Multiple vulnerabilities in Oracle Database Server (July 23, 2026)
Multiple vulnerabilities have been discovered in Oracle Database Server. They allow an attacker to cause remote denial of service, data confidentiality breaches, and data integrity breaches.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote denial of service and data confidentiality breaches.
- Who is affected
- Deployments of Oracle Database Server are affected.
- Urgency
- Remediation is urgent due to the potential for severe data breaches.
- Action
- Apply the latest patches for Oracle Database Server.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Database Server
Get an email when a new Database Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0914/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-469750.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-470610.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Moderate exploitation riskCVE-2026-341801.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all scored CVEs.
- Low exploitation riskCVE-2026-427661.00% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all scored CVEs.
- Low exploitation riskCVE-2026-90760.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-545140.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-341810.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-427700.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-454450.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-470400.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] OpenSSL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] FasterXML Jackson: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] OpenSSL: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle Solaris third-party components: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Construction and Engineering: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Database Server: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-61211: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd
- highCVE-2026-60175: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd
- mediumCVE-2026-47061: Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are aff…nvd
Recent advisories for Oracle Database Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Oracle Database Server: Multiple vulnerabilitiescert-bund · 2026-07-22
- criticalCVE-2026-61211: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd · 2026-07-21
- highCVE-2026-60175: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd · 2026-07-21
- mediumCVE-2026-47061: Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are aff…nvd · 2026-07-21
- mediumCVE-2026-47060: Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are aff…nvd · 2026-07-21
- highCVE-2026-47046: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are af…nvd · 2026-07-21
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31