Critical Security Vulnerabilities (CVSS > 9.5) – (July 2026 CPU)
in Middleware
Problem Description:
We have received an official security alert from Costa Rica CSIRT (MICITT) regarding multiple critical vulnerabilities affecting Oracle products, published as part of the July 2026 Critical Patch Update (CPU).
The alert identifies several vulnerabilities with CVSS scores ≥ 9.8, which allow remote code execution (RCE) without authentication, potentially compromising the confidentiality, integrity, and availability of systems.
Relevant CVEs (from advisory):
- CVE-2026-60880 (Oracle E-Business Suite – Work in Process)
- CVE-2026-60198 (Oracle WebLogic Server – T3/IIOP)
- CVE-2026-60199 (Oracle WebLogic Server – HTTP)
- CVE-2026-60200 (Oracle WebLogic Server – SOAP)
- CVE-2026-60262 (Oracle Coherence – Fusion Middleware)
- CVE-2026-60367 (Oracle Platform Security for Java)
Tagged:
0