{"cvss":0.0,"cwes":null,"datePublished":"2026-07-14","dateUpdated":"2026-07-14","description":"Bulk import from Oracle's July 2026 Critical Patch Update (quarterly security patch release), affecting Oracle E-Business Suite. Security-in-depth hardening fix in the Oracle Bills of Material component; Oracle states this issue is not exploitable in the context of this product. IMPORTANT: this is a routine quarterly vendor patch cycle entry, NOT a confirmed or assessed exploited vulnerability -- Oracle's own advisory text contains no exploitation claim of any kind for this CVE (checked the main advisory, the verbose risk matrix, and the accompanying blog post). Recorded with exploited=true per explicit user direction despite the complete absence of any exploitation signal from the vendor.","dueDate":"","id":"CVE-2026-60151","kev_catalogs":["ndaal"],"knownRansomwareCampaignUse":"","product":"Oracle E-Business Suite","severity":"HIGH","source":"ndaal_kev","title":"CVE-2026-60151","vendor":""}