Critical Security Vulnerabilities (CVSS > 9.5) – Impact on ERP Cloud, OCI, OIC and ADFdi (July 2026
Summary:
Dear Community, we received a security alert for following relevant CVEs.
CVE-2026-60880 (Oracle E-Business Suite – Work in Process)
CVE-2026-60198 (Oracle WebLogic Server – T3/IIOP)
CVE-2026-60199 (Oracle WebLogic Server – HTTP)
CVE-2026-60200 (Oracle WebLogic Server – SOAP)
CVE-2026-60262 (Oracle Coherence – Fusion Middleware)
CVE-2026-60367 (Oracle Platform Security for Java)
Our Environment:
Oracle ERP Cloud (Fusion Applications – SaaS)
Oracle Cloud Infrastructure (OCI) services: Functions, free db pass, buckets
Integration components ( OIC3, REST/SOAP ERP services, VBCS embedded )
Usage of ADF Desktop Integration (ADFdi) Excel templates for data import/export
Our Concern
We understand that Oracle manages patching for SaaS and OCI services; however, due to the severity of these vulnerabilities (CVSS ≥ 9.5), we require clarification for our specific environment.