CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0253 [1.00] [M/H] Vulnerabilities fixed in Oracle E-Business Suite components

unknownCVE-2026-60880CVE-2026-60773CVE-2026-62549CVE-2026-62546
Oracle has fixed multiple vulnerabilities in Oracle E-Business Suite, including various modules such as Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command Center Framework, Flow Manufacturing, General Ledger, Installed Base, iReceivables, Labor Distribution, Order Management, Payables, Payroll, Process Manufacturing, Product Hub, Project Intelligence, Public Sector Financials, Sales Offline, SDP Number Portability, Trade Management, Transportation Execution, Warehouse Management, Yard Management, TeleSales, Service Fulfillment Manager, Contracts Integration, Applications Manager, Common Application Components, Price Protection, Workflow, and other components within versions 12.2.3 to 12.2.15. The total number of vulnerabilities fixed in these updates is 410. The most severe vulnerabilities, 4 in total, have high scores ranging from 9.1 to 9.8 and are found in various Oracle E-Business components. The vulnerability with a score of 9.8 allows unauthenticated attackers to take over Oracle Work in Process via HTTP. A limiting factor is that the vulnerable products are not designed to be publicly accessible, reducing the likelihood of widespread exploitation. The other severe vulnerabilities can be exploited via HTTP or HTTPS, depending on the required permissions, allowing an attacker to gain unauthorized access to sensitive data, modify or delete it, or even gain full control over parts of the Oracle Applications Framework environment. The remaining 406 vulnerabilities have scores lower than 9. Detailed information for these vulnerabilities is not included in this advisory, and the NCSC therefore refers to the attached reference.

CSIRTS triage

vendor: Oracleproduct: Oracle E-Business SuiteOtheraffected: 12.2.3 to 12.2.15
What
Multiple vulnerabilities have been fixed across various components of Oracle E-Business Suite.
Who is affected
Deployments of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Urgency
Remediation is important to mitigate potential risks from these vulnerabilities.
Action
Update to the latest version of Oracle E-Business Suite.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Oracle E-Business Suite

Get an email when a new Oracle E-Business Suite advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0253

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-60880coverage & exploitation statusNVD · CVE.org
CVE-2026-60773coverage & exploitation statusNVD · CVE.org
CVE-2026-62549coverage & exploitation statusNVD · CVE.org
CVE-2026-62546coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Oracle E-Business Suite

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories