Multiple vulnerabilities in Oracle Systems (July 23, 2026)
Multiple vulnerabilities have been discovered in Oracle Systems. They allow an attacker to cause data confidentiality breaches, data integrity breaches, and denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause data confidentiality breaches, data integrity breaches, and denial of service.
- Who is affected
- Deployments of Oracle Systems are affected.
- Urgency
- Remediation is urgent due to the potential for severe data breaches.
- Action
- Update Oracle Systems to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle Systems
Get an email when a new Oracle Systems advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0918/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-610100.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-606590.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-606610.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-610520.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
- Low exploitation riskCVE-2026-608330.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-612850.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-608340.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-612020.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-610000.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-612870.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-61010 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60659 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60661 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61052 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60833 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60834 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61202 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61000 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-61287 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Oracle Solaris: Multiple vulnerabilitiescert-bund
- highCVE-2026-61287: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd
- highCVE-2026-61285: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd
- highCVE-2026-61202: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported …nvd
- mediumCVE-2026-61052: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The su…nvd
- highCVE-2026-61010: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd
- highCVE-2026-61000: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd
- highCVE-2026-60834: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The suppor…nvd
- highCVE-2026-60833: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The suppor…nvd
- highCVE-2026-60661: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The su…nvd
- highCVE-2026-60659: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The su…nvd
Recent advisories for Oracle Systems
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-62525: Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Wor…nvd · 2026-07-21
- highCVE-2026-61287: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd · 2026-07-21
- highCVE-2026-61285: Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (…nvd · 2026-07-21
- highCVE-2026-61202: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported …nvd · 2026-07-21
- highCVE-2026-61164: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager produc…nvd · 2026-07-21
- mediumCVE-2026-61147: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager produc…nvd · 2026-07-21
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans PHP (31 juillet 2026)2026-07-31
- unknownVulnérabilité dans Microsoft Azure (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31