22. July 2026
Oracle Releases Critical Patch Update for Oracle APEX
We would like to inform you about a new Critical Patch Update from Oracle that addresses 3 security vulnerabilities in the Oracle APEX environment.

Overview
- Affected versions: Oracle APEX 24.1, 24.2 and 26.1
- Risk: 2 of the 3 vulnerabilities allow a remote attack without the need for authentication (over the network/HTTP).
- Severity: CVSS scores range from 5.3 to 5.5.
Vulnerability details
- CVE-2026-60630 (Component: Installation | CVSS: 5.5) – Local vector, impacts data confidentiality.
- CVE-2026-60156 (Component: General | CVSS: 5.3) – Remotely exploitable over HTTP.
- CVE-2026-54285 (Component: Infrastructure - opentelemetry-js | CVSS: 5.3) – Remotely exploitable.
Recommendation
We recommend scheduling and performing the update to the patched versions as soon as possible. Should you have any questions or need help applying the patches, I remain fully at your disposal.





