T

Threats

Oracle Releases 943 Security Patches in August 2026 Update

Overview

  • Vendor: Oracle

  • Advisory: August 2026 Critical Security Patch Update

  • Severity: Critical

  • Initial publication: 18 August 2026

  • Latest revision reviewed: 20 August 2026

  • Security patches: 943

  • Key exposure: More than 460 vulnerabilities were reported as remotely exploitable without authentication.


Oracle's August 2026 Critical Security Patch Update covers a broad range of enterprise products. Fusion Middleware and Hyperion received 262 new patches each. Oracle also issued updates for E-Business Suite, Commerce, Siebel CRM, Supply Chain, Database Server, Java SE, MySQL, PeopleSoft, VM VirtualBox and other product families.

Oracle warns that attackers continue to target vulnerabilities for which patches are already available. Organisations should prioritise internet-facing systems and products that process untrusted network traffic.


Affected Versions

Oracle publishes affected versions at the individual product and CVE level in its risk matrices. Publicly confirmed examples include:

Oracle Database Products

  • Affected: Portable Clusterware 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3 for CVE-2026-71063 and CVE-2026-71064. Oracle Database Server 23.4.0-23.26.2 for CVE-2026-71062.

  • Fixed: Apply the August 2026 Oracle security patch applicable to the installed release. Oracle does not publish a single fixed build for all supported branches in the public advisory.

  • Not affected: Oracle states that the six new Database Products patches are not applicable to client-only installations without Oracle Database Server.

  • Source: Oracle Critical Security Patch Update Advisory - August 2026

Oracle E-Business Suite

  • Affected: Oracle E-Business Suite 12.2.3-12.2.15.

  • Fixed: Apply the August 2026 patches identified in Oracle's E-Business Suite Release 12 Critical Security Patch Update Knowledge Document, My Oracle Support Note KA923. Also patch the Oracle Database and Fusion Middleware components used by the deployment.

  • Not affected: Oracle has not identified a generally unaffected E-Business Suite configuration in the public advisory.

  • Source: Oracle Critical Security Patch Update Advisory - August 2026

Oracle Fusion Middleware Examples

  • Affected: Oracle Access Manager, Oracle Identity Manager, Oracle Identity Manager Connector and Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. Oracle Managed File Transfer and Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0.

  • Fixed: Apply the August 2026 Oracle security patches mapped to each installed component and release through My Oracle Support.

  • Not affected: The public advisory does not provide one unaffected configuration covering the full Fusion Middleware portfolio.

  • Source: Oracle Critical Security Patch Update Advisory - August 2026

Oracle Hyperion Example

  • Affected: Oracle Hyperion Calculation Manager 11.2.25.0.0.

  • Fixed: Apply the applicable August 2026 Oracle security patch through My Oracle Support.

  • Not affected: The public advisory does not identify a generally unaffected Hyperion configuration.

  • Source: Oracle Critical Security Patch Update Advisory - August 2026


Vulnerability Breakdown

CVE-2026-71063 - Oracle Portable Clusterware

  • Severity: Critical

  • CVSS: 9.6

  • Description: A vulnerability in Oracle Portable Clusterware can be reached over TLS from an adjacent network without authentication.

  • Impact: Successful exploitation can result in high-impact confidentiality, integrity and availability compromise.

  • Conditions: Adjacent network access. No privileges or user interaction are required.

  • Affected: 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3.

  • Source: Oracle August 2026 advisory entry for CVE-2026-71063

CVE-2026-71064 - Oracle Portable Clusterware

  • Severity: Critical

  • CVSS: 9.6

  • Description: A second vulnerability in Oracle Portable Clusterware can be reached over TLS from an adjacent network without authentication.

  • Impact: Successful exploitation can result in high-impact confidentiality, integrity and availability compromise.

  • Conditions: Adjacent network access. No privileges or user interaction are required.

  • Affected: 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3.

  • Source: Oracle August 2026 advisory entry for CVE-2026-71064

CVE-2026-60782 - Oracle Payments

  • Severity: Critical

  • CVSS: 9.8

  • Description: This vulnerability affects the File Transmission component of Oracle Payments and is remotely exploitable over HTTP without authentication.

  • Impact: Successful exploitation can result in high-impact confidentiality, integrity and availability compromise.

  • Conditions: Network access is required. No privileges or user interaction are required.

  • Affected: Oracle E-Business Suite 12.2.3-12.2.15.

  • Source: Oracle August 2026 advisory entry for CVE-2026-60782

CVE-2026-70926 - Oracle Workflow

  • Severity: Critical

  • CVSS: 9.8

  • Description: This vulnerability affects the Workflow Notification Mailer component and is remotely exploitable over SMTP without authentication.

  • Impact: Successful exploitation can result in high-impact confidentiality, integrity and availability compromise.

  • Conditions: Network access is required. No privileges or user interaction are required.

  • Affected: Oracle E-Business Suite 12.2.3-12.2.15.

  • Source: Oracle August 2026 advisory entry for CVE-2026-70926

CVE-2026-71062 - Oracle Database Server RDBMS

  • Severity: High

  • CVSS: 8.5

  • Description: This Oracle Database Server vulnerability is reachable over Oracle Net by an authenticated user with high privileges.

  • Impact: Successful exploitation can result in high-impact confidentiality, integrity and availability compromise.

  • Conditions: Network access and a high-privileged authenticated account are required. No user interaction is required.

  • Affected: 23.4.0-23.26.2. Oracle revised this range on 20 August 2026.

  • Source: Oracle August 2026 advisory entry for CVE-2026-71062


Mitigation

  • Inventory Oracle products, components and versions across the organisation.

  • Review the Oracle August 2026 risk matrices for every installed product.

  • Obtain the exact patches for supported releases through My Oracle Support.

  • Prioritise internet-facing systems and vulnerabilities that require no authentication.

  • Patch Oracle Database and Fusion Middleware components embedded in E-Business Suite and Enterprise Manager deployments.

  • Test patches in a controlled environment, then deploy through the organisation's emergency change process.

  • Restrict network access to exposed Oracle services until patching is complete.

  • Monitor Oracle services and authentication logs for suspicious activity.

  • Upgrade unsupported releases to a supported version before applying current patches.


Summary for IT Teams

  • Products: Oracle Fusion Middleware, Hyperion, E-Business Suite, Commerce, Siebel CRM, Supply Chain, Database Server, Java SE, MySQL, PeopleSoft, VM VirtualBox and other Oracle product families.

  • Threat Level: Critical, with some vulnerabilities rated up to CVSS 10.0.

  • Action Required: Identify affected Oracle deployments, consult the product-specific risk matrix and My Oracle Support patch document, then apply the August 2026 updates without delay.


Need Help?

Secure ISS can help your organisation assess Oracle exposure, prioritise remediation and validate patch deployment. Contact us on 1300 769 460.


Reference

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.