
[CIAD-2026-0043] Multiple Vulnerabilities in Oracle Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Oracle Products
Original Issue Date: August 28, 2026
Severity Rating: High
Software Affected
Oracle MySQL
Oracle Access Manager
Oracle Supply Chain Products
Oracle Analytics
Oracle Commerce
Oracle Communications
Oracle Database Server
Oracle E-Business Suite
Oracle Enterprise Manager
Oracle Financial Services Applications
For complete list of affected products and versions refer to the Oracle advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html
Overview
Multiple vulnerabilities have been reported in various Oracle products which could be exploited by a remote attacker to gain unauthorized access, execute arbitrary code, disclose sensitive information, manipulate data, bypass security controls, or cause denial-of-service conditions on the targeted system.
Target Audience:
Organizations and IT administrators using Oracle Corporation products.
Risk Assessment:
Risk of remote code execution, unauthorized access, sensitive information disclosure, data manipulation, or denial-of-service conditions.
Impact Assessment:
Potential unauthorized access to sensitive information, data manipulation, and security control bypass, and disruption of affected systems.
Description
Oracle products are used for several applications including enterprise-level data management, cloud solutions, software development, communications, financial services, hospitality, retail, and business applications. They are employed across a wide range of sectors, including finance, healthcare, manufacturing, government, and retail, among others.
These vulnerabilities exist in various components of Oracle products due to weaknesses affecting different product functionalities and third-party components. Several of the vulnerabilities may be exploited remotely without authentication over a network without requiring valid user credentials.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, execute arbitrary code, access sensitive information, manipulate data, bypass security controls, or cause denial-of-service conditions on the targeted system.
For complete list of affected products and versions refer to the Oracle advisory:
https://www.oracle.com/security-alerts/cspuaug2026.html
Solution
Apply appropriate updates as mentioned by the Vendor:
https://www.oracle.com/security-alerts/cspuaug2026.html
Vendor Information
Oracle
https://www.oracle.com/security-alerts/
References
https://www.oracle.com/security-alerts/cspuaug2026.html
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVkeYACgkQ3jCgcSdc
ys8fUQ//dZxhfz8io0OEI8LePllsEkCV57qYIhHM5Ru0ObYPoSccigzorgFpmWCz
AKOZ6S1jPay/4i6DlEUaukorCs//BONDja7FkfrUYbLOqiPN5LUTn92xkH4e61za
r6vZrip0gSEooiDbdFRRhTqzAgzc8mh9I3zYZkMKUv3gS0EevM1gzJYcqNBv3Ivs
Ew5hNcWjvQB8ok90R9ri6ti7V3XD0L/WiElxdbpfR8UeC2dNG3bvNaLJdl0vUQC4
nnYYN9rqWmAjEyAvj9dOhOllHRLO2zZD9zqC0P95xoZhsuGIF/qZU3yXrnfgdcZU
ZuJwn7lQBWFndy4OTGmLdhpGgWfQi/PXhGy7vhTo4812Edg19Ej6hjjn4/NvOINR
Cct2FavUaWWnc/ZuvgUywkdoapwQSBKJqyLdMhHZULp1aKfHQ3dHYCqHnWT8XNI5
gp0zYIZIYp3cwZv4HNzTOjYfkLI5YOFHswdpp9CRvMvo+7Pw5b0cnAYufoteJLld
iRyVW62pFJabx0ib9C2zRy/VbnrJTwYWkLABixwArNSB6FI6mQtHPs4HsWiMAV5v
LOMCMWckaH0rtTq/wtRrbO+HNTFHUfyQR9hd3/LYXomfTF4+MoAk+OPJMxH3wHwx
PoNDjre/H+cA8BzuBZLNfTh2lhy0JB3Od2h3R6W0KLdJM7w/pnk=
=yO1H
—–END PGP SIGNATURE—–


