CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-60880

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-07-21
Oracle has fixed multiple vulnerabilities in Oracle E-Business Suite, including various modules such as Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command Center Framework, Flow Manufacturing, General Ledger, Installed Base, iReceivables, Labor Distribution, Order Management, Payables, Payroll, Process Manufacturing, Product Hub, Project Intelligence, Public Sector Financials, Sales Offline, SDP Number Portability, Trade Management, Transportation Execution, Warehouse Management, Yard Management, TeleSales, Service Fulfillment Manager, Contracts Integration, Applications Manager, Common Application Components, Price Protection, Workflow, and other components within versions 12.2.3 to 12.2.15. The total number of vulnerabilities fixed in these updates is 410. The most severe vulnerabilities, 4 in total, have high scores ranging from 9.1 to 9.8 and are found in various Oracle E-Business components. The vulnerability with a score of 9.8 allows unauthenticated attackers to take over Oracle Work in Process via HTTP. A limiting factor is that the vulnerable products are not designed to be publicly accessible, reducing the likelihood of widespread exploitation. The other severe vulnerabilities can be exploited via HTTP or HTTPS, depending on the required permissions, allowing an attacker to gain unauthorized access to sensitive data, modify or delete it, or even gain full control over parts of the Oracle Applications Framework environment. The remaining 406 vulnerabilities have scores lower than 9. Detailed information for these vulnerabilities is not included in this advisory, and the NCSC therefore refers to the attached reference.

CSIRTS triage

vendor: Oracleproduct: Oracle E-Business SuiteOtheraffected: 12.2.3 to 12.2.15
What
Multiple vulnerabilities have been fixed across various components of Oracle E-Business Suite.
Who is affected
Deployments of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Urgency
Remediation is important to mitigate potential risks from these vulnerabilities.
Action
Update to the latest version of Oracle E-Business Suite.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-60880

Get an email if CVE-2026-60880 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-60880

CVE.org record

Embed the live status

CVE-2026-60880 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-60880 status](https://www.csirts.com/badge/CVE-2026-60880)](https://www.csirts.com/cve/CVE-2026-60880)