Security Digest: July 24, 2026 - 9 Critical Vulnerabilities

Oracle has issued nine new critical and high-severity vulnerabilities affecting Oracle Analytics BI Publisher, Siebel CRM Cloud Applications, PeopleSoft HCM, and MySQL Router. Several are network-reachable and require no user interaction, which means exposed systems should be treated as urgent patch targets today.

· 42 min read

Executive Summary

Oracle has issued nine new critical and high-severity vulnerabilities affecting Oracle Analytics BI Publisher, Siebel CRM Cloud Applications, PeopleSoft HCM, and MySQL Router. Several are network-reachable and require no user interaction, which means exposed systems should be treated as urgent patch targets today.

Act now: prioritize internet-facing Oracle services, apply vendor patches immediately, and restrict HTTP/TCP access until remediation is complete. If you run any affected Oracle stack, assume these flaws are exploitable and begin validation and monitoring now.

Critical Vulnerabilities

CVE-2026-60719: Oracle BI Publisher Web Service API compromise

  • Impact: Attackers with low privileges can compromise BI Publisher, modify or delete critical data, access all accessible data, and trigger partial denial of service.
  • Affected Systems: Oracle Analytics BI Publisher 8.2.0.0.0, 12.2.1.4.0, 26.01.0.0.0
  • Immediate Action: Patch Oracle Analytics immediately and isolate BI Publisher from broad network exposure.
  • Mitigation: Apply the latest Oracle CPU; restrict HTTP access to trusted admin networks only.

CVE-2026-60711: Siebel Cloud Manager takeover risk

  • Impact: Low-privileged attackers can take over Siebel CRM Cloud Applications.
  • Affected Systems: Oracle Siebel CRM Cloud Applications 22.3-26.5
  • Immediate Action: Patch now and review all Siebel Cloud Manager access paths.
  • Mitigation: Apply Oracle’s fix; temporarily limit access to management interfaces.

CVE-2026-60668: PeopleSoft HCM data exposure and modification

  • Impact: Unauthenticated attackers can access sensitive HR data and alter records.
  • Affected Systems: Oracle PeopleSoft Enterprise HCM Human Resources 9.2
  • Immediate Action: Patch immediately and block public access to the affected service.
  • Mitigation: Install the vendor update; verify HTTP exposure is removed or tightly restricted.

CVE-2026-60690: Siebel Cloud Manager confidential data exposure

  • Impact: Low-privileged attackers can access complete Siebel Cloud data.
  • Affected Systems: Oracle Siebel CRM Cloud Applications 22.3-26.5
  • Immediate Action: Treat as urgent and patch the affected Siebel components.
  • Mitigation: Apply Oracle’s patch bundle and restrict network reachability.

CVE-2026-60689: Unauthenticated Siebel Cloud data disclosure

  • Impact: Attackers can access all accessible Siebel Cloud data without credentials.
  • Affected Systems: Oracle Siebel CRM Cloud Applications 22.3-26.5
  • Immediate Action: Patch now and confirm the service is not exposed to the internet.
  • Mitigation: Deploy Oracle’s fix; add temporary firewall blocks if patching is delayed.

CVE-2026-60704: Siebel Cloud Manager unauthenticated data access

  • Impact: Unauthenticated attackers can access sensitive Siebel Cloud data.
  • Affected Systems: Oracle Siebel CRM Cloud Applications 22.3-26.5
  • Immediate Action: Patch immediately and audit external access paths.
  • Mitigation: Apply the Oracle update; limit exposure to trusted networks.

CVE-2026-60667: PeopleSoft Core crash and data integrity risk

  • Impact: Unauthenticated attackers can modify critical data and trigger repeatable crashes or a full denial of service.
  • Affected Systems: Oracle PeopleSoft Enterprise HCM Human Resources 9.2
  • Immediate Action: Patch urgently and monitor for service instability.
  • Mitigation: Install the fix from Oracle; segment access to the affected TCP service.

CVE-2026-60725: MySQL Router data compromise

  • Impact: Attackers can modify or access critical data through MySQL Router.
  • Affected Systems: MySQL Router 8.4.0-8.4.10, 9.7.0-9.7.1
  • Immediate Action: Upgrade immediately and restrict network access to the router.
  • Mitigation: Apply the Oracle/MySQL patch release; remove unnecessary HTTP exposure.

CVE-2026-60705: Siebel Cloud partial denial of service

  • Impact: Unauthenticated attackers can access data, alter some records, and cause partial service disruption.
  • Affected Systems: Oracle Siebel CRM Cloud Applications 22.3-26.5
  • Immediate Action: Patch now and validate service availability after remediation.
  • Mitigation: Apply Oracle’s fix; restrict access until all exposed endpoints are updated.

Previously Alerted

What to Do Now

  1. Patch Oracle systems first. Focus on internet-facing BI Publisher, Siebel Cloud Manager, PeopleSoft HCM, and MySQL Router instances.
  2. Reduce exposure immediately. Block public HTTP/TCP access to affected services until updates are applied.
  3. Validate versions. Confirm whether you run BI Publisher 8.2.0.0.0/12.2.1.4.0/26.01.0.0.0, Siebel 22.3-26.5, PeopleSoft HCM 9.2, or MySQL Router 8.4.0-8.4.10 / 9.7.0-9.7.1.
  4. Check for abuse. Review logs for unusual authentication attempts, unexpected data access, config changes, crashes, or service restarts.
  5. Escalate if patching is delayed. Put compensating controls in place and notify incident response.

Verification steps: confirm patch levels after deployment, retest external reachability, and ensure no affected endpoint remains exposed. Monitoring: watch for new admin accounts, abnormal API calls, database/HR record changes, and denial-of-service symptoms.

Related Resources

  • Internal: upcoming CyberLens AI deep-dive on Oracle July 24 emergency patching guidance.
  • Official vendor advisories: Oracle Critical Patch Update and Oracle Security Alert documentation for July 2026.

Keep reading