NCSC-2026-0253 [1.00] [M/H] Vulnerabilities fixed in Oracle E-Business Suite components
Oracle has fixed multiple vulnerabilities in Oracle E-Business Suite, including various modules such as Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command Center Framework, Flow Manufacturing, General Ledger, Installed Base, iReceivables, Labor Distribution, Order Management, Payables, Payroll, Process Manufacturing, Product Hub, Project Intelligence, Public Sector Financials, Sales Offline, SDP Number Portability, Trade Management, Transportation Execution, Warehouse Management, Yard Management, TeleSales, Service Fulfillment Manager, Contracts Integration, Applications Manager, Common Application Components, Price Protection, Workflow, and other components within versions 12.2.3 to 12.2.15. The total number of vulnerabilities fixed in these updates is 410. The most severe vulnerabilities, 4 in total, have high scores ranging from 9.1 to 9.8 and are found in various Oracle E-Business components. The vulnerability with a score of 9.8 allows unauthenticated attackers to take over Oracle Work in Process via HTTP. A limiting factor is that the vulnerable products are not designed to be publicly accessible, reducing the likelihood of widespread exploitation. The other severe vulnerabilities can be exploited via HTTP or HTTPS, depending on the required permissions, allowing an attacker to gain unauthorized access to sensitive data, modify or delete it, or even gain full control over parts of the Oracle Applications Framework environment. The remaining 406 vulnerabilities have scores lower than 9. Detailed information for these vulnerabilities is not included in this advisory, and the NCSC therefore refers to the attached reference.
CSIRTS triage
- What
- Multiple vulnerabilities have been fixed across various components of Oracle E-Business Suite.
- Who is affected
- Deployments of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
- Urgency
- Remediation is important to mitigate potential risks from these vulnerabilities.
- Action
- Update to the latest version of Oracle E-Business Suite.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Oracle E-Business Suite
Get an email when a new Oracle E-Business Suite advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0253
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-608800.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-607730.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-625490.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-625460.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60880 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60773 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62549 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62546 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalCVE-2026-62549: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payrol…nvd
- criticalCVE-2026-62546: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (compone…nvd
- criticalCVE-2026-60880: Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Int…nvd
- criticalCVE-2026-60773: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (com…nvd
Recent advisories for Oracle E-Business Suite
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Oracle E-Business Suite: Multiple vulnerabilitiescert-bund · 2026-07-22
- highCVE-2026-62567: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payrol…nvd · 2026-07-21
- highCVE-2026-62565: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payrol…nvd · 2026-07-21
- mediumCVE-2026-62563: Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Int…nvd · 2026-07-21
- mediumCVE-2026-62562: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal …nvd · 2026-07-21
- highCVE-2026-62561: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal …nvd · 2026-07-21
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30