Oracle Commerce Experience Manager: 61 records in one advisory
61 records announced together, published 2026-08-18, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.oracle.com/security-alerts/cspuaug2026.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
1 of 61 record names something of its own. For the other 60, held sources say the same thing about each.
Most commonly mapped weakness across the batch: Easily exploitable vulnerability allows…
What this page does not cover
This batch is 61 of the 890 records that cite the same advisory. The other 829 are different findings announced alongside it.
408 of them are on the sibling batches linked below. The remaining 421 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: oracle-cspuaug2026-090c48f372, oracle-cspuaug2026-242cea9b39, oracle-cspuaug2026-2cf943460d, oracle-cspuaug2026-8922c502ed, oracle-cspuaug2026-97574cd1a2, oracle-cspuaug2026-b95b629f66, oracle-cspuaug2026-ba534bfb8f, oracle-cspuaug2026-cfddc9bb6a, oracle-cspuaug2026-da9629c137
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Oracle's third monthly patch day, and the seven identifiers that explain 943 against 925
Oracle now ships security patches on the third Tuesday of every month, and this advisory is the August 2026 release, dated 18 August 2026. SecurityWeek calls it Oracle's third monthly rollout. The page carries 23 risk matrices, one for each product family, and counting every row across them gives 943 rows holding 925 distinct identifiers. The gap is not an error. Seven identifiers are listed more than once because they sit in a library that Oracle bundles into several products, and Oracle gives each affected product its own row: CVE-2026-34481 in Apache Log4j appears on eleven rows, from Oracle Retail Item Planning to the Agile product lifecycle management connector. Oracle's own text says the release "contains 66 new security patches for Oracle Commerce" and that "47 of these vulnerabilities may be remotely exploitable without authentication". Of the 66, 63 rows name Oracle Commerce Guided Search / Oracle Commerce Experience Manager, every one of them at version 11.4.0, spread across eight component names: Endeca Application Controller has 20, Experience Manager 18, Content Acquisition System 18, Forge 3, and Workbench, Internal operations and two third-party rows take one each. SecurityWeek reports that Oracle announced earlier in 2026 that it was using large language models to speed up patching, which is that publication's explanation for the volume rather than a statement Oracle makes about any of these records.
These records were announced on one day in one table. Each is its own row in Oracle's matrix with its own score and its own exploitability line, and sharing a table is all they share.
Oracle's Commerce matrix gives a component name and a score and nothing else. The eight component names cover the whole product, so the row cannot tell you which screen or which request is involved, and no row carries a bug class. Published counts of this release also disagree: SecurityWeek says the update covers more than 1,000 unique identifiers, while counting the rows on Oracle's own page gives 925.
Written from oracle.com, securityweek.com, tenable.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
61 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.