CTIPilot

Oracle Fusion Middleware

product · product:oracle-fusion-middleware

Coverage timeline
2
first 2026-07-26 → last 2026-08-20
Peak priority
high
1 high · 1 notable
Sources cited
7
6 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/oracle-august-2026-cpu-three-unauthenticated-cvss-10 · 2026-07-26/oracle-july-2026-cpu-fusion-middleware-cvss10-unauth · ATT&CK page ↗

Story timeline

  1. 2026-08-20Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory
    trending-vulnerabilities943 patches in a monthly release, and the ones that decide the sequencing are the three needing no credential and no user interaction at all
  2. 2026-07-26Oracle July 2026 CPU, nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term
    trending-vulnerabilitiesTwo national CERTs escalated the July Oracle cycle: 219 of the Fusion Middleware fixes need no authentication at all

Where this entity is cited

  • trending-vulnerabilities2

Source distribution

  • oracle.com2 (29%)
  • advisories.ncsc.nl1 (14%)
  • cert.ssi.gouv.fr1 (14%)
  • csoonline.com1 (14%)
  • security-hub.ncsc.admin.ch1 (14%)
  • securityweek.com1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Oracle Fusion Middleware (2)

2026-08-20 · view entry permalink →

Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory

Oracle published its August 2026 Critical Security Patch Update on 2026-08-18, stating that it "contains 943 new security patches across the product families listed below" (Oracle, 2026-08-18); Switzerland's NCSC put it in front of its own constituency the next day (NCSC-CH, 2026-08-19). This is worth naming precisely, because the release type sets the patch window: a Critical Security Patch Update is Oracle's monthly release (the page states that security patches ship on the third Tuesday of each month and lists 15 September 2026 as the next one) and it is a distinct thing from the quarterly cumulative Critical Patch Update it complements, the next of which is 20 October 2026 (Oracle, 2026-08-18). An estate that treats this as the quarterly cycle will both misjudge how soon the next batch lands and, more importantly, wait a quarter for fixes that are already out. Most of a release this size is still routine maintenance; what takes a handful of items past routine is their own mechanics, and those are not in the families with the largest counts.

Three CVEs in the release carry a CVSS 3.1 base score of 10.0, and in Oracle's own risk matrices all three record Privileges Required as None, User Interaction as None, and Scope as Changed, an anonymous, single-request path to full compromise of the component and beyond it. CVE-2026-61241 is in the OID LDAP Server component of Oracle Internet Directory, reachable over LDAP, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The other two, CVE-2026-70880 and CVE-2026-70921, are in the Access and security component of Hyperion Data Relationship Management (reachable over TCP) and the Security component of Hyperion Financial Management (reachable over TLS), both at 11.2.25.0.000 (Oracle, 2026-08-18). The Internet Directory flaw is the one that should move first in a public-sector estate: an LDAP directory server is identity infrastructure, it is normally reachable from every application that authenticates against it, and a scope-changed compromise of it is not contained to the directory.

The concentration behind those three is what makes the sequencing work non-trivial. Oracle records 262 new patches for Fusion Middleware, of which it states 182 "may be remotely exploitable without authentication", and 120 for E-Business Suite, of which 27 may be; Hyperion carries 262 patches with 107 in that category (Oracle, 2026-08-18). Within E-Business Suite the two highest-scored unauthenticated flaws sit on inbound processing paths that an internet-facing deployment exposes by design, CVE-2026-60782 in the File Transmission component of Oracle Payments over HTTP, and CVE-2026-70926 in the Workflow Notification Mailer over SMTP, both 9.8. In Fusion Middleware, CVE-2026-60672 is an unauthenticated 9.8 in the WebLogic Server core reachable over T3 and IIOP, a protocol pair with a long history of public exploit work following Oracle releases.

No source fetched this run reports exploitation of any individual flaw in this cycle, and NCSC-CH's relay records exploitation status as unknown for the batch as a whole (NCSC-CH, 2026-08-19). Oracle's own advisory makes the point that matters more than any single score: it "continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches" (Oracle, 2026-08-18). For estates that cannot patch 943 items at once, the useful hardening step in the meantime is network placement rather than version: T3, IIOP, RMI, CORBA and LDAP listeners on middleware and directory hosts have no business being reachable from a general-purpose user network, and restricting them removes the reachability half of every unauthenticated flaw in this release regardless of which one is patched first.

This Critical Security Patch Update contains 943 new security patches across the product families listed below.

Oracle continues to periodically receive reports of attempts to maliciously exploit vulnerabilities for which Oracle has already released security patches. In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches.

Oracle 2026-08-18
vulnerability20 Aug 04:44Zmulti-sourceOpen finding ↗

2026-07-26 · view entry permalink →

NOTABLECVE-2026-47056 +2NATOA1

Oracle July 2026 CPU, nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term

Oracle's quarterly Critical Patch Update is normally exactly what the routine patch cycle exists to absorb, and most of the July 2026 release is. What separates this one is a concentration that two national CERTs judged worth their own advisories inside the following week. On Oracle's own account, "This Critical Patch Update contains 355 new security patches , plus additional third party patches noted below, for Oracle Fusion Middleware. 219 of these vulnerabilities may be remotely exploitable without authentication" (Oracle, 2026-07-16); CSOonline reports the same split, noting that "Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials" (CSOonline, 2026-07-22).

Two counts differ between the sources, and the difference is worth knowing before you brief anyone. NCSC-NL states that the most severe vulnerabilities, nine of them, received the highest score of 10.0 (NCSC-NL, 2026-07-22), while press coverage says ten. Both are right about their own object: Oracle's Fusion Middleware risk matrix carries ten rows at base score 10.0 but only nine distinct CVE identifiers, because CVE-2026-60365 appears twice, once under Oracle HTTP Server and once under the WebLogic Server Proxy Plug-in (Oracle, 2026-07-16). NCSC-NL's total for the component also differs from Oracle's, 345 fixes against Oracle's 355. Nine distinct maximum-severity CVEs is the figure to use.

Each of the nine is reachable over a standard network protocol (HTTP, LDAP, SOAP, or raw TCP in Oracle Coherence's case) with no authentication and no user interaction. NCSC-NL's advisory lists the maximum-severity CVE identifiers, among them CVE-2026-47056 and CVE-2026-60217 (NCSC-NL, 2026-07-22); it does not itself pair those identifiers with products, so the pairing, the component names and the affected versions all come from Oracle's risk matrix rather than the advisory, Data Integrator 12.2.1.4.0 and 14.1.2.0.0 in the Rest Service component, and Coherence Core 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 (Oracle, 2026-07-16). The remaining maximum-severity cases sit across Oracle Access Manager, HTTP Server, Platform Security for Java, WebCenter Content, Service Delivery Platform, Unified Directory and the WebLogic Server Proxy Plug-in. On the database side CVE-2026-61211 (CVSS 9.9) abuses DBMS_CLOUD to reach full server control, though that one is post-authentication.

The escalation is the CERT assessment rather than any observed activity. NCSC-NL's advisory states that "Because of the large number and the severity of these vulnerabilities, the NCSC considers it very likely that large-scale abuse will take place in the short term" (NCSC-NL, 2026-07-22), and CERT-FR published its own advisory the following day (CERT-FR, 2026-07-23). To be precise about what is and is not known: there is no confirmed in-the-wild exploitation of any of the new CVEs, no public proof-of-concept code, and no reported scanning specific to them. This is a forward-looking assessment by two national authorities about an exposure class with a long history of rapid weaponisation, not a report of an active campaign.

Triage: with no public exploit detail there is no behavioural signature specific to these CVEs, and inventing one would be guesswork. What is available is exposure telemetry: enumerate which Fusion Middleware listeners answer from outside the perimeter, and in web-server and application logs for those hosts, treat unauthenticated requests to administrative or REST service paths from unfamiliar source ranges as the class worth reviewing while patching proceeds. Note that Coherence's cluster protocol is raw TCP rather than HTTP, so HTTP-layer inspection will not see it, that exposure has to be established from network policy rather than from application logs.

Door het grote aantal en de ernst van deze kwetsbaarheden acht het NCSC het zeer waarschijnlijk dat grootschalig misbruik op korte termijn plaats gaat vinden.

NCSC-NL (NCSC-2026-0252)

Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiring user credentials.

CSOonline 2026-07-22
vulnerability26 Jul 14:11Zmulti-sourceOpen finding ↗