Vulnerability
Published 2026-08-18
Verified 2026-09-19

Oracle August 2026 CSPU: 943 patches, including WebLogic 9.8 and OID 10.0

Oracle's 18 August 2026 Critical Security Patch Update (revision 3 on 27 August) contains 943 new security patches. Oracle says it continues to receive reports of attempts to exploit already-patched issues where customers had not applied available updates. Fusion Middleware includes unauthenticated WebLogic Server Core issues CVE-2026-60698 (IIOP, 9.8), CVE-2026-60672 and CVE-2026-60696 (T3/IIOP, 9.8) on 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, plus CVE-2026-60977 (RMI, 9.8) on 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, and Oracle Internet Directory LDAP Server CVE-2026-61241 at 10.0 on 12.2.1.4.0 and 14.1.2.1.0. Database Server includes adjacent-network Portable Clusterware issues CVE-2026-71063 and CVE-2026-71064 at 9.6. Apply the August 2026 CSPU for each product family you run. This is separate from CVE-2026-21962 (January 2026 CPU, later added to CISA KEV).

Product
Oracle Fusion Middleware, Database Server and other families in the August 2026 CSPU
Versions
See the August 2026 CSPU risk matrices; WebLogic 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 among others
CVSS
Up to (CVE-2026-61241, CVSS 3.1, Oracle)
Exploited in Australia?
unknown
Patch to
August 2026 Critical Security Patch Update for each affected product

Primary: Oracle CSPU August 2026 · Vendor: Oracle (vendor) · CVE: CVE-2026-60698, CVE-2026-60672, CVE-2026-60696, CVE-2026-60977, CVE-2026-61241, CVE-2026-71063, CVE-2026-71064, CVE-2026-21962

vulnerabilities cloud