Weekly Security Roundup (2026-07-24-to-2026-07-31)
Your end-of-week security briefing: top CVEs and immediate priorities.
· 7 min read
Here’s your weekly security roundup covering the last 7 days of digests and alerts. This week was dominated by Oracle-related disclosures, with multiple critical issues affecting enterprise applications, plus a high-severity Netty flaw that could be abused for memory exhaustion. If you run any of the affected products, treat patching as urgent.
Top Priorities
- CVE-2026-60663 — Critical alert with a maximum CVSS of 9.9. Immediate action recommended. Read alert
- CVE-2026-60880 — Critical alert with a maximum CVSS of 9.8. Immediate action recommended. Read alert
- CVE-2026-60999 — Critical alert with a maximum CVSS of 9.8. Immediate action recommended. Read alert
- Oracle July 24 digest — Nine critical and high-severity vulnerabilities across BI Publisher, Siebel CRM, PeopleSoft HCM, and MySQL Router. Read digest
- Oracle E-Business Suite July 26 digest — Two critical vulnerabilities, including a data exposure flaw and a host-access takeover risk. Read digest
- Netty July 30 digest — High-severity HAProxyMessageDecoder flaw can be remotely abused to exhaust direct memory. Read digest
- Oracle E-Business Suite July 31 digest — Four high-risk HR and HCM vulnerabilities, including sensitive data exposure and takeover paths. Read digest
July 24, 2026
- Security Alert: CVE-2026-60663 — A critical vulnerability rated up to CVSS 9.9. The alert calls for immediate action. Read alert
- Security Digest: July 24, 2026 - 9 Critical Vulnerabilities — Oracle disclosed nine new critical and high-severity flaws across BI Publisher, Siebel CRM, PeopleSoft HCM, and MySQL Router. Organizations should patch quickly and restrict external exposure where possible. CVEs include CVE-2026-60719, CVE-2026-60711, CVE-2026-60668, CVE-2026-60690, CVE-2026-60689, CVE-2026-60704, CVE-2026-60667, CVE-2026-60725, and CVE-2026-60705. Read digest
July 26, 2026
- Security Alert: CVE-2026-60880 — Critical vulnerability with a maximum CVSS of 9.8. Immediate action is recommended. Read alert
- Security Digest: July 26, 2026 - 2 Critical Vulnerabilities — Oracle E-Business Suite administrators are urged to patch two newly disclosed vulnerabilities right away. The issues include a critical data exposure flaw and a host-access takeover risk. CVEs: CVE-2026-60773 and CVE-2026-60763. Read digest
July 30, 2026
- Security Digest: July 30, 2026 - 1 Critical Vulnerability — Netty’s HAProxyMessageDecoder flaw is rated high severity (CVSS 7.5) and can be remotely abused to exhaust direct memory, potentially causing service disruption. Operators should move to the fixed releases immediately. CVE: CVE-2026-55851. Read digest
July 31, 2026
- Security Alert: CVE-2026-60999 — Critical vulnerability with a maximum CVSS of 9.8. Immediate action recommended. Read alert
- Security Digest: July 31, 2026 - 4 Critical Vulnerabilities — Oracle E-Business Suite users should patch four high-risk HR and HCM vulnerabilities immediately. The flaws include issues that expose sensitive data and enable takeover scenarios. CVEs: CVE-2026-60966, CVE-2026-60982, CVE-2026-60965, and CVE-2026-60900. Read digest
What Stands Out This Week
The week’s most urgent theme is the concentration of critical Oracle disclosures. Multiple digests focused on Oracle enterprise products, with the July 24 and July 26 advisories especially notable for the number and severity of flaws. These are the kinds of issues that can affect core business systems, so patch prioritization should be immediate for exposed environments.
Another key development is the appearance of repeated standalone critical alerts: CVE-2026-60663, CVE-2026-60880, and CVE-2026-60999. Even without full exploit details in the summaries, the severity ratings alone justify fast triage, validation, and remediation planning.
Finally, the July 30 Netty issue deserves attention even though it is rated high rather than critical. Memory exhaustion bugs can still be operationally disruptive, especially in high-throughput services or internet-facing systems. If you use Netty, confirm whether your deployed version is affected and upgrade promptly.
Recommended Actions
- Patch internet-facing Oracle systems first, especially E-Business Suite, BI Publisher, Siebel CRM, PeopleSoft HCM, and MySQL Router.
- Review exposure for any systems tied to the critical alerts and accelerate remediation for CVE-2026-60663, CVE-2026-60880, and CVE-2026-60999.
- Upgrade Netty deployments to the fixed releases and monitor for abnormal memory pressure or service instability.
- Validate compensating controls such as access restrictions, segmentation, and temporary service isolation where patching cannot be immediate.
- Track vendor advisories closely, as this week’s pattern suggests more follow-on disclosures may be likely.
For teams managing enterprise application estates, this week is a reminder that patch cadence and exposure management remain essential. The highest-risk items should be addressed first, but no item in this roundup should be left unreviewed.