Oracle E-Business Suite, Oracle Workflow (Workflow Notification Mailer), unauthenticated flaw over SMTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.
cve · CVE-2026-70926
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-70926, newest first. Check the date before acting on an older one.
- Sequence this release by unauthenticated network exposure rather than by product owner, and note it is Oracle's monthly Critical Security Patch Update, not the quarterly cumulative one, so the next release is 15 September: the three flaws Oracle scores 10.0, CVE-2026-61241 in the Oracle Internet Directory LDAP server, CVE-2026-70880 and CVE-2026-70921 in Hyperion Data Relationship Management and Financial Management; all carry Privileges Required: None and User Interaction: None in Oracle's own matrix, so any instance of those three reachable from a user network or the internet is the first patch, ahead of the higher-count families.2026-08-20CVE-2026-61241 +5
Defender insights
What each entry about CVE-2026-70926 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-20/oracle-august-2026-cpu-three-unauthenticated-cvss-10 · ATT&CK page ↗
Entries about Oracle E-Business Suite, Oracle Workflow (Workflow Notification Mailer), unauthenticated flaw over SMTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Oracle E-Business Suite×1
- Oracle E-Business Suite, Oracle Payments (File Transmission), unauthenticated flaw over HTTP, CVSS 9.8, EBS 12.2.3-12.2.15; August 2026 Critical Security Patch Update.×1
- Oracle Fusion Middleware×1
- Oracle Hyperion Data Relationship Management×1
- Oracle Hyperion Data Relationship Management (Access and security), unauthenticated flaw over TCP, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.×1
- Oracle Hyperion Financial Management×1
- Oracle Hyperion Financial Management (Security), unauthenticated flaw over TLS, CVSS 3.1 base 10.0; August 2026 Critical Security Patch Update.×1
- Oracle Internet Directory×1
Where this entity is cited
Source distribution
- oracle.com1 (33%)
- security-hub.ncsc.admin.ch1 (33%)
- securityweek.com1 (33%)
External references
All cited sources (3)
- oracle.comprimaryOraclehttps://www.oracle.com/security-alerts/cspuaug2026.html
- security-hub.ncsc.admin.chNCSC Switzerland, Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12862
- securityweek.comSecurityWeekhttps://www.securityweek.com/943-patches-rolled-out-with-oracles-august-2026-security-update/