Oracle Enterprise Manager, Process Manufacturing flaws patched
CERT-FR advisory details multiple vulnerabilities in Oracle Enterprise Manager for Systems Infrastructure and Oracle Process Manufacturing that can compromise data confidentiality and integrity.
CERT-FR published an advisory covering multiple vulnerabilities in Oracle Systems products, specifically Oracle Enterprise Manager for Systems Infrastructure (versions 13.5 and 24.1) and Oracle Process Manufacturing Systems (versions 12.2.3 through 12.2.15). The flaws could allow an attacker to compromise data confidentiality and integrity, though the advisory does not indicate active exploitation or provide technical exploitation details.
Four CVEs are referenced (CVE-2026-60822, CVE-2026-70737, CVE-2026-70829, CVE-2026-70830), tied to Oracle's Critical Patch Update bulletin cspuaug2026 released August 18, 2026. Affected organizations should consult the vendor bulletin and apply the corresponding patches. No threat actor, malware, or in-the-wild exploitation is mentioned in this advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1051
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free