CSIRT Toscana

Critical Patch Update di Oracle (AL03/260617/CSIRT-ITA)

Data:
17 Giugno 2026

Impatto Sistemico

Alto (66.66)

Sintesi

Oracle ha rilasciato il Critical Patch Update di giugno che mira a correggere numerose vulnerabilità su più prodotti, di cui 122 con gravità “critica” e 102 con gravità “alta”.

Tipologia

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege
  • Security Restriction Bypass
  • Data Manipulation

Prodotti e/o versioni affette

Oracle

  • APM – Application Performance Management
  • Application Development Framework (ADF)
  • Identity Manager
  • Identity Manager Connector
  • JD Edwards EnterpriseOne Accounts Payable
  • JD Edwards EnterpriseOne General Ledger
  • JD Edwards EnterpriseOne Human Resources Management
  • JD Edwards EnterpriseOne Order Promising
  • JD Edwards EnterpriseOne Project Costing
  • JD Edwards EnterpriseOne Tools
  • MySQL NDB Cluster
  • MySQL Router
  • MySQL Server
  • MySQL Shell
  • Oracle Access Manager
  • Oracle Advanced Outbound Telephony
  • Oracle Agile PLM
  • Oracle Application Development Framework (ADF)
  • Oracle Applications Manager
  • Oracle Coherence
  • Oracle Complex Maintenance, Repair and Overhaul
  • Oracle Configure to Order
  • Oracle Cost Management
  • Oracle Data Integrator
  • Oracle Enterprise Asset Management
  • Oracle Enterprise Command Center Framework
  • Oracle Enterprise Manager Base Platform
  • Oracle Financials for EMEA
  • Oracle HR Intelligence
  • Oracle HRMS (UK)
  • Oracle Human Resources
  • Oracle In-Memory Cost Management for Discrete Industries
  • Oracle iSetup
  • Oracle iSupplier Portal
  • Oracle iSupport
  • Oracle Outsourced Mfg for Discrete Industries
  • Oracle Process Manufacturing Process Planning
  • Oracle Process Manufacturing Product Development
  • Oracle Project Portfolio Analysis
  • Oracle Property Manager
  • Oracle Public Sector Financials (International)
  • Oracle Public Sector Payroll
  • Oracle Quality
  • Oracle Receivables
  • Oracle Solaris
  • Oracle Spares Management
  • Oracle Subledger Accounting
  • Oracle Unified Directory
  • Oracle Universal Work Queue
  • Oracle Virtual Directory
  • Oracle VM VirtualBox
  • Oracle WebCenter Content
  • Oracle WebCenter Enterprise Capture
  • Oracle WebCenter Portal
  • Oracle WebCenter Sites
  • PeopleSoft Enterprise CS Campus Community
  • PeopleSoft Enterprise CS Student Financials
  • PeopleSoft Enterprise PT PeopleTools
  • Siebel Apps – Marketing
  • Siebel CRM Cloud Applications
  • Siebel CRM Deployment
  • Siebel CRM Integration
  • WebCenter Content
  • WebCenter Content: Imaging
  • WebLogic Server

Azioni di mitigazione

In linea con le dichiarazioni del vendor, si consiglia di aggiornare i prodotti all’ultima versione disponibile.

Per approfondimenti sui prodotti interessati e sulle modalità di intervento si consiglia di fare riferimento al bollettino di sicurezza disponibile nella sezione Riferimenti.

Di seguito sono riportate le sole CVE relative alle vulnerabilità con gravità “alta” e “critica”:

Riferimenti

CVE

CVE-ID
CVE-2026-46780 CVE-2026-46782 CVE-2026-46781 CVE-2026-46777
CVE-2026-46898 CVE-2026-46776 CVE-2026-46897 CVE-2026-46779
CVE-2026-46778 CVE-2026-46899 CVE-2026-46773 CVE-2026-46894
CVE-2026-46893 CVE-2026-46896 CVE-2026-46774 CVE-2026-46895
CVE-2026-46791 CVE-2026-46793 CVE-2026-46792 CVE-2026-46788
CVE-2026-46787 CVE-2026-46789 CVE-2026-46784 CVE-2026-46783
CVE-2026-46786 CVE-2026-46785 CVE-2026-35309 CVE-2026-35307
CVE-2026-35308 CVE-2026-35305 CVE-2026-35306 CVE-2026-35303
CVE-2026-35304 CVE-2026-35301 CVE-2026-35302 CVE-2026-35300
CVE-2026-46799 CVE-2026-46798 CVE-2026-46795 CVE-2026-46794
CVE-2026-46797 CVE-2026-46796 CVE-2026-35318 CVE-2026-35319
CVE-2026-35316 CVE-2026-35317 CVE-2026-35314 CVE-2026-35315
CVE-2026-35312 CVE-2026-35313 CVE-2026-35310 CVE-2026-35311
CVE-2026-35320 CVE-2026-35288 CVE-2026-35289 CVE-2026-35298
CVE-2026-35295 CVE-2026-35296 CVE-2025-70873 CVE-2026-35293
CVE-2026-46858 CVE-2026-35294 CVE-2026-46857 CVE-2026-46978
CVE-2026-35292 CVE-2026-46859 CVE-2026-46854 CVE-2026-46853
CVE-2026-46974 CVE-2026-46856 CVE-2026-46855 CVE-2026-46976
CVE-2026-46850 CVE-2026-46971 CVE-2026-46970 CVE-2026-46852
CVE-2026-46973 CVE-2026-46851 CVE-2026-46972 CVE-2026-46870
CVE-2026-35299 CVE-2026-46868 CVE-2026-46865 CVE-2026-46864
CVE-2026-46867 CVE-2026-46866 CVE-2026-46861 CVE-2026-46860
CVE-2026-46863 CVE-2026-46862 CVE-2026-46881 CVE-2026-46880
CVE-2026-46879 CVE-2026-46875 CVE-2026-46878 CVE-2026-46872
CVE-2026-46873 CVE-2026-46890 CVE-2026-46892 CVE-2026-46891
CVE-2026-46769 CVE-2026-46766 CVE-2026-46887 CVE-2026-46765
CVE-2026-46886 CVE-2026-46889 CVE-2026-46767 CVE-2026-46888
CVE-2026-46883 CVE-2026-46882 CVE-2026-46885 CVE-2026-46884
CVE-2026-46939 CVE-2026-46938 CVE-2026-46814 CVE-2026-46935
CVE-2026-46813 CVE-2026-46934 CVE-2026-46937 CVE-2026-46931
CVE-2026-46930 CVE-2026-46933 CVE-2026-46932 CVE-2026-35259
CVE-2026-35258 CVE-2026-35265 CVE-2026-46949 CVE-2026-35262
CVE-2026-35263 CVE-2026-46946 CVE-2026-46945 CVE-2026-46947
CVE-2026-46942 CVE-2026-46944 CVE-2026-46940 CVE-2026-35268
CVE-2026-35269 CVE-2026-35267 CVE-2026-35275 CVE-2026-35276
CVE-2026-35274 CVE-2026-35271 CVE-2026-46957 CVE-2026-35272
CVE-2026-46956 CVE-2026-46838 CVE-2026-46959 CVE-2026-35270
CVE-2026-46958 CVE-2026-46832 CVE-2026-46953 CVE-2026-46952
CVE-2026-46955 CVE-2026-46951 CVE-2026-46950 CVE-2026-35279
CVE-2026-35278 CVE-2026-35286 CVE-2026-35284 CVE-2026-35285
CVE-2026-35282 CVE-2026-46847 CVE-2026-35283 CVE-2026-46846
CVE-2026-46967 CVE-2026-35280 CVE-2026-46849 CVE-2026-35281
CVE-2026-46848 CVE-2026-46969 CVE-2026-46964 CVE-2026-46963
CVE-2026-46845 CVE-2026-46966 CVE-2026-46844 CVE-2026-46965
CVE-2026-46960 CVE-2026-46962 CVE-2026-46961 CVE-2026-35327
CVE-2026-35325 CVE-2026-35326 CVE-2026-35323 CVE-2026-35324
CVE-2026-35321 CVE-2026-35322 CVE-2026-34481 CVE-2026-46909
CVE-2026-46906 CVE-2026-46905 CVE-2026-46908 CVE-2026-46907
CVE-2026-46902 CVE-2026-46901 CVE-2026-46904 CVE-2026-46903
CVE-2026-46900 CVE-2026-46916 CVE-2026-46919 CVE-2026-46918
CVE-2026-46913 CVE-2026-46912 CVE-2026-46915 CVE-2026-46914
CVE-2026-46911 CVE-2026-46910 CVE-2026-46807 CVE-2026-46928
CVE-2026-46806 CVE-2026-46927 CVE-2026-46809 CVE-2026-46808
CVE-2026-46929 CVE-2026-46803 CVE-2026-46802 CVE-2026-46805
CVE-2026-46926 CVE-2026-46804 CVE-2026-46925 CVE-2026-46920
CVE-2026-46801 CVE-2026-46922 CVE-2026-46800 CVE-2026-46921

Change log

Versione Note Data
1.0 Pubblicato il 17-06-2026 17/06/2026

Il presente articolo è un prodotto originale di csirt.gov.it, riproposto qui a solo scopo di aumentarne la visibilità. Può essere visualizzato in versione originale al seguente link

Ultimo aggiornamento

17 Giugno 2026, 14:31