vciy

Oracle Commerce Experience Manager: 61 records in one advisory

61 records announced together, published 2026-08-18, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.oracle.com/security-alerts/cspuaug2026.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

1 of 61 record names something of its own. For the other 60, held sources say the same thing about each.

Most commonly mapped weakness across the batch: Easily exploitable vulnerability allows…

What this page does not cover

This batch is 61 of the 890 records that cite the same advisory. The other 829 are different findings announced alongside it.

408 of them are on the sibling batches linked below. The remaining 421 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: oracle-cspuaug2026-090c48f372, oracle-cspuaug2026-242cea9b39, oracle-cspuaug2026-2cf943460d, oracle-cspuaug2026-8922c502ed, oracle-cspuaug2026-97574cd1a2, oracle-cspuaug2026-b95b629f66, oracle-cspuaug2026-ba534bfb8f, oracle-cspuaug2026-cfddc9bb6a, oracle-cspuaug2026-da9629c137

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Oracle's third monthly patch day, and the seven identifiers that explain 943 against 925

Oracle now ships security patches on the third Tuesday of every month, and this advisory is the August 2026 release, dated 18 August 2026. SecurityWeek calls it Oracle's third monthly rollout. The page carries 23 risk matrices, one for each product family, and counting every row across them gives 943 rows holding 925 distinct identifiers. The gap is not an error. Seven identifiers are listed more than once because they sit in a library that Oracle bundles into several products, and Oracle gives each affected product its own row: CVE-2026-34481 in Apache Log4j appears on eleven rows, from Oracle Retail Item Planning to the Agile product lifecycle management connector. Oracle's own text says the release "contains 66 new security patches for Oracle Commerce" and that "47 of these vulnerabilities may be remotely exploitable without authentication". Of the 66, 63 rows name Oracle Commerce Guided Search / Oracle Commerce Experience Manager, every one of them at version 11.4.0, spread across eight component names: Endeca Application Controller has 20, Experience Manager 18, Content Acquisition System 18, Forge 3, and Workbench, Internal operations and two third-party rows take one each. SecurityWeek reports that Oracle announced earlier in 2026 that it was using large language models to speed up patching, which is that publication's explanation for the volume rather than a statement Oracle makes about any of these records.

These records were announced on one day in one table. Each is its own row in Oracle's matrix with its own score and its own exploitability line, and sharing a table is all they share.

2026-08-18Oracle publishes the August 2026 Critical Security Patch Update, revision 1, with 943 patch rows across 23 risk matrices.

Oracle's Commerce matrix gives a component name and a score and nothing else. The eight component names cover the whole product, so the row cannot tell you which screen or which request is involved, and no row carries a bug class. Published counts of this release also disagree: SecurityWeek says the update covers more than 1,000 unique identifiers, while counting the rows on Oracle's own page gives 925.

Written from oracle.com, securityweek.com, tenable.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-70976no title heldEasily exploitable vulnerability allows…
CVE-2026-70977no title heldEasily exploitable vulnerability allows…
CVE-2026-70978no title heldEasily exploitable vulnerability allows…
CVE-2026-70979no title heldEasily exploitable vulnerability allows…
CVE-2026-70980no title heldDifficult to exploit vulnerability allows…
CVE-2026-70981no title heldEasily exploitable vulnerability allows…
CVE-2026-70982no title heldDifficult to exploit vulnerability allows…
CVE-2026-70983no title heldDifficult to exploit vulnerability allows…
CVE-2026-70984no title heldEasily exploitable vulnerability allows…
CVE-2026-70985no title heldEasily exploitable vulnerability allows…
CVE-2026-70986no title heldEasily exploitable vulnerability allows…
CVE-2026-70987no title heldEasily exploitable vulnerability allows…
CVE-2026-70988no title heldEasily exploitable vulnerability allows low…
CVE-2026-70989no title heldEasily exploitable vulnerability allows low…
CVE-2026-70990no title heldDifficult to exploit vulnerability allows…
CVE-2026-70991no title heldEasily exploitable vulnerability allows…
CVE-2026-70992no title heldDifficult to exploit vulnerability allows low…
CVE-2026-70993no title heldEasily exploitable vulnerability allows…
CVE-2026-70994no title heldEasily exploitable vulnerability allows…
CVE-2026-70995no title heldEasily exploitable vulnerability allows…
CVE-2026-70996no title heldEasily exploitable vulnerability allows…
CVE-2026-70997no title heldEasily exploitable vulnerability allows…
CVE-2026-70998no title heldEasily exploitable vulnerability allows…
CVE-2026-70999no title heldEasily exploitable vulnerability allows low…
CVE-2026-71000no title heldEasily exploitable vulnerability allows low…
CVE-2026-71001no title heldEasily exploitable vulnerability allows low…
CVE-2026-71002no title heldEasily exploitable vulnerability allows low…
CVE-2026-71003no title heldEasily exploitable vulnerability allows low…
CVE-2026-71004no title heldEasily exploitable vulnerability allows…
CVE-2026-71005no title heldEasily exploitable vulnerability allows…
CVE-2026-71006no title heldEasily exploitable vulnerability allows…
CVE-2026-71007no title heldEasily exploitable vulnerability allows high…
CVE-2026-71008no title heldEasily exploitable vulnerability allows high…
CVE-2026-71009no title heldDifficult to exploit vulnerability allows…
CVE-2026-71010no title heldEasily exploitable vulnerability allows…
CVE-2026-71011no title heldEasily exploitable vulnerability allows…
CVE-2026-71012no title heldEasily exploitable vulnerability allows low…
CVE-2026-71014no title heldEasily exploitable vulnerability allows…
CVE-2026-71015no title heldEasily exploitable vulnerability allows…
CVE-2026-71016no title heldEasily exploitable vulnerability allows…
CVE-2026-71017no title heldDifficult to exploit vulnerability allows…
CVE-2026-71018no title heldEasily exploitable vulnerability allows…
CVE-2026-71019no title heldEasily exploitable vulnerability allows…
CVE-2026-71020no title heldEasily exploitable vulnerability allows low…
CVE-2026-71021no title heldEasily exploitable vulnerability allows low…
CVE-2026-71022workbenchEasily exploitable vulnerability allows low…
CVE-2026-71023no title heldEasily exploitable vulnerability allows…
CVE-2026-71024no title heldEasily exploitable vulnerability allows…
CVE-2026-71025no title heldEasily exploitable vulnerability allows…
CVE-2026-71026no title heldEasily exploitable vulnerability allows…
CVE-2026-71027no title heldEasily exploitable vulnerability allows low…
CVE-2026-71028no title heldEasily exploitable vulnerability allows low…
CVE-2026-71030no title heldEasily exploitable vulnerability allows…
CVE-2026-71031no title heldEasily exploitable vulnerability allows…
CVE-2026-71032no title heldEasily exploitable vulnerability allows…
CVE-2026-71033no title heldEasily exploitable vulnerability allows low…
CVE-2026-71034no title heldEasily exploitable vulnerability allows…
CVE-2026-71035no title heldDifficult to exploit vulnerability allows…
CVE-2026-71036no title heldEasily exploitable vulnerability allows…
CVE-2026-71037no title heldEasily exploitable vulnerability allows…
CVE-2026-71038no title heldEasily exploitable vulnerability allows…

61 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.