Critical Patch Update di Oracle (AL06/260916/CSIRT-ITA)
Data:
16 Settembre 2026
Impatto Sistemico
Alto (66.66)
Sintesi
Oracle ha rilasciato il Critical Patch Update di settembre che mira a correggere numerose vulnerabilità su più prodotti, di cui 97 con gravità “critica” e 485 con gravità “alta”.
Tipologia
- Authentication Bypass
- Denial of Service
- Information Disclosure
- Privilege Escalation
- Remote Code Execution
- Security Restriction Bypass
Prodotti e/o versioni affette
- Oracle Database Server
- Oracle Application Testing Suite
- Oracle Commerce Guided Search / Oracle Commerce Experience Manager
- Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Oracle Applications Framework
- Oracle Document Management and Collaboration
- Oracle Mobile Application Server
- Oracle Alert
- Oracle Application Object Library
- Oracle Applications Manager
- Oracle Bills of Material
- Oracle Complex Maintenance, Repair and Overhaul
- Oracle Contract Lifecycle Management for Public Sector
- Oracle Contracts
- Oracle Customer Interaction History
- Oracle Demand Signal Repository
- Oracle Depot Repair
- Oracle Marketing
- Oracle Product Hub
- Oracle Purchasing
- Oracle Report Manager
- Oracle Sales Online
- Oracle Spares Management
- Oracle User Management
- Oracle iStore
- Oracle HRMS (India)
- Oracle iRecruitment
- Oracle Product Workbench
- Oracle Financials for Asia/Pacific
- Oracle Engineering
- Oracle CRM Technical Foundation
- Oracle Financials Common Modules
- Oracle Installed Base
- Oracle One-to-One Fulfillment
- Oracle Order Management
- Oracle Project Intelligence
- Oracle Work in Process
- Oracle Advanced Benefits
- Applications DBA
- Enterprise Command Center Framework
- Oracle Field Service
- Oracle Proposals
- Oracle Sales
- Oracle Sales Offline
- Oracle Web Applications Desktop Integrator
- Oracle Quality
- Oracle Sourcing
- Oracle Common Applications
- Oracle Lease and Finance Management
- Oracle Common Applications Calendar
- Oracle Partner Management
- Oracle Site Hub
- Oracle US Federal Human Resources
- Oracle XML Gateway
- Oracle Enterprise Manager for Fusion Middleware
- Oracle Enterprise Manager for Oracle Database
- Oracle Banking Branch
- Oracle Banking Corporate Lending
- Oracle Banking Origination
- Oracle Banking Corporate Lending Process Management
- Oracle Access Manager
- Oracle Forms
- Oracle Internet Directory
- Oracle Platform Security for Java
- Oracle WebLogic Server
- Oracle WebCenter Portal
- Oracle WebCenter Sites
- Service Delivery Platform
- Oracle Data Integrator
- Oracle Identity Manager
- Oracle JDeveloper
- Oracle WebCenter Enterprise Capture
- Oracle Managed File Transfer
- Oracle Identity Manager Connector
- Oracle Coherence
- Oracle Fusion Middleware Control
- Oracle Web Services Manager
- Helidon
- Oracle Middleware Common Libraries and Tools
- Oracle WebCenter Content
- Oracle Business Intelligence Enterprise Edition
- Oracle BI Publisher
- Oracle Hyperion Financial Management
- Oracle Hyperion Data Relationship Management
- Oracle GraalVM for JDK, Oracle GraalVM
- Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM
- PeopleSoft Enterprise PeopleTools
- PeopleSoft Enterprise FIN Engineering Brazil
- PeopleSoft Enterprise FIN Inventory Brazil
- PeopleSoft Enterprise PRTL Interaction Hub
- Siebel Apps – Financial Services
- Siebel CRM Deployment
- Siebel CRM End User
- Siebel Apps – Self Service
- Siebel CRM Cloud Applications
- Siebel CRM Development
- Siebel Apps – Customer Order Management
- Siebel Apps – Life Sciences
- Siebel CRM Integration
- Siebel Apps – Marketing
- Oracle Product Lifecycle Analytics
- Oracle Agile PLM
- Oracle Agile Engineering Data Management
- Oracle Agile PLM MCAD Connector
- Oracle Utilities Network Management System
- Oracle VM VirtualBox
Azioni di mitigazione
In linea con le dichiarazioni del vendor, si consiglia di aggiornare i prodotti all’ultima versione disponibile.
Per approfondimenti sui prodotti interessati e sulle modalità di intervento si consiglia di fare riferimento al bollettino di sicurezza disponibile nella sezione Riferimenti.
Di seguito sono riportate le sole CVE relative alle vulnerabilità con gravità “alta” e “critica”:
Riferimenti
CVE
Change log
| Versione | Note | Data |
|---|---|---|
| 1.0 | Pubblicato il 16-09-2026 | 16/09/2026 |
Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità. Può essere visualizzato in versione originale al seguente link
Ultimo aggiornamento
16 Settembre 2026, 13:01
CSIRT Toscana