[CIAD-2026-0036] Multiple Vulnerabilities in Oracle Products

By Published On: July 23, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Oracle Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: High


Software Affected


Oracle MySQL

Java SE

Oracle Database Server

WebLogic Server

Oracle Communications

Oracle Construction and Engineering

Oracle Enterprise Manager

Oracle Financial Services Applications

Oracle Fusion Middleware

Oracle E-Business Suite

For complete list of affected products refer to the oracle advisory:

https://www.oracle.com/security-alerts/cpujul2026.html


Overview


Multiple vulnerabilities have been reported in various Oracle products which could be exploited by a remote attacker to execute arbitrary code, gain elevated privileges, cause denial-of-service conditions, access sensitive information, manipulate data, or bypass security controls on the targeted system.


Target Audience:

Organizations and IT administrators using Oracle Corporation products.


Risk Assessment:

Risk of remote code execution, system instability or sensitive information disclosure.


Impact Assessment:

Potential unauthorized access to sensitive information, denial of service, data manipulation, and complete takeover of control of the target system.


Description


Oracle products are used for several applications including enterprise-level data management, cloud solutions, software development, and business applications. They are employed across a wide range of sectors, including finance, healthcare, manufacturing, government, and retail, among others.


These vulnerabilities exist in various components of Oracle products due to improper input validation, deserialization issues, memory corruption errors, access control weaknesses, insufficient authentication, SQL injection, XML parsing errors, or vulnerable third-party libraries.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain elevated privileges, cause denial-of-service conditions, access sensitive information, manipulate data, or bypass security controls on the targeted system.


For complete list of affected products, CVEs, workarounds and solutions, refer to the oracle advisory:

https://www.oracle.com/security-alerts/cpujul2026.html




Solution


Apply appropriate updates as mentioned in Oracle updates:  

https://www.oracle.com/security-alerts/cpujul2026.html


Vendor Information


Oracle

https://www.oracle.com/security-alerts/cpujul2026.html


References


 

https://www.oracle.com/security-alerts/cpujul2026.html




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKd8ACgkQ3jCgcSdc

ys9yBA//ZIFp6wGa57NFcqjZNHhVWU9+9ff46PoorbAGzmN86wJxV6Uc3CgFMiiU

P7kJxHrYE4CxZks9eq/We6aNLqUeXY93aIlsgkdNHp7N2A028AmHkTbK6b3tsmiC

OLn7D7h+hZtbIAKslQ7gcmelohHS6BjdazLHPuFeDKL3yIkl1qOnhzQ6zMRxnnCw

S9UE22+P9IoQvmw66FwLUu+6MkBaGtLwd4UGRmn+Yl7zTWNKpTmlxfuKZyOKMIi1

08NXnv6h2YGvDsK293sDkztarWZpHo0OVOE+ch1RbXh4EcLth9Ia8eqC6BdU9Wwf

N1qKjGRkZ/duVLDanzvkQYBrUvn58qjOZF4vGZhjEs39MSBNUNNfi4n5DCTzdClr

tHx3fUPHDggj2fnaRc8yA3/LzgD3HtuOjuKJA7ADclmJ5+bEiSZpynLXfPAkFWnR

/Z9gCVWtzYdOXvQIqWY191KGSG1Re7Xh4srWaD/oIWuqOjudMkI7HRFX0BneLttD

WSVx3q9L1DY4ZVt00xNKnKGK3i2gxgCj0P4O9CKv+g1gn1oaVoIm1vQqhi8SeSFx

FK5QAAV4roYB8m5sOGdtH334xFSTd9trRbyRyo0iICZ89eVf9Vwj4VvP8B0s43m0

K1q8OcJLZ+9XNfSCKPl7pror7a67eL7570k3FiS7Y+hKpyxHWFA=

=9kRu

—–END PGP SIGNATURE—–

Share this article