[CIAD-2026-0043] Multiple Vulnerabilities in Oracle Products

By Published On: August 31, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Oracle Products


Original Issue Date: August 28, 2026


Severity Rating: High


Software Affected


Oracle MySQL

Oracle Access Manager

Oracle Supply Chain Products

Oracle Analytics

Oracle Commerce

Oracle Communications

Oracle Database Server

Oracle E-Business Suite

Oracle Enterprise Manager

Oracle Financial Services Applications

For complete list of affected products and versions refer to the Oracle advisory:

https://www.oracle.com/security-alerts/cspuaug2026.html


Overview


Multiple vulnerabilities have been reported in various Oracle products which could be exploited by a remote attacker to gain unauthorized access, execute arbitrary code, disclose sensitive information, manipulate data, bypass security controls, or cause denial-of-service conditions on the targeted system.


Target Audience:

Organizations and IT administrators using Oracle Corporation products.


Risk Assessment:

Risk of remote code execution, unauthorized access, sensitive information disclosure, data manipulation, or denial-of-service conditions.


Impact Assessment:

Potential unauthorized access to sensitive information, data manipulation, and security control bypass, and disruption of affected systems.


Description


Oracle products are used for several applications including enterprise-level data management, cloud solutions, software development, communications, financial services, hospitality, retail, and business applications. They are employed across a wide range of sectors, including finance, healthcare, manufacturing, government, and retail, among others.


These vulnerabilities exist in various components of Oracle products due to weaknesses affecting different product functionalities and third-party components. Several of the vulnerabilities may be exploited remotely without authentication over a network without requiring valid user credentials.


Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, execute arbitrary code, access sensitive information, manipulate data, bypass security controls, or cause denial-of-service conditions on the targeted system.


For complete list of affected products and versions refer to the Oracle advisory:

https://www.oracle.com/security-alerts/cspuaug2026.html




Solution


Apply appropriate updates as mentioned by the Vendor:  

https://www.oracle.com/security-alerts/cspuaug2026.html


Vendor Information


Oracle

https://www.oracle.com/security-alerts/


References


 

https://www.oracle.com/security-alerts/cspuaug2026.html




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVkeYACgkQ3jCgcSdc

ys8fUQ//dZxhfz8io0OEI8LePllsEkCV57qYIhHM5Ru0ObYPoSccigzorgFpmWCz

AKOZ6S1jPay/4i6DlEUaukorCs//BONDja7FkfrUYbLOqiPN5LUTn92xkH4e61za

r6vZrip0gSEooiDbdFRRhTqzAgzc8mh9I3zYZkMKUv3gS0EevM1gzJYcqNBv3Ivs

Ew5hNcWjvQB8ok90R9ri6ti7V3XD0L/WiElxdbpfR8UeC2dNG3bvNaLJdl0vUQC4

nnYYN9rqWmAjEyAvj9dOhOllHRLO2zZD9zqC0P95xoZhsuGIF/qZU3yXrnfgdcZU

ZuJwn7lQBWFndy4OTGmLdhpGgWfQi/PXhGy7vhTo4812Edg19Ej6hjjn4/NvOINR

Cct2FavUaWWnc/ZuvgUywkdoapwQSBKJqyLdMhHZULp1aKfHQ3dHYCqHnWT8XNI5

gp0zYIZIYp3cwZv4HNzTOjYfkLI5YOFHswdpp9CRvMvo+7Pw5b0cnAYufoteJLld

iRyVW62pFJabx0ib9C2zRy/VbnrJTwYWkLABixwArNSB6FI6mQtHPs4HsWiMAV5v

LOMCMWckaH0rtTq/wtRrbO+HNTFHUfyQR9hd3/LYXomfTF4+MoAk+OPJMxH3wHwx

PoNDjre/H+cA8BzuBZLNfTh2lhy0JB3Od2h3R6W0KLdJM7w/pnk=

=yO1H

—–END PGP SIGNATURE—–

Share this article