Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026) — Threadlinqs Intelligence
As of 2026-07-22, Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1616 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
CERT-Bund's WID-SEC-2026-2450 advisory (rated "hoch"/high) warns that a remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle Supply Chain to compromise
On 2026-07-21, Oracle released its July 2026 Critical Patch Update (CPU), the company's largest to date, covering 1,235 unique CVEs across 32 product families with 1,449 individual security patches (261 rated critical, 18% of all patches; 52.7% high severity, 24.7% medium; CVSS scores ranged up to 10.0). Within this release, the Oracle Supply Chain product family (which Oracle groups under its Supply Chain Management applications, including components historically covered by prior CPUs such as Agile PLM, Transportation Management, Global Trade Management, Supply Chain Collaboration, and Value Chain Planning) received 39 patches addressing 16 distinct CVEs. Oracle's own risk-matrix breakdown flags all 16 of these Supply Chain CVEs as remotely exploitable over a network by an attacker without requiring authentication credentials, which is the basis for CERT-Bund's "hoch" (high) severity rating in WID-SEC-2026-2450 and for the confidentiality/integrity/availability impact language in that advisory.
Oracle's authoritative per-CVE risk matrix (cpujul2026verbose.html) and the primary advisory page (cpujul2026.html) both returned HTTP 403 to automated fetch during this analysis, and CERT-Bund's WID portal is a JavaScript-rendered SPA that did not return the advisory body to WebFetch/WebSearch either. No secondary aggregator (Tenable, Security Boulevard, IMTR, OffSeq Threat Radar) that indexed the July 2026 CPU broke out individual CVE identifiers, CVSS vectors, or per-component detail specific to the Supply Chain family for THIS quarter's release at the time of research — they report only the family-level patch/CVE/remote-exploitability counts cited above. Per the no-invention rule, individual CVE IDs, CVSS scores/vectors, and specific vulnerable Supply Chain sub-components for the July 2026 disclosure itself are left null/empty rather than guessed; this threat should be revisited once Oracle's risk matrix becomes fetchable or a vendor/researcher writeup names the specific CVEs.
However, the Oracle Supply Chain family (specifically Oracle Agile PLM, a component of this family) has an established, sourced pattern of unauthenticated-remote-exploit vulnerabilities in prior 2026 CPU cycles that illustrates the likely exploit class for this disclosure: the January 2026 CPU patched CVE-2026-21969, a CVSS 3.1 9.8 unauthenticated remote-code-execution flaw in Oracle Agile PLM for Process 6.2.4's Supplier Portal component (analysts assessed likely root causes as insecure Java deserialization, unauthenticated malicious file upload, or authentication/session-bypass via header manipulation), CVE-2026-21940, a CVSS 7.5 unauthenticated information-disclosure flaw (CWE-200) in Agile PLM 9.3.6's User and User Group component, and CVE-2026-46859, a CVSS 9.8 unauthenticated RCE in Agile PLM 9.3.6's Security component. Separately, in the sibling Oracle E-Business Suite family (patched in the May 2026 CPU), CVE-2026-46817 — a CVSS 9.8 unauthenticated file-read/takeover flaw in the Oracle Payments "File Transmission" component (versions 12.2.3-12.2.15), exploited via crafted unauthenticated HTTP POST requests with XML payloads to the /OA_HTML/ibytransmit endpoint to redirect an internal Java function into arbitrary filesystem reads — was first observed under active exploitation in the wild by threat-intel firm Defused Cyber on 2026-06-27/29 and was added to CISA's KEV catalog on 2026-07-15, with federal agencies ordered to patch by 2026-07-18. This recurring pattern (unauthenticated, network-exploitable, CVSS ~9.8, HTTP-tier Oracle enterprise-application flaws that are weaponized in the wild within weeks to months of CPU patch release) is the primary basis for treating WID-SEC-2026-2450's 16 unauthenticated remote Supply Chain vulnerabilities as an urgent, high-confidence exploitation risk even absent per-CVE detail for this specific disclosure.
As a class, unauthenticated remotely-exploitable vulnerabilities in Oracle enterprise applications (per Ora
Target sectors: manufacturing, retail, logistics, government administration, finance
Target regions: Global
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1590, T1595, T1583, T1587, T1190, T1059, T1505, T1068, T1211, T1212