NCSC-2026-0310 [1.00] [M/H] Vulnerabilities resolved in Oracle E-Business Suite
Oracle has resolved vulnerabilities in different components of Oracle E-Business Suite, including General Ledger, Payments, Workflow, Sales, Purchasing, Call Center Technology, and other modules within versions 12.2.3 through 12.2.15. The vulnerabilities in Oracle E-Business Suite versions 12.2.3 through 12.2.15 allow an attacker with low to high privileges and network access via HTTP or HTTPS to perform unauthorized actions. These actions include creating, deleting, modifying or reading critical data, obtaining unauthorized access to sensitive information, and in some cases completely taking over the system. Some vulnerabilities require user interaction, while others can be exploited without authentication. The impact extends to confidentiality, integrity and availability of systems and data. Additionally, there are vulnerabilities that can cause Denial-of-Service by making application components hang or crash. The vulnerabilities are present in diverse modules such as financial administration, payment processing, workflow management, sales, purchasing, customer service, and other business processes within Oracle E-Business Suite.
CSIRTS triage
- What
- Multiple vulnerabilities allow attackers with varying privilege levels to perform unauthorized actions, modify data, gain system access, and cause denial-of-service.
- Who is affected
- Deployments of Oracle E-Business Suite versions 12.2.3 through 12.2.15.
- Urgency
- Medium to high severity with network access and low-privilege exploitation paths; apply patches without delay.
- Action
- Apply Oracle security patches for E-Business Suite versions 12.2.3 through 12.2.15.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch E-Business Suite
Get an email when a new E-Business Suite advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0310
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-606930.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607480.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607590.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607690.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607810.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607820.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608300.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609760.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-611390.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-611980.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Oracle E-Business Suite: Multiple vulnerabilitiescert-bund
- highCVE-2026-70764: Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Inte…nvd
- highCVE-2026-70763: Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (compon…nvd
- highCVE-2026-70762: Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70761: Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70760: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Pr…nvd
- highCVE-2026-70747: Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Cu…nvd
- mediumCVE-2026-70732: Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (comp…nvd
- highCVE-2026-70729: Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service…nvd
- mediumCVE-2026-70726: Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70725: Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (com…nvd
- highCVE-2026-70722: Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (com…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21