CVE-2026-62546
Oracle has fixed multiple vulnerabilities in Oracle E-Business Suite, including various modules such as Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command Center Framework, Flow Manufacturing, General Ledger, Installed Base, iReceivables, Labor Distribution, Order Management, Payables, Payroll, Process Manufacturing, Product Hub, Project Intelligence, Public Sector Financials, Sales Offline, SDP Number Portability, Trade Management, Transportation Execution, Warehouse Management, Yard Management, TeleSales, Service Fulfillment Manager, Contracts Integration, Applications Manager, Common Application Components, Price Protection, Workflow, and other components within versions 12.2.3 to 12.2.15. The total number of vulnerabilities fixed in these updates is 410. The most severe vulnerabilities, 4 in total, have high scores ranging from 9.1 to 9.8 and are found in various Oracle E-Business components. The vulnerability with a score of 9.8 allows unauthenticated attackers to take over Oracle Work in Process via HTTP. A limiting factor is that the vulnerable products are not designed to be publicly accessible, reducing the likelihood of widespread exploitation. The other severe vulnerabilities can be exploited via HTTP or HTTPS, depending on the required permissions, allowing an attacker to gain unauthorized access to sensitive data, modify or delete it, or even gain full control over parts of the Oracle Applications Framework environment. The remaining 406 vulnerabilities have scores lower than 9. Detailed information for these vulnerabilities is not included in this advisory, and the NCSC therefore refers to the attached reference.
CSIRTS triage
- What
- Multiple vulnerabilities have been fixed across various components of Oracle E-Business Suite.
- Who is affected
- Deployments of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
- Urgency
- Remediation is important to mitigate potential risks from these vulnerabilities.
- Action
- Update to the latest version of Oracle E-Business Suite.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-62546
Get an email if CVE-2026-62546 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownNCSC-2026-0253 [1.00] [M/H] Vulnerabilities fixed in Oracle E-Business Suite componentsncsc-nl · 2026-07-22
- criticalCVE-2026-62546: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (compone…nvd · 2026-07-21
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-62546)