CERT-In Issues High-Severity Alert Over Multiple Vulnerabilities in Oracle Products

CERT-In Issues High-Severity Alert Over Multiple Vulnerabilities in Oracle Products

India’s Computer Emergency Response Team (CERT-In) has issued a high-severity security advisory over multiple vulnerabilities affecting several Oracle products.

The advisory, CIAD-2026-0043, was originally issued on August 28, 2026. It covers Oracle MySQL, Oracle Access Manager, Oracle Supply Chain Products, Oracle Analytics, Oracle Commerce, Oracle Communications, Oracle Database Server, Oracle E-Business Suite, Oracle Enterprise Manager and Oracle Financial Services Applications.

According to CERT-In, the vulnerabilities could be exploited by a remote attacker to gain unauthorised access, execute arbitrary code, disclose sensitive information, manipulate data, bypass security controls or cause denial-of-service conditions on a targeted system.

The advisory is aimed at organisations and IT administrators using Oracle Corporation products.

CERT-In said Oracle products are used across several applications, including enterprise-level data management, cloud solutions, software development, communications, financial services, hospitality, retail and business applications. They are used across sectors including finance, healthcare, manufacturing, government and retail.

The vulnerabilities exist in various components of Oracle products due to weaknesses affecting different product functionalities and third-party components.

Several of these vulnerabilities may be exploited remotely over a network without authentication and without requiring valid user credentials.

Successful exploitation could allow an attacker to gain unauthorised access, execute arbitrary code, access sensitive information, manipulate data, bypass security controls or cause denial-of-service conditions on affected systems.

CERT-In has advised users and organisations to apply the appropriate security updates issued by Oracle.