[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilities
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle Siebel CRM to compromise confidentiality, integrity and availability.
CSIRTS triage
- What
- Multiple vulnerabilities in Oracle Siebel CRM allow remote attackers to compromise confidentiality, integrity, and availability.
- Who is affected
- Deployments of Oracle Siebel CRM running affected versions with remote or authenticated access.
- Urgency
- High severity with no current exploitation; prioritize if externally accessible.
- Action
- Apply the latest Oracle Siebel CRM security patches from Oracle's official updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Siebel CRM
Get an email when a new Siebel CRM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2900
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-607510.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607520.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607530.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607540.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607570.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607580.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607650.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607660.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607670.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-607790.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
+2 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-70951: Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Man…nvd
- highCVE-2026-70949: Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Inf…nvd
- highCVE-2026-70910: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Su…nvd
- highCVE-2026-70859: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Su…nvd
- highCVE-2026-70857: Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Su…nvd
- highCVE-2026-70856: Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration)…nvd
- criticalCVE-2026-70855: Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpd…nvd
- highCVE-2026-62596: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Inte…nvd
- highCVE-2026-62595: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Inte…nvd
- highCVE-2026-62594: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Inte…nvd
- highCVE-2026-62593: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Inte…nvd
- criticalCVE-2026-62592: Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Inte…nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25