URGENT ACTION RECOMMENDED
For Waratek customers and prospects
Highlights
Advisory scope: 943 new security patches across 23 product families. Several vulnerabilities affect more than one product, so a single CVE can appear in multiple risk matrices. Severity counts below are Waratek’s tally of the rows published in Oracle’s risk matrices.
- 943 new security patches, against 245 in the June CSPU and 35 in the first CSPU on 28 May 2026. August is the largest monthly security release Oracle has published, and is roughly two thirds the size of the record 1,448-patch July quarterly CPU.
- 467 of the 943 patches, just under half the release, address vulnerabilities Oracle describes as remotely exploitable without authentication, meaning no credentials are required.
- 154 patches carry a CVSS base score of 9.0 or higher, and 131 of those 154 are remotely exploitable without authentication. Roughly 85 percent of the critical scoring issues in this release need no credentials at all.
- Three vulnerabilities score a full 10.0, all of them unauthenticated: CVE-2026-61241 in Oracle Internet Directory, and CVE-2026-70880 and CVE-2026-70921 in Hyperion Data Relationship Management and Hyperion Financial Management.
- Fusion Middleware receives 262 patches, 182 of them unauthenticated and 78 scoring 9.0 or above. It alone accounts for 39 percent of the unauthenticated remote issues and just over half the critical scoring ones in this CSPU.
- Hyperion also receives 262 patches, 107 unauthenticated, 27 scoring 9.0 or above, after receiving no product specific entries in the July CPU.
- E-Business Suite receives 120 patches, 27 unauthenticated, across versions 12.2.3 through 12.2.15. Both of its 9.8 rated issues are unauthenticated, and one of them sits in the same Oracle Payments File Transmission component as CVE-2026-46817, which is in the CISA Known Exploited Vulnerabilities catalog.
- PeopleSoft receives 15 patches, 7 unauthenticated, now covering PeopleTools 8.61 through 8.63. Its single 9.8 is CVE-2026-60821 in the Business Interlink component.
- Java SE receives 5 patches, 4 of them unauthenticated, with a ceiling of 7.8. The severity profile is far lower than the application families that run on the JVM.
- No vulnerability first disclosed in this CSPU has been publicly confirmed as under active exploitation as of publication. Previously exploited flaws are rolled into some of these patches, and two CISA KEV-listed Oracle vulnerabilities affect product families covered here.
Patch volume by product family
| Product family | Patches | Remote, no auth | Highest CVSS |
|---|---|---|---|
| Oracle Fusion Middleware | 262 | 182 | 10.0 |
| Oracle Hyperion | 262 | 107 | 10.0 |
| Oracle E-Business Suite | 120 | 27 | 9.8 |
| Oracle Commerce | 66 | 47 | 9.8 |
| Oracle Siebel CRM | 50 | 21 | 9.9 |
| Oracle Supply Chain | 46 | 18 | 9.8 |
| Oracle Virtualization (VirtualBox) | 21 | 2 | 8.6 |
| Oracle Analytics | 16 | 3 | 9.9 |
| Oracle PeopleSoft | 15 | 7 | 9.8 |
| Oracle Communications | 13 | 9 | 9.8 |
| Oracle Enterprise Manager | 11 | 6 | 9.1 |
| Oracle MySQL | 9 | 5 | 8.2 |
| Oracle Financial Services Applications | 8 | 6 | 9.1 |
| Oracle Application Testing Suite | 7 | 3 | 9.1 |
| Oracle Autonomous Health Framework | 7 | 2 | 8.8 |
| Oracle Database Server | 6 | 4 | 9.6 |
| Oracle JD Edwards | 6 | 2 | 9.8 |
| Oracle Java SE | 5 | 4 | 7.8 |
| Oracle Retail Applications | 5 | 5 | 7.5 |
| Oracle Essbase | 4 | 3 | 9.8 |
| Oracle Food and Beverage (Simphony) | 2 | 2 | 9.1 |
| Oracle Construction and Engineering | 1 | 1 | 8.2 |
| Oracle Hospitality (OPERA 5) | 1 | 1 | 8.8 |
| Total | 943 | 467 | 10.0 |
Source: Oracle risk matrices, August 2026 CSPU, Revision 1. Counts are new security patches, not unique CVEs.
Highest severity vulnerabilities
The table below lists the 10.0 and 9.9 rated entries in full, together with representative 9.8 and 9.6 entries from the product families most likely to be internet reachable. It is a selection, not the complete set of 154 patches scoring 9.0 or above.
| CVE ID | Product and component | Family | No auth | CVSS |
|---|---|---|---|---|
| CVE-2026-61241 | Internet Directory, OID LDAP Server | Fusion Middleware | Yes | 10.0 |
| CVE-2026-70880 | Data Relationship Management, Access and security | Hyperion | Yes | 10.0 |
| CVE-2026-70921 | Financial Management, Security | Hyperion | Yes | 10.0 |
| CVE-2026-73930 | Helidon, Imperative Web Server | Fusion Middleware | Yes | 9.9 |
| CVE-2026-60916 | WebCenter Enterprise Capture, Client Bundle | Fusion Middleware | Yes | 9.9 |
| CVE-2026-60702 | WebLogic Server, Core (T3, IIOP) | Fusion Middleware | No | 9.9 |
| CVE-2026-60720 | Identity Manager, OIM Legacy UI | Fusion Middleware | No | 9.9 |
| CVE-2026-61003 | Managed File Transfer, MFT Runtime Server | Fusion Middleware | No | 9.9 |
| CVE-2026-61021 | WebCenter Sites | Fusion Middleware | No | 9.9 |
| CVE-2026-61206 | Calculation Manager, Security | Hyperion | No | 9.9 |
| CVE-2026-71059 | BI Publisher, Web Service API | Analytics | No | 9.9 |
| CVE-2026-60698 | WebLogic Server, Core (IIOP) | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60672 | WebLogic Server, Core (T3, IIOP) | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60696 | WebLogic Server, Core (T3, IIOP) | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60977 | WebLogic Server, WLS Core Components (RMI) | Fusion Middleware | Yes | 9.8 |
| CVE-2026-70905 | Access Manager, Agent infrastructure (SAML) | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60721 | Identity Manager, OIM Legacy UI | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60727 | Identity Manager, OIM Legacy UI | Fusion Middleware | Yes | 9.8 |
| CVE-2026-60782 | Oracle Payments, File Transmission | E-Business Suite | Yes | 9.8 |
| CVE-2026-70926 | Oracle Workflow, Notification Mailer (SMTP) | E-Business Suite | Yes | 9.8 |
| CVE-2026-60821 | PeopleTools, Business Interlink | PeopleSoft | Yes | 9.8 |
| CVE-2023-50164 | Infrastructure Technology (Apache Struts) | Hyperion | Yes | 9.8 |
| CVE-2026-71040 | Agile PLM, Security | Supply Chain | Yes | 9.8 |
| CVE-2026-70995 | Guided Search, Endeca Application Controller | Commerce | Yes | 9.8 |
| CVE-2026-71063 | Portable Clusterware (TLS) | Database Server | Yes | 9.6 |
Source: Oracle risk matrices, August 2026 CSPU, Revision 1.
Family level analysis
Oracle Fusion Middleware
Fusion Middleware is the dominant risk surface in this release, with 262 patches, 182 of them unauthenticated, and 78 scoring 9.0 or above. Roughly 69 percent of its patches require no credentials.
The single 10.0 is CVE-2026-61241 in the Oracle Internet Directory LDAP Server. It is unauthenticated, low complexity, scope changing, and rated High for confidentiality, integrity and availability. A directory service compromise is not contained to the directory, since scope change means the attacker reaches beyond the vulnerable component into whatever trusts it for identity.
WebLogic Server carries four unauthenticated 9.8 issues in its core: CVE-2026-60698 over IIOP, CVE-2026-60672 and CVE-2026-60696 over T3 and IIOP, and CVE-2026-60977 over RMI, plus a 9.9 authenticated core issue in CVE-2026-60702. The affected range runs from 12.2.1.4.0 through 15.1.1.0.0. T3, IIOP and RMI are the classic Java deserialization channels for this product, and any deployment exposing those ports beyond a trusted management network should be treated as urgent.
Identity infrastructure is heavily represented. Access Manager has an unauthenticated 9.8 in its SAML agent path (CVE-2026-70905). Identity Manager has two unauthenticated 9.8 issues (CVE-2026-60721 and CVE-2026-60727) and two authenticated 9.9 issues. Internet Directory adds an unauthenticated 9.8 (CVE-2026-61258) alongside its 10.0.
Two volume drivers are worth calling out because they can distort a simple patch count. Oracle Reports Developer contributes a large block of unauthenticated 9.8 entries spread across HTTP, IIOP, CORBA, TCP and UDP in its Security and Authentication component. Helidon contributes a long tail of web server issues ranging from 9.9 down to 3.7. Both matter, but neither should displace WebLogic and the identity products in a triage order built on likely internet exposure.
Several patches in this family also close previously known and in some cases previously exploited flaws. The fix for CVE-2026-60727 also addresses CVE-2025-61757, the Identity Manager authentication bypass confirmed exploited in the wild last year. The fix for CVE-2026-60679 also addresses CVE-2023-21839 and CVE-2024-20931, both long standing WebLogic issues with public exploit history. The fix for CVE-2026-61001 also addresses CVE-2026-21992. Anyone who deferred those earlier patches inherits them here.
Oracle E-Business Suite
EBS receives 120 patches, 27 unauthenticated, across 12.2.3 through 12.2.15. Only two entries reach 9.8, but both are unauthenticated and both deserve priority.
CVE-2026-60782 is an unauthenticated 9.8 in the File Transmission component of Oracle Payments. That is the same product and component as CVE-2026-46817, which Oracle fixed in the May 2026 CSPU and which CISA added to the Known Exploited Vulnerabilities catalog on 15 July with a three day federal remediation deadline. The August matrix contains six Oracle Payments File Transmission entries in total, at 9.8, 8.2, 7.7, 7.7, 7.5 and 7.4. A component with a demonstrated attacker following and a fresh unauthenticated critical should be first in the EBS queue.
CVE-2026-70926 is an unauthenticated 9.8 in the Workflow Notification Mailer, reachable over SMTP. Mail paths into ERP are frequently overlooked in exposure reviews because attention concentrates on HTTP.
The remainder of the EBS matrix is a broad sweep of authenticated 8.8 and 8.1 issues across Payroll, Purchasing, General Ledger, Risk Management, HRMS and dozens of other modules. These matter for insider and post compromise risk rather than perimeter risk. Oracle also restates that EBS inherits exposure from its Database and Fusion Middleware components, and that those patches should be applied alongside the EBS specific fixes.
Oracle PeopleSoft
PeopleSoft receives 15 patches, 7 unauthenticated, with a ceiling of 9.8, now covering PeopleTools 8.61 through 8.63 plus several Enterprise application modules. The count is modest, but this remains the family with the most credible current threat because it is the platform under named adversary attention.
CVE-2026-60821 is the single 9.8, unauthenticated and low complexity, in the PeopleTools Business Interlink component. Two further unauthenticated issues sit in the integration layer that the 2026 intrusion campaign used: CVE-2026-60831 in Integration Broker at 8.1, and CVE-2026-60742 in PIA Core Technology at 8.1. Integration Broker is reached through the /PSIGW/ path that appears in the published indicators for the ShinyHunters campaign, so any organization that hardened those endpoints in June should verify their controls still hold after patching.
One version note matters. PeopleTools 8.63 is in scope for most of these entries, while CVE-2026-60975 is scoped only to 8.61 and 8.62. Organizations that scoped their June remediation to the two versions named in the CVE-2026-35273 alert should confirm coverage on 8.63.
Oracle Java SE
Java SE receives 5 patches, 4 of them unauthenticated, affecting Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4 and 26.0.2, plus GraalVM for JDK 17.0.20 and 21.0.12 and GraalVM Enterprise Edition 21.3.19.
The highest score is 7.8 for CVE-2026-62574 in the Install component, which is a local vector and not a network exposure. The unauthenticated entries are CVE-2026-70906 in 2D at 7.5, affecting availability only, CVE-2026-61308 in Networking at 6.8, which is scope changing with High confidentiality impact, CVE-2026-70907 in JSSE at 5.3 and CVE-2026-60589 in Security at 3.7. Oracle notes that these scores assume a user running with administrator privileges, and that impact drops on systems where that is not the case.
The JDK is therefore a normal cycle item this month. The structural point is more important than the severity one. Fusion Middleware, WebLogic, Helidon, Hyperion, PeopleTools and E-Business Suite all execute on the JVM, so the Java runtime is the layer on which the 10.0 and 9.8 rated issues in this advisory actually run, even though the Java SE section itself tops out at 7.8.
Vulnerabilities under active exploitation
As of publication, no vulnerability first disclosed in the August CSPU has been publicly confirmed as exploited in the wild. Two previously disclosed flaws in products covered by this release remain the practical threat picture, and one of this month’s critical issues lands in a component with recent exploitation history.
CVE-2026-35273, PeopleSoft Enterprise PeopleTools, CVSS 9.8
An unauthenticated flaw in the Updates Environment Management component, classified as server side request forgery and chained to remote code execution. Mandiant dated exploitation to 27 May through 9 June 2026, ahead of Oracle’s out of band alert on 10 June, making it a true zero day for the duration of the campaign. Reporting attributes it to the ShinyHunters extortion group, tracked as UNC6240, with more than 100 organizations notified and roughly two thirds of them in higher education. The published attack chain runs from SSRF to code execution, then to remote management agents for persistence, credential harvesting from psappsrv.cfg, credential spraying for lateral movement, and SMB based NetNTLM hash capture. CISA addressed it under Binding Operational Directive 26-04.
CVE-2026-46817, Oracle E-Business Suite, CVSS 9.8
An improper privilege management flaw in the File Transmission component of Oracle Payments allowing an unauthenticated attacker with HTTP access to take over the component. Fixed in the May 2026 CSPU and added to the CISA Known Exploited Vulnerabilities catalog on 15 July with a three day remediation deadline of 18 July. CVE-2026-60782 in this month’s advisory is a new unauthenticated 9.8 in that same component.
The pattern across both is consistent. In each case the exploitation activity either preceded the patch or continued well after it shipped. A patch that exists but has not yet cleared regression testing provides no protection, and neither does one applied to a system that was already compromised during the exposure window.
Waratek recommends a defense in depth posture for these attack chains, so that there are multiple points at which an attack can be intercepted rather than a single dependency on patch availability and deployment speed. Waratek customers who need assistance identifying or enabling the relevant controls should contact our Customer Success team.
Rising volume and an accelerating release cadence
The 2026 trend line is unambiguous. The first CSPU on 28 May carried 35 patches. June carried 245. August carries 943, close to four times the June figure. The July quarterly CPU carried 1,448, the largest Oracle has issued. Oracle now publishes security content on the third Tuesday of every month. The dates named in this advisory are 15 September 2026 for the next CSPU, 20 October 2026 for the quarterly CPU, then CSPUs on 17 November and 15 December.
The credit statement in this advisory is instructive about where the volume originates. External researchers and coordinated disclosure programs are credited with roughly 34 CVEs out of 943 patches, and a substantial share of those sit in the VirtualBox matrix. The enterprise application families that carry almost all of the critical scoring, unauthenticated issues are overwhelmingly the product of Oracle’s internal discovery, which the company attributes in part to AI assisted identification of actionable security findings alongside expanded coverage and accelerated security engineering.
That cuts both ways. The same class of automation that lets a vendor surface and fix hundreds of issues per month is available to adversaries for discovery, triage and weaponization, and the PeopleSoft campaign showed how little time separates discovery from mass exploitation when the target is an internet facing ERP platform. Machine assisted discovery compounds human research rather than replacing it, and the combined output lands on defenders who still have to validate every change against production business logic.
The arithmetic is the problem. A monthly release of 943 patches across 23 product families, roughly half of them unauthenticated and remote, with 154 at 9.0 or above, exceeds what most enterprise change control processes can regression test in a 30-day window. Multi-tier estates such as E-Business Suite, PeopleSoft and Hyperion require coordinated updates across web, application and database layers with testing at each step, and this month those three families alone account for 397 patches. The gap between disclosure and safe deployment is where breaches occur, and on the current trajectory that gap is widening.
How Waratek addresses the risk
Waratek RASP operates inside the Java Virtual Machine rather than at the network perimeter. Because it enforces on what the application is actually doing at runtime, it addresses classes of unsafe behavior including deserialization of untrusted data, server-side request forgery, path traversal, command injection, JNDI and LDAP lookups, SQL injection and XML external entity processing.
That distinction matters for this release in particular. The WebLogic T3, IIOP and RMI issues, the LDAP path in Internet Directory, the Struts and Log4j entries in Hyperion and the SSRF chain used against PeopleSoft are all recognizable behavior classes rather than isolated one-off defects. Coverage organized around behavior applies equally to a vulnerability published this morning, one not yet published, and one produced by an automated discovery pipeline rather than a human researcher.
Virtual rules and patching supply the one thing the current cadence removes, which is time. Waratek applies compensating controls with no source code changes, no recompilation and no downtime, so exposure can be reduced on the day an advisory lands while regression testing and vendor patching proceed on a schedule the business can absorb. That is directly relevant to Fusion Middleware 12.2.1.4.0 estates approaching end of support, to Hyperion 11.2 deployments that were not expecting a 262-patch month, and to E-Business Suite and PeopleSoft environments where coordinated multi-tier patching realistically takes weeks.
Waratek customers should contact our Customer Success team for guidance on which existing RASP rules already cover the vulnerability classes represented in the August 2026 CSPU.
Frequently asked questions
What is a Critical Security Patch Update and how does it differ from a Critical Patch Update?
A CSPU is a targeted monthly release of high-priority security fixes in a smaller and more focused format than the quarterly cumulative Critical Patch Update. Oracle introduced the CSPU in May 2026 to complement rather than replace the quarterly CPU. For customers who follow the monthly cadence, critical fixes can be closed in roughly 30 days instead of waiting up to 90.
Why is the August CSPU so much larger than June’s?
It carries 943 patches against 245 in June. Two families drive most of the increase: Fusion Middleware and Hyperion contribute 262 each, together 56 percent of the release. Oracle attributes the broader growth to expanded product coverage, accelerated security engineering and AI assisted identification of security findings.
Is anything in this release under active exploitation right now?
Nothing first disclosed in the August CSPU has been publicly confirmed as exploited as of publication. CVE-2026-35273 in PeopleSoft PeopleTools and CVE-2026-46817 in E-Business Suite Oracle Payments are confirmed exploited, affect products patched in this release, and should be verified as remediated first. Note also that CVE-2026-60782, a new unauthenticated 9.8 this month, sits in the same Oracle Payments File Transmission component as the KEV listed CVE-2026-46817.
We patched PeopleTools for CVE-2026-35273 in June. Are we covered?
Not necessarily. The June out of band alert covered PeopleTools 8.61 and 8.62. Most August PeopleSoft entries cover 8.61 through 8.63, so confirm your current release is patched. Separately, any instance that was internet facing and unpatched between 27 May and 9 June should be investigated for compromise regardless of its current patch level, because patching does not evict an attacker who is already resident.
Should we prioritize the three 10.0 issues first?
Prioritize by exposure and exploitation status first, and by score second. Verify remediation of the confirmed exploited PeopleSoft and E-Business Suite flaws, then take the unauthenticated criticals on anything internet reachable. In practice that means WebLogic where T3, IIOP or RMI are exposed, Internet Directory and the identity products, the Oracle Payments component in E-Business Suite, and PeopleTools Business Interlink and Integration Broker. The Hyperion 10.0 issues follow closely, weighted by whether Data Relationship Management and Financial Management are reachable from outside the application tier.
Is Java SE urgent this month?
Not on severity grounds. Its highest score is 7.8 and that entry has a local attack vector, while the unauthenticated network issues top out at 7.5 with availability impact. Apply on a normal cycle unless you run long lived JVMs, mutual TLS or JNDI lookups against untrusted input. The caveat is structural rather than severity based: the JVM is the execution layer for the products that do carry the critical issues.
We cannot regression test 943 patches within the monthly window. What are our options?
Prioritize internet facing and unauthenticated attack surface first, since 467 of the 943 patches address issues exploitable with no credentials and 131 of those score 9.0 or above. Establish compensating controls for what you cannot patch immediately so the exposure window is covered while testing proceeds. Runtime protection is designed for exactly this gap, reducing risk on day one without a code change or an outage.
For More Information
Waratek customers should contact customersuccess@waratek.com for guidance on which RASP rules already cover CVEs in the August 2026 CSPU.
Prospects evaluating Waratek can contact sales@waratek.com for a protection assessment.
For assistance enabling recommended configurations, contact support@waratek.com.
Source advisory: https://www.oracle.com/security-alerts/cspuaug2026.html
This bulletin is a security news summary compiled by Waratek for customers and prospects from Oracle’s published advisory and from public reporting on active exploitation. It is not an official Oracle publication. All Oracle product names are trademarks of Oracle.
About Waratek
Waratek offers Waratek IAST+RASP, the only compiler-based, runtime application tools that find vulnerabilities in the pre-production development pipeline, block attacks in production, and virtually patch flaws with no downtime or source code changes. Waratek IAST watches code execute to identify security flaws with absolute certainty, eliminating the “guesswork” and alert fatigue associated with traditional scanners. Waratek RASP intercepts and terminates unsafe operations at the JVM level, stopping attempts to change app behavior in attacks aimed at known and Zero Day vulnerabilities. Waratek is a trusted partner for organizations in global financial services, hospitality, healthcare, technology and other industries. Waratek has offices in Dublin, Ireland and Chicago, Illinois.