Security Digest: July 31, 2026 - 4 Critical Vulnerabilities

Oracle has disclosed four serious vulnerabilities in Oracle E-Business Suite that can expose sensitive HR data and, in one case, enable full takeover of a configuration workbench. Three of the issues are reachable over the network via HTTP and affect supported versions 12.2.3 through 12.2.15; one requires high privileges, but still carries broad impact if exploited.

· 9 min read

Oracle E-Business Suite flaws demand immediate patching: 4 high-risk vulnerabilities exposed

Executive Summary

Oracle has disclosed four serious vulnerabilities in Oracle E-Business Suite that can expose sensitive HR data and, in one case, enable full takeover of a configuration workbench. Three of the issues are reachable over the network via HTTP and affect supported versions 12.2.3 through 12.2.15; one requires high privileges, but still carries broad impact if exploited.

Action required now: prioritize emergency patching, restrict access to E-Business Suite application endpoints, and verify whether any HR or HCM modules are exposed beyond trusted administrative networks.

Critical Vulnerabilities

CVE-2026-60966: Oracle Public Sector Human Resources regression testing flaw

  • Impact: A low-privileged attacker with network access via HTTP could read, change, or delete critical HR data. Oracle rates this as CVSS 8.1.
  • Affected Systems: Oracle E-Business Suite 12.2.3-12.2.15, Oracle Public Sector Human Resources component (Regression Testing).
  • Immediate Action: Treat as an active patch priority for any environment using Oracle Public Sector HR. Restrict HTTP access to the application now and review whether the module is internet-reachable or available to broad internal networks.
  • Mitigation: Apply Oracle’s security update as soon as it is available for your release line. If patching is delayed, place the application behind strict network controls and limit user privileges to the minimum required.

CVE-2026-60982: Oracle US Federal Human Resources internal operations flaw

  • Impact: A low-privileged attacker with network access via HTTP could compromise Oracle US Federal Human Resources and access or alter critical data. CVSS 8.1.
  • Affected Systems: Oracle E-Business Suite 12.2.3-12.2.15, Oracle US Federal Human Resources component (Internal Operations).
  • Immediate Action: Confirm whether this module is deployed anywhere in production, test, or shared service environments. If yes, move patching to the top of today’s queue and block non-administrative access immediately.
  • Mitigation: Install Oracle’s fixed release when published. Until then, enforce strict segmentation, disable unnecessary external access, and monitor for unusual HR data changes.

CVE-2026-60965: Oracle HRMS (France) data exposure and modification flaw

  • Impact: A low-privileged attacker with network access via HTTP could gain unauthorized access to HRMS (France) data and potentially modify or delete records. CVSS 8.1.
  • Affected Systems: Oracle E-Business Suite 12.2.3-12.2.15, Oracle Human Resources Management System (France).
  • Immediate Action: If your organization uses French HR functionality, assume this is high risk for sensitive employee data. Verify exposure, patch quickly, and tighten access controls around the HRMS application tier.
  • Mitigation: Apply Oracle’s update when available. Until then, limit access to trusted administrators and business users only, and review logs for suspicious HR record activity.

CVE-2026-60900: Oracle HCM Configuration Workbench takeover risk

  • Impact: A high-privileged attacker with network access via HTTP could take over Oracle HCM Configuration Workbench. Oracle rates this CVSS 7.2, with potential impact to confidentiality, integrity, and availability.
  • Affected Systems: Oracle E-Business Suite 12.2.3-12.2.15, Oracle HCM Configuration Workbench (Rapid Implementation).
  • Immediate Action: Audit who has high-privilege access right now. Remove standing admin rights where possible, and ensure only essential staff can reach the workbench over HTTP.
  • Mitigation: Patch as soon as Oracle provides remediation. In the meantime, enforce privileged-access controls, restrict network paths, and review configuration changes for tampering.

Previously Alerted

What to Do Now

  1. Patch Oracle E-Business Suite immediately for all affected HR/HCM modules on versions 12.2.3-12.2.15.
  2. Restrict HTTP access now to trusted administrative networks only; remove any public exposure.
  3. Review privileged accounts tied to HCM Configuration Workbench and HR modules; reduce standing access.
  4. Check logs for suspicious HR changes, especially unauthorized record creation, deletion, or modification.
  5. Verify asset inventory to identify every Oracle E-Business Suite instance, including test and DR systems.

Verification steps: confirm installed E-Business Suite release, validate which HR/HCM components are enabled, and document whether any instance is reachable outside your trusted network. If you cannot prove it is isolated, assume exposure.

Monitoring recommendations: watch for unusual login patterns, privilege escalation, bulk HR data exports, and configuration changes in the workbench. Increase alerting on application-tier web traffic and admin actions until patching is complete.

Related Resources

  • Internal blog posts: Oracle E-Business Suite emergency response guidance; HR/HCM exposure checklist; privileged access hardening for application tiers.
  • Official vendor advisories: Oracle Critical Patch Update advisory for July 2026; Oracle E-Business Suite security documentation and release notes.

Keep reading