[NEW] [high] Oracle E-Business Suite: Multiple vulnerabilities
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle E-Business Suite to compromise confidentiality, integrity and availability.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote attackers to compromise confidentiality, integrity, and availability of Oracle E-Business Suite.
- Who is affected
- Deployments of Oracle E-Business Suite accessible to remote anonymous or authenticated attackers.
- Urgency
- High severity; affects core business functionality and data protection.
- Action
- Apply Oracle security patches addressing CVE-2026-60693, CVE-2026-60748, CVE-2026-60759, CVE-2026-60769, CVE-2026-60781, CVE-2026-60782, CVE-2026-60830, and CVE-2026-60976.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch E-Business Suite
Get an email when a new E-Business Suite advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2891
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-606930.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607480.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607590.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607690.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607810.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607820.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-608300.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-609760.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-611390.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-611980.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0310 [1.00] [M/H] Vulnerabilities resolved in Oracle E-Business Suitencsc-nl
- highCVE-2026-70764: Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Inte…nvd
- highCVE-2026-70763: Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (compon…nvd
- highCVE-2026-70762: Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70761: Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70760: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Pr…nvd
- highCVE-2026-70747: Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Cu…nvd
- mediumCVE-2026-70732: Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (comp…nvd
- highCVE-2026-70729: Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service…nvd
- mediumCVE-2026-70726: Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Int…nvd
- highCVE-2026-70725: Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (com…nvd
- highCVE-2026-70722: Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (com…nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25