Site Level Administration HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46938 Oracle Cost Management Cost Planning HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46969 Oracle Financials for EMEA Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46922 Oracle HR Intelligence Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46970 Oracle HR Intelligence Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46953 Oracle HRMS (UK) UK Payroll HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46960 Oracle Project Portfolio Analysis Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46956 Oracle Property Manager Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46976 Oracle Public Sector Payroll Internal Operations HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.3-12.2.15  
CVE-2026-46932 Oracle Enterprise Asset Management Internal Operations HTTP No 7.1 Network Low Low None Un-
changed
High None Low 12.2.3-12.2.15  

 

Oracle Enterprise Manager Risk Matrix

This Critical Security Patch Update contains 16 new security patches for Oracle Enterprise Manager.  6 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  None of these patches are applicable to client-only installations, i.e., installations that do not have Oracle Enterprise Manager installed. The English text form of this Risk Matrix can be found here.

Oracle Enterprise Manager products include Oracle Database and Oracle Fusion Middleware components that are affected by the vulnerabilities listed in the Oracle Database and Oracle Fusion Middleware sections. The exposure of Oracle Enterprise Manager products is dependent on the Oracle Database and Oracle Fusion Middleware versions being used. Oracle Database and Oracle Fusion Middleware security updates are not listed in the Oracle Enterprise Manager risk matrix. However, since vulnerabilities affecting Oracle Database and Oracle Fusion Middleware versions may affect Oracle Enterprise Manager products, Oracle recommends that customers apply the June 2026 Critical Security Patch Update to the Oracle Database and Oracle Fusion Middleware components of Enterprise Manager. For information on what patches need to be applied to your environments, refer to Critical Security Patch Update June 2026 Patch Availability Document for Oracle Products, My Oracle Support Note CPU175.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46854 Oracle Enterprise Manager Base Platform Target Management HTTP No 9.9 Network Low Low None Changed High High High 13.5, 24.1  
CVE-2026-46832 Oracle Enterprise Manager Base Platform Discovery Framework HTTPS No 9.9 Network Low Low None Changed High High High 13.5, 24.1  
CVE-2026-46852 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS No 9.9 Network Low Low None Changed High High High 13.5, 24.1  
CVE-2026-46855 Oracle Enterprise Manager Base Platform Metadata Plugin HTTPS No 9.9 Network Low Low None Changed High High High 13.5, 24.1  
CVE-2026-46857 Oracle Enterprise Manager Base Platform Oracle Management Service HTTP Yes 9.8 Network Low None None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46853 Oracle Enterprise Manager Base Platform Metadata Plugin HTTP Yes 9.6 Network Low None Required Changed High High High 13.5, 24.1  
CVE-2026-46856 Oracle Enterprise Manager Base Platform Metadata Plugin HTTP Yes 9.6 Network Low None Required Changed High High High 13.5, 24.1  
CVE-2026-46858 APM - Application Performance Management JADM, JVM Diagnostics HTTP Yes 9.1 Network Low None None Un-
changed
None High High 13.5, 24.1  
CVE-2026-46875 Oracle Enterprise Manager Base Platform Deployment Library HTTPS No 9.1 Network Low High None Changed High High High 13.5, 24.1  
CVE-2026-46872 Oracle Enterprise Manager Base Platform Install HTTPS No 9.0 Network Low High None Changed Low High High 13.5, 24.1  
CVE-2026-46864 Oracle Enterprise Manager Base Platform Agent Next Gen SSH No 8.8 Network Low Low None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46866 Oracle Enterprise Manager Base Platform Agent Next Gen HTTPS Yes 8.2 Network Low None None Un-
changed
None Low High 13.5, 24.1  
CVE-2026-46865 Oracle Enterprise Manager Base Platform Extensibility Framework None No 8.2 Local Low High None Changed High High High 13.5, 24.1  
CVE-2026-34481 Oracle Enterprise Manager Base Platform Agent Next Gen (Apache Log4j) HTTP Yes 7.5 Network Low None None Un-
changed
None High None 13.5, 24.1  
CVE-2026-46867 Oracle Enterprise Manager Base Platform Extensibility Framework HTTPS No 7.2 Network Low High None Un-
changed
High High High 13.5, 24.1  
CVE-2026-46868 Oracle Enterprise Manager Base Platform Extensibility Framework HTTPS No 7.2 Network Low High None Un-
changed
High High High 13.5, 24.1  

Additional CVEs addressed are:

  • The patch for CVE-2026-34481 also addresses CVE-2026-34477, CVE-2026-34478, CVE-2026-34479, and CVE-2026-34480.

 

Oracle Fusion Middleware Risk Matrix

This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware.  53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

To get the full list of current and previously released Critical Security Patch Update and Critical Patch Update patches for Oracle Fusion Middleware products, refer to My Oracle Support Doc ID KA1182.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-35308 Oracle Coherence Centralized Third Party Jars HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35307 Oracle Coherence Core HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46778 Oracle WebCenter Enterprise Capture Client Bundle RMI Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46781 Oracle WebCenter Enterprise Capture Client Bundle RMI Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46803 Oracle WebCenter Portal Security Framework HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46846 Oracle WebCenter Portal Security Framework HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46798 Oracle WebCenter Sites WebCenter Sites HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46800 Oracle WebCenter Sites WebCenter Sites HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35301 WebLogic Server Console HTTP Yes 10.0 Network Low None None Changed High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-35292 WebLogic Server Console HTTP Yes 10.0 Network Low None None Changed High High High 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35268 Identity Manager Core T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46793 Identity Manager Connector Database User HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46792 Identity Manager Connector Generic Unix Connector HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35294 Identity Manager Connector Mainframe Connectors HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46794 Identity Manager Connector Generic Unix Connector SSH No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35313 Oracle Access Manager Authentication Engine HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35316 Oracle WebCenter Content Content Server HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35321 Oracle WebCenter Content Content Server HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35323 Oracle WebCenter Content Content Server HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46782 Oracle WebCenter Enterprise Capture Client Bundle HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46779 Oracle WebCenter Enterprise Capture Client Bundle T3 No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35280 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35281 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35282 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35283 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35284 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35285 Oracle WebCenter Enterprise Capture Client Bundle T3, IIOP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46765 Oracle WebCenter Portal Composer HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46767 Oracle WebCenter Portal Composer HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46814 Oracle WebCenter Portal Security Framework HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46802 Oracle WebCenter Portal Security Framework HTTP No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46847 Oracle WebCenter Portal Runtime Tools HTTPS No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46838 Oracle WebCenter Portal Security Framework HTTPS No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46844 Oracle WebCenter Portal Security Framework HTTPS No 9.9 Network Low Low None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35263 WebLogic Server Core HTTP No 9.9 Network Low Low None Changed High High High 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46807 Identity Manager OIM Legacy UI T3, IIOP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35309 Oracle Coherence Centralized Third Party Jars HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35310 Oracle Coherence Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35304 Oracle Coherence Core HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46773 Oracle Unified Directory OUD Core LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46774 Oracle Unified Directory OUD Core RMI Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35312 Oracle Virtual Directory Virtual Directory Server LDAP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35319 Oracle WebCenter Content Content Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46766 Oracle WebCenter Content Content Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35286 Oracle WebCenter Content Content Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46813 Oracle WebCenter Content Content Server HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46845 Oracle WebCenter Portal Security Framework HTTPS Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35293 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 14.1.2.0.0  
CVE-2026-46797 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35296 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46799 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46801 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46783 WebCenter Content: Imaging Core HTTP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35300 WebLogic Server Core TCP Yes 9.8 Network Low None None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46786 Oracle WebCenter Content Content Server HTTP Yes 9.6 Network Low None Required Changed High High High 14.1.2.0.0  
CVE-2026-46789 Oracle WebCenter Content Content Server HTTP Yes 9.6 Network Low None Required Changed High High High 14.1.2.0.0  
CVE-2026-35305 Oracle Coherence Centralized Third Party Jars HTTP Yes 9.3 Network Low None None Changed High Low None 15.1.1.0.0  
CVE-2026-35306 Oracle Coherence Centralized Third Party Jars HTTP Yes 9.3 Network Low None None Changed High Low None 15.1.1.0.0  
CVE-2026-46785 Oracle WebCenter Content Content Server HTTP Yes 9.3 Network Low None Required Changed High High None 14.1.2.0.0  
CVE-2026-46795 Oracle WebCenter Content Content Server HTTP Yes 9.3 Network Low None Required Changed High High None 14.1.2.0.0  
CVE-2026-46805 Oracle WebCenter Content Content Server HTTP Yes 9.3 Network Low None Required Changed High High None 14.1.2.0.0  
CVE-2026-35270 Oracle WebCenter Content Content Server HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46777 Oracle WebCenter Content Content Server HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46809 Oracle WebCenter Sites WebCenter Sites HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46784 WebCenter Content: Imaging Core HTTP Yes 9.1 Network Low None None Un-
changed
High High None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35298 WebLogic Server Core HTTP No 9.1 Network Low High None Changed High High High 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35320 Oracle WebCenter Content Content Server HTTP Yes 9.0 Network High None None Changed High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35267 Identity Manager REST WebServices HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35265 Identity Manager Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35315 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35317 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35322 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35324 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35325 Oracle WebCenter Content Content Server HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35318 Oracle WebCenter Sites WebCenter Sites HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46780 WebCenter Content: Imaging Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35299 WebLogic Server Console HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-35303 WebLogic Server Console HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-35311 WebLogic Server Core HTTP No 8.8 Network Low Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35259 WebLogic Server Console HTTPS Yes 8.8 Network Low None Required Un-
changed
High High High 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46804 Oracle WebCenter Content Content Server HTTP No 8.7 Network Low Low Required Changed High High None 14.1.2.0.0  
CVE-2026-46808 Oracle WebCenter Content Content Server HTTP No 8.7 Network Low Low Required Changed High High None 14.1.2.0.0  
CVE-2026-35258 WebLogic Server Console HTTPS No 8.7 Network Low Low Required Changed High High None 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46776 Oracle Unified Directory OUD Core LDAP Yes 8.6 Network Low None None Un-
changed
Low High Low 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46788 Oracle WebCenter Content Content Server HTTP No 8.4 Network Low High Required Changed High High High 14.1.2.0.0  
CVE-2026-35262 Oracle Data Integrator Market Place HTTP No 8.3 Network Low Low None Un-
changed
High High Low 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35302 WebLogic Server Console HTTP Yes 8.3 Network High None Required Changed High High High 12.2.1.4.0, 14.1.1.0.0  
CVE-2026-46806 Oracle WebCenter Content Content Server HTTPS Yes 8.2 Network Low None Required Changed High Low None 14.1.2.0.0  
CVE-2026-46787 Oracle WebCenter Content Content Server HTTP Yes 8.0 Network High None Required Changed High High None 14.1.2.0.0  
CVE-2026-46796 Oracle WebCenter Sites WebCenter Sites HTTP No 8.0 Network Low Low Required Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46848 WebLogic Server Console None No 7.9 Local Low Low Required Changed High High None 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-35327 Oracle WebCenter Content Content Server HTTPS No 7.6 Network Low Low Required Changed High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35269 Identity Manager REST WebServices HTTP Yes 7.5 Network Low None None Un-
changed
None High None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46791 Oracle WebCenter Content Content Server HTTP Yes 7.5 Network Low None None Un-
changed
High None None 14.1.2.0.0  
CVE-2026-35295 Oracle WebCenter Sites WebCenter Sites HTTP No 7.5 Network High Low None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35314 Oracle Access Manager Web Server Plugin HTTP Yes 7.3 Network Low None None Un-
changed
Low Low Low 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46769 Oracle Application Development Framework (ADF) ADF Shared Components HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35326 Oracle WebCenter Content Content Server HTTP No 7.2 Network Low High None Un-
changed
High High High 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-35291 WebLogic Server Console HTTP No 6.6 Network High High None Un-
changed
High High High 14.1.2.0.0, 15.1.1.0.0  
CVE-2026-46810 Identity Manager End User Self Service IIOP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-35261 Oracle Access Manager Authentication Engine HTTP Yes 6.5 Network Low None None Un-
changed
Low Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46812 Oracle Access Manager Authentication Engine HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.1.4.0, 14.1.2.1.0  
CVE-2026-46770 Oracle Application Development Framework (ADF) Security Framework HTTP Yes 6.1 Network Low None Required Changed Low Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46790 Oracle WebCenter Content Content Server HTTP Yes 5.3 Network Low None None Un-
changed
Low None None 14.1.2.0.0  
CVE-2026-46772 Oracle Application Development Framework (ADF) ADF Faces None No 4.7 Local High High None Un-
changed
High Low None 12.2.1.4.0, 14.1.2.0.0  
CVE-2026-46771 Oracle Application Development Framework (ADF) Java Business Objects None No 4.1 Local High High None Un-
changed
High None None 12.2.1.4.0, 14.1.2.0.0  

Additional CVEs addressed are:

  • The patch for CVE-2026-46783 also addresses CVE-2022-21445.
  • The patch for CVE-2026-35316 also addresses CVE-2022-21552.

 

Oracle JD Edwards Risk Matrix

This Critical Security Patch Update contains 20 new security patches for Oracle JD Edwards.  12 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46908 JD Edwards EnterpriseOne Accounts Payable Accounts Payable HTTP No 9.9 Network Low Low None Changed High High High 9.2  
CVE-2026-46893 JD Edwards EnterpriseOne General Ledger E1 Foundation SMB No 9.9 Network Low Low None Changed High High High 9.2  
CVE-2026-46907 JD Edwards EnterpriseOne Order Promising Order Promising Integration HTTP No 9.9 Network Low Low None Changed High High High 9.2  
CVE-2026-46909 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46905 JD Edwards EnterpriseOne Tools Web Runtime Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46878 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46879 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46880 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46881 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46882 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46883 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46904 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security JDENET Yes 9.8 Network Low None None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46911 JD Edwards EnterpriseOne Project Costing Job Costing JDENET No 9.6 Network Low Low None Changed High High None 9.2  
CVE-2026-46906 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security HTTP No 9.6 Network Low Low None Changed High High None 9.2.0.0-9.2.26.2  
CVE-2026-46912 JD Edwards EnterpriseOne Tools Web Runtime Security HTTP Yes 9.3 Network Low None None Changed High Low None 9.2.0.0-9.2.26.2  
CVE-2026-46913 JD Edwards EnterpriseOne Tools Installation Security None No 9.3 Local Low None None Changed High High High 9.2.0.0-9.2.26.2  
CVE-2026-46892 JD Edwards EnterpriseOne Human Resources Management Human Resources HTTP Yes 9.1 Network Low None None Un-
changed
High High None 9.2  
CVE-2026-46910 JD Edwards EnterpriseOne Tools Enterprise Infrastructure Security HTTP Yes 9.1 Network Low None None Un-
changed
High None High 9.2.0.0-9.2.26.2  
CVE-2026-46903 JD Edwards EnterpriseOne Tools Business Logic Infrastructure Security HTTP No 8.8 Network Low Low None Un-
changed
High High High 9.2.0.0-9.2.26.2  
CVE-2026-46891 JD Edwards EnterpriseOne Accounts Payable Accounts Payable HTTP No 8.1 Network Low Low None Un-
changed
High High None 9.2  

 

Oracle MySQL Risk Matrix

This Critical Security Patch Update contains 8 new security patches for Oracle MySQL.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46850 MySQL Shell Shell for VS Code HTTP No 9.9 Network Low Low None Changed High High High 2026.2.0+9.6.1  
CVE-2026-46860 MySQL Router Router: General HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.0.0-9.7.0  
CVE-2026-46861 MySQL NDB Cluster Cluster: NDB Operator HTTP No 9.6 Network Low Low None Changed High High None 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0  
CVE-2026-46870 MySQL Shell Shell for VS Code MySQL Protocol No 8.5 Network High Low None Changed High High High 2026.2.0+9.6.1  
CVE-2026-46862 MySQL Router Router: General TLS Yes 7.5 Network Low None None Un-
changed
None None High 8.4.0-8.4.9, 9.0.0-9.7.0  
CVE-2026-46863 MySQL Server, MySQL Cluster Server: Connection Handling MySQL Protocol Yes 7.5 Network Low None None Un-
changed
None None High MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9, 9.0.0-9.7.0  
CVE-2026-46871 MySQL Shell Shell for VS Code MySQL Protocol No 6.5 Network Low Low None Un-
changed
High None None 2026.2.0+9.6.1  
CVE-2026-46869 MySQL Shell Shell: Dump and Load MySQL Protocol Yes 6.5 Network Low None Required Un-
changed
High None None 8.4.0-8.4.9, 9.0.0-9.7.0  

 

Oracle PeopleSoft Risk Matrix

This Critical Security Patch Update contains 11 new security patches for Oracle PeopleSoft.  7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-35278 PeopleSoft Enterprise PT PeopleTools Performance Monitor HTTP Yes 9.8 Network Low None None Un-
changed
High High High 8.61, 8.62  
CVE-2026-35271 PeopleSoft Enterprise PT PeopleTools Weblogic HTTP Yes 8.7 Network High None None Changed High High None 8.61, 8.62  
CVE-2026-35272 PeopleSoft Enterprise PT PeopleTools Deployment Package None No 8.4 Local Low None None Un-
changed
High High High 8.61, 8.62  
CVE-2026-35274 PeopleSoft Enterprise PT PeopleTools Deployment Package HTTP Yes 8.2 Network Low None None Un-
changed
High Low None 8.61, 8.62  
CVE-2026-35288 PeopleSoft Enterprise PT PeopleTools Deployment Package None No 8.2 Local Low High None Changed High High High 8.61, 8.62  
CVE-2026-46851 PeopleSoft Enterprise CS Campus Community Security HTTP Yes 8.1 Network High None None Un-
changed
High High High 9.2.38  
CVE-2026-46849 PeopleSoft Enterprise CS Student Financials Other HTTP No 8.1 Network Low Low None Un-
changed
High High None 9.2.38  
CVE-2026-35276 PeopleSoft Enterprise PT PeopleTools Application Server HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.61, 8.62  
CVE-2026-35279 PeopleSoft Enterprise PT PeopleTools Performance Monitor HTTP Yes 8.1 Network High None None Un-
changed
High High High 8.61, 8.62  
CVE-2026-35289 PeopleSoft Enterprise PT PeopleTools Deployment Package HTTPS Yes 8.1 Network High None None Un-
changed
High High High 8.61, 8.62  
CVE-2026-46979 PeopleSoft Enterprise CS Campus Community Integration and Interfaces HTTPS No 6.5 Network Low High None Un-
changed
High High None 9.2.38  

 

Oracle Siebel CRM Risk Matrix

This Critical Security Patch Update contains 12 new security patches for Oracle Siebel CRM.  7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46884 Siebel Apps - Marketing Marketing HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46887 Siebel Apps - Marketing Marketing HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46889 Siebel Apps - Marketing Marketing HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46890 Siebel Apps - Marketing Marketing HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46919 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 9.8 Network Low None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46886 Siebel Apps - Marketing Marketing HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.5  
CVE-2026-46921 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.5  
CVE-2026-46926 Siebel CRM Cloud Applications Siebel Cloud Manager None No 8.8 Local Low Low None Changed High High High 17.0-26.5  
CVE-2026-46885 Siebel CRM Integration EAI HTTP No 8.8 Network Low Low None Un-
changed
High High High 17.0-26.5  
CVE-2026-46925 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 8.3 Adjacent
Network
High None None Changed High High High 17.0-26.5  
CVE-2026-46920 Siebel CRM Cloud Applications Siebel Cloud Manager HTTP Yes 8.1 Network High None None Un-
changed
High High High 17.0-26.5  
CVE-2026-46888 Siebel CRM Deployment Database Upgrade None No 7.8 Local Low Low None Un-
changed
High High High 17.0-26.5  

 

Oracle Supply Chain Risk Matrix

This Critical Security Patch Update contains 1 new security patch for Oracle Supply Chain.  This vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46859 Oracle Agile PLM Security HTTP Yes 9.8 Network Low None None Un-
changed
High High High 9.3.6  

Additional CVEs addressed are:

  • The patch for CVE-2026-46859 also addresses CVE-2026-21940.

 

Oracle Systems Risk Matrix

This Critical Security Patch Update contains 3 new security patches for Oracle Systems.  1 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46978 Oracle Solaris Remote Administration Daemon HTTPS Yes 10.0 Network Low None None Changed High High None 11.4  
CVE-2026-46914 Oracle Solaris Filesystem None No 7.1 Local Low Low None Un-
changed
High None High 11.4  
CVE-2026-35233 Oracle Solaris Libraries None No 4.4 Local Low Low None Un-
changed
None Low Low 11.4  

 

Oracle Virtualization Risk Matrix

This Critical Security Patch Update contains 10 new security patches for Oracle Virtualization.  None of these vulnerabilities may be remotely exploitable without authentication, i.e., none may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here.

CVE ID Product Component Protocol Remote
Exploit
without
Auth.?
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) Supported Versions Affected Notes
Base
Score
Attack
Vector
Attack
Complex
Privs
Req'd
User
Interact
Scope Confid-
entiality
Inte-
grity
Avail-
ability
CVE-2026-46974 Oracle VM VirtualBox Core None No 7.5 Local High High None Changed High High High 7.2.8  
CVE-2026-35275 Oracle VM VirtualBox Shared Folders None No 7.5 Local High Low None Changed High High None 7.2.8  
CVE-2026-46873 Oracle VM VirtualBox VMSVGA device None No 7.5 Local High High None Changed High High High 7.2.8  
CVE-2026-46768 Oracle VM VirtualBox VMSVGA device None No 6.0 Local Low High None Changed None None High 7.2.8  
CVE-2026-46825 Oracle VM VirtualBox VMSVGA device None No 6.0 Local Low High None Changed None High None 7.2.8  
CVE-2026-46877 Oracle VM VirtualBox VMSVGA device None No 6.0 Local Low High None Changed High None None 7.2.8  
CVE-2026-46874 Oracle VM VirtualBox Core None No 3.2 Local Low High None Changed Low None None 7.2.8  
CVE-2026-46815 Oracle VM VirtualBox VMSVGA device None No 3.2 Local Low High None Changed Low None None 7.2.8  
CVE-2026-46816 Oracle VM VirtualBox VMSVGA device None No 3.2 Local Low High None Changed Low None None 7.2.8  
CVE-2026-46977 Oracle VM VirtualBox VMSVGA device None No 3.2 Local Low High None Changed Low None None 7.2.8