Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026) — Threadlinqs Intelligence
As of 2026-07-22, Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1616 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
CERT-Bund's WID-SEC-2026-2450 advisory (rated "hoch"/high) warns that a remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle Supply Chain to compromise
On 2026-07-21, Oracle released its July 2026 Critical Patch Update (CPU), the company's largest to date, covering 1,235 unique CVEs across 32 product families with 1,449 individual security patches (261 rated critical, 18% of all patches; 52.7% high severity, 24.7% medium; CVSS scores ranged up to 10.0). Within this release, the Oracle Supply Chain product family (which Oracle groups under its Supply Chain Management applications, including components historically covered by prior CPUs such as Agile PLM, Transportation Management, Global Trade Management, Supply Chain Collaboration, and Value Chain Planning) received 39 patches addressing 16 distinct CVEs. Oracle's own risk-matrix breakdown flags all 16 of these Supply Chain CVEs as remotely exploitable over a network by an attacker without requiring authentication credentials, which is the basis for CERT-Bund's "hoch" (high) severity rating in WID-SEC-2026-2450 and for the confidentiality/integrity/availability impact language in that advisory.
Oracle's authoritative per-CVE risk matrix (cpujul2026verbose.html) and the primary advisory page (cpujul2026.html) both returned HTTP 403 to automated fetch during this analysis, and CERT-Bund's WID portal is a JavaScript-rendered SPA that did not return the advisory body to WebFetch/WebSearch either. No secondary aggregator (Tenable, Security Boulevard, IMTR, OffSeq Threat Radar) that indexed the July 2026 CPU broke out individual CVE identifiers, CVSS vectors, or per-component detail specific to the Supply Chain family for THIS quarter's release at the time of research — they report only the family-level patch/CVE/remote-exploitability counts cited above. Per the no-invention rule, individual CVE IDs, CVSS scores/vectors, and specific vulnerable Supply Chain sub-components for the July 2026 disclosure itself are left null/empty rather than guessed; this threat should be revisited once Oracle's risk matrix becomes fetchable or a vendor/researcher writeup names the specific CVEs.
However, the Oracle Supply Chain family (specifically Oracle Agile PLM, a component of this family) has an established, sourced pattern of unauthenticated-remote-exploit vulnerabilities in prior 2026 CPU cycles that illustrates the likely exploit class for this disclosure: the January 2026 CPU patched CVE-2026-21969, a CVSS 3.1 9.8 unauthenticated remote-code-execution flaw in Oracle Agile PLM for Process 6.2.4's Supplier Portal component (analysts assessed likely root causes as insecure Java deserialization, unauthenticated malicious file upload, or authentication/session-bypass via header manipulation), CVE-2026-21940, a CVSS 7.5 unauthenticated information-disclosure flaw (CWE-200) in Agile PLM 9.3.6's User and User Group component, and CVE-2026-46859, a CVSS 9.8 unauthenticated RCE in Agile PLM 9.3.6's Security component. Separately, in the sibling Oracle E-Business Suite family (patched in the May 2026 CPU), CVE-2026-46817 — a CVSS 9.8 unauthenticated file-read/takeover flaw in the Oracle Payments "File Transmission" component (versions 12.2.3-12.2.15), exploited via crafted unauthenticated HTTP POST requests with XML payloads to the /OA_HTML/ibytransmit endpoint to redirect an internal Java function into arbitrary filesystem reads — was first observed under active exploitation in the wild by threat-intel firm Defused Cyber on 2026-06-27/29 and was added to CISA's KEV catalog on 2026-07-15, with federal agencies ordered to patch by 2026-07-18. This recurring pattern (unauthenticated, network-exploitable, CVSS ~9.8, HTTP-tier Oracle enterprise-application flaws that are weaponized in the wild within weeks to months of CPU patch release) is the primary basis for treating WID-SEC-2026-2450's 16 unauthenticated remote Supply Chain vulnerabilities as an urgent, high-confidence exploitation risk even absent per-CVE detail for this specific disclosure.
As a class, unauthenticated remotely-exploitable vulnerabilities in Oracle enterprise applications (per Ora
Target sectors: manufacturing, retail, logistics, government administration, finance
Target regions: Global
Timeline
- Oracle's January 2026 CPU patches CVE-2026-21969 (CVSS 9.8, unauthenticated RCE in Agile PLM for Process 6.2.4 Supplier Portal) and CVE-2026-21940 (CVSS 7.5, unauthenticated info disclosure in Agile PLM 9.3.6 User/User Group component) — both in the same Oracle Supply Chain product family, establishing the unauthenticated-remote-exploit pattern later echoed in WID-SEC-2026-2450.
- Oracle's May 2026 CPU patches CVE-2026-46817 (CVSS 9.8, unauthenticated file-read/takeover in Oracle E-Business Suite Payments "File Transmission" component, versions 12.2.3-12.2.15), a sibling Oracle enterprise-application family to Supply Chain.
- Threat-intel firm Defused Cyber observes the first unauthenticated exploitation attempts against CVE-2026-46817 in the wild via honeypot monitoring, roughly seven weeks after the patch shipped.
- CISA adds CVE-2026-46817 (Oracle E-Business Suite Payments) to its Known Exploited Vulnerabilities catalog and orders U.S. federal civilian agencies to patch by 2026-07-18, confirming the pattern of Oracle CPU-era enterprise-application flaws being weaponized post-disclosure.
- Oracle releases the July 2026 Critical Patch Update, its largest to date, covering 1,235 unique CVEs / 1,449 patches across 32 product families, including 39 patches for 16 CVEs in the Oracle Supply Chain family.
- Oracle publishes cpujul2026.html and the accompanying verbose risk-matrix (cpujul2026verbose.html) detailing per-product CVE risk data.
- Tenable, Security Boulevard, IMTR, and OffSeq Threat Radar publish independent summaries of the July 2026 CPU, each confirming the Oracle Supply Chain family patch/CVE counts.
- CERT-Bund publishes WID-SEC-2026-2450, rating the Oracle Supply Chain multi-vulnerability disclosure "hoch" (high) and flagging remote, anonymous-or-authenticated exploitability with confidentiality/integrity/availability impact.
- TL-Intel-Harness ingests the CERT-Bund WID feed item and opens threat TL-2026-1616 for research.
- Automated research finds Oracle's authoritative per-CVE risk matrix and the CERT-Bund advisory body both inaccessible to WebFetch/WebSearch (403 / JS-rendered SPA); analysis proceeds using only sourced family-level CPU statistics plus historical same-family/sibling-family CVE precedent.
Detections & IOCs
As of 2026-09-09, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1590, T1595, T1583, T1587, T1190, T1059, T1505, T1068, T1211, T1212